Cyber Security
Cyber Essentials vs Cyber Essentials Plus: What's the Difference?
Cyber Essentials is a self-assessed questionnaire; Cyber Essentials Plus adds independent technical verification. Here's what each involves, what they cost in effort, and which one your business actually needs.
FNS Team · 4 min read · Updated September 2026
Cyber Essentials is a self-assessed certification based on a questionnaire; Cyber Essentials Plus covers the same five technical controls but adds an independent, hands-on technical audit of your systems. Plus is more rigorous, takes more effort and typically costs more, but carries more weight.
Both are UK government-backed schemes, administered on behalf of the National Cyber Security Centre (NCSC) through certification bodies such as IASME. Both are built around the same five technical controls. The difference is entirely in how compliance is verified — and that difference matters a lot more than it might first appear.
What Cyber Essentials involves
Cyber Essentials (sometimes just called "CE") is a self-assessment. A senior individual within the business (typically a director or senior manager) completes a detailed questionnaire covering the five technical control areas — firewalls, secure configuration, security update management, user access control, and malware protection. The answers are then reviewed and verified by a qualifying certification body before the certificate is issued.
Because it's self-assessed, Cyber Essentials is quicker and less expensive to achieve. It's a solid entry point for demonstrating that basic cyber hygiene is in place, and it's often required by clients or supply chains as a minimum bar.
What Cyber Essentials Plus adds
Cyber Essentials Plus builds on the same questionnaire but adds an independent technical audit carried out by a qualifying assessor. Rather than taking your word for it, the assessor actually tests your systems — this typically includes:
- Vulnerability scanning of in-scope devices and systems.
- Verification that security updates are genuinely applied, not just claimed.
- Checks on a sample of devices to confirm configuration matches what was described.
- Testing that malware protection and access controls are working as stated.
Because Plus involves an assessor's time on site or working with your systems remotely, it takes longer to arrange and costs more than standard Cyber Essentials. Exact current pricing and process details are set out by IASME and the NCSC and do change from time to time, so it's worth checking iasme.co.uk and ncsc.gov.uk directly rather than relying on a fixed figure.
Side-by-side comparison
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment method | Self-assessed questionnaire | Independent technical audit |
| Verified by | Reviewed by certification body | Tested hands-on by a qualified assessor |
| Typical time to achieve | Days to a few weeks | Longer — audit needs scheduling |
| Relative cost | Lower | Higher |
| Rigour | Confirms controls are declared and understood | Confirms controls actually work in practice |
| Renewal | Annual | Annual (and current CE certification is usually a prerequisite) |
| Common use case | Baseline requirement, supplier assurance | Higher-value contracts, public sector work, stronger assurance |
Why the difference matters in practice
In our experience, standard Cyber Essentials is genuinely useful for getting the fundamentals right and demonstrating a baseline of care — and for many SMEs it's the sensible starting point. But because it's self-assessed, it relies on the person filling in the questionnaire understanding their own IT environment accurately. It's entirely possible to pass Cyber Essentials while still having gaps that a technical audit would catch — an unpatched device that was mistakenly believed to be up to date, for example, or a firewall rule that isn't quite what was described.
Cyber Essentials Plus closes that gap. It's increasingly asked for by larger organisations, public sector procurement, and insurers, precisely because it provides independent proof rather than a self-reported answer.
A worked example
Picture a 12-person engineering firm that wants to bid for a contract with a larger manufacturer. The manufacturer's procurement team asks for evidence of Cyber Essentials Plus as a condition of working with subcontractors. The firm already holds standard Cyber Essentials, having completed the questionnaire the previous year. To get to Plus, they need to book an assessor, make sure every laptop actually has current updates installed (not just believed to be), and be ready for the assessor to run vulnerability scans against their live network. The process takes a few weeks longer than the standard renewal did, but it's what unlocks the contract.
Which should you go for?
- If you're starting from nothing, get standard Cyber Essentials in place first — see our companion guide on what Cyber Essentials actually requires.
- If a client, insurer, or public sector tender specifically asks for Plus, you'll need to go through the additional audit — there's no substitute.
- If you want the strongest available assurance that your controls genuinely work, not just that they're declared, Plus is worth the extra effort even without an external requirement.
- Either certification depends on your underlying IT being properly managed day to day — decent endpoint protection, patched devices and sensible access control don't happen by accident. That's a large part of what a good Managed IT and Cyber Security provider should already be doing for you.
Common mistakes
- Assuming Cyber Essentials Plus is "just a more expensive version of the same form" — the audit genuinely tests things.
- Leaving Plus preparation until a contract deadline is imminent — scheduling an assessor takes time.
- Not maintaining the controls between renewals, then scrambling every year to get back into shape.
- Confusing Cyber Essentials with broader frameworks like ISO 27001, which cover a much wider scope of information security management.
Related questions
- What does Cyber Essentials actually require?
- Is Microsoft Defender enough for a small business?
- How much should managed IT support cost in the UK?
If you're weighing up which certification is right for your business, or need help getting your environment ready for either one, our Cyber Security team can talk you through it — get in touch to start the conversation.


