← Back to Blog
Cybersecurity

Cyber Essentials vs Cyber Essentials Plus: Which Certification Do You Need?

10 September 2026 · By Ethan Fernandes

Cyber Essentials vs Cyber Essentials Plus: Which Certification Do You Need?

A clear comparison of the two Cyber Essentials certification levels, what each involves, and how to decide which one your business should pursue.

If you've looked into improving your business's cybersecurity — or you've been asked to demonstrate it for a contract or tender — you've probably come across Cyber Essentials. But there are two levels: Cyber Essentials and Cyber Essentials Plus. They sound similar, and the difference isn't always obvious at first glance.

This guide explains what each certification covers, how they differ, and which one makes sense for your business. If you're new to the scheme entirely, our Cyber Essentials certification guide covers the fundamentals in detail.

What Is Cyber Essentials?

Cyber Essentials is a UK government-backed cybersecurity certification scheme. It was introduced to help organisations of all sizes protect themselves against the most common cyber threats — the attacks that account for the vast majority of breaches.

The scheme focuses on five key technical controls:

  • Firewalls — securing the boundary between your network and the internet
  • Secure configuration — ensuring devices and software are set up securely
  • User access control — limiting who can access what, and with what privileges
  • Malware protection — defending against viruses, ransomware, and other malicious software
  • Security update management — keeping software patched and up to date

These aren't exotic, advanced security measures. They're the basics — but they're the basics that a staggering number of businesses still get wrong.

The UK government estimates that Cyber Essentials controls, when properly implemented, would prevent around 80% of common cyber attacks. That's a significant reduction in risk from getting the fundamentals right.

Cyber Essentials (Standard): The Self-Assessment

Cyber Essentials at the standard level is a self-assessment. Your business completes a questionnaire about how you've implemented the five technical controls. A qualified assessor then reviews your answers and, if everything meets the required standard, issues the certification.

What's involved

  • You complete an online self-assessment questionnaire
  • The questionnaire covers all five control areas
  • A certification body reviews your submission
  • No physical or technical testing of your systems takes place
  • Certification is valid for 12 months

The standard level is the entry-level option in terms of both cost and effort. Most small businesses can achieve it within a few weeks, depending on how much remediation is needed to bring their systems up to standard.

Cyber Essentials Plus: The Verified Audit

Cyber Essentials Plus builds on the standard certification by adding independent, hands-on technical verification. Instead of just taking your word for it, a qualified assessor actually tests your systems to confirm the controls are working as described.

What's involved

  • You must first hold a current Cyber Essentials (standard) certificate
  • An assessor conducts on-site or remote technical testing
  • Testing includes vulnerability scans of your external IP addresses
  • Assessors check a sample of your devices for secure configuration
  • They verify that malware protection is active and effective
  • They test that user access controls are properly implemented
  • Certification is valid for 12 months
Think of it this way: Cyber Essentials asks "have you locked the doors?" Cyber Essentials Plus sends someone to try the handles. Both are valuable, but Plus provides verified assurance that your controls actually work in practice.

Side-by-Side Comparison

Factor Cyber Essentials Cyber Essentials Plus
Assessment type Self-assessment questionnaire Independent technical audit
Technical testing None Vulnerability scans, device checks, control verification
Cost Entry-level — affordable for most small businesses Costs more due to hands-on assessor time
Time to certify Typically a few weeks Typically a few weeks after achieving standard CE
Prerequisite None Current Cyber Essentials certificate required
Level of assurance Self-declared compliance Independently verified compliance
Validity 12 months 12 months
Suitable for Businesses wanting baseline security and contract eligibility Businesses needing verified security for sensitive contracts or higher assurance

Government Contracts and Cyber Essentials

One of the most common reasons businesses pursue Cyber Essentials is that it's required for certain government contracts. Since 2014, the UK government has mandated that suppliers bidding for contracts involving the handling of sensitive or personal data must hold at least Cyber Essentials certification.

For more detail on which contracts require it and how to position your business, see our guide on whether you need Cyber Essentials for government contracts.

Don't wait until you're mid-tender to start the certification process. Getting your systems ready can take several weeks, and failing a Plus assessment means remediation and re-testing. Start early so the certificate is in hand when opportunities arise.

While standard Cyber Essentials meets the minimum requirement for most government contracts, some contracts — particularly those involving more sensitive data or higher-risk environments — may specify Cyber Essentials Plus. It's worth checking the specific requirements of any tender you're interested in.

Which One Do You Need?

The right choice depends on your business's circumstances, your clients' expectations, and the level of assurance you want to demonstrate.

Cyber Essentials (standard) is right if you:

  • Want to establish baseline cybersecurity practices
  • Need to meet the minimum requirement for government contracts
  • Are looking for a cost-effective starting point for formal security certification
  • Want to demonstrate to clients and partners that you take security seriously
  • Are a small business looking to reduce your exposure to common attacks

Cyber Essentials Plus is right if you:

  • Handle sensitive client data and want independently verified protection
  • Bid for government contracts that specifically require Plus
  • Work in sectors where clients expect a higher level of security assurance (legal, financial, healthcare)
  • Want the confidence that your controls have been tested by an external party, not just self-declared
  • Need to satisfy cyber insurance requirements that mandate verified certification

Our Recommendation

For most small businesses, we recommend starting with Cyber Essentials as your first step. It's achievable, affordable, and immediately improves your security posture. Once you have the standard certification in place, pursuing Cyber Essentials Plus is a natural next step — especially if you work with sensitive data, serve regulated industries, or want to stand out in competitive tenders. The standard gives you the foundation; Plus gives you the proof.

Whichever level you pursue, the process of getting certified is valuable in itself. It forces you to review your security practices, close gaps, and build habits that protect your business long after the certificate is issued.

The Certification Process: What to Expect

For the standard level, the process is straightforward. You'll work through the self-assessment questionnaire, which asks detailed questions about how your organisation implements each of the five controls. If you're working with an MSP, they'll typically help you prepare — identifying gaps in your current setup and resolving them before you submit.

For Plus, the additional technical assessment usually takes a day or two, depending on the size of your organisation. The assessor will scan your external-facing systems, check a sample of devices, and verify your controls in practice. If issues are found, you'll have a window to remediate and re-test.

Both certifications are valid for 12 months, after which you'll need to recertify. This annual cycle is actually a strength — it ensures your security practices stay current rather than becoming a one-time box-ticking exercise.

Frequently Asked Questions

Do I need Cyber Essentials before I can get Cyber Essentials Plus?

Yes. Cyber Essentials Plus requires a current Cyber Essentials (standard) certificate as a prerequisite. You must achieve the standard level first, and then the Plus assessment builds on that foundation with hands-on technical testing.

How long does each certification take?

Cyber Essentials standard can typically be achieved in two to four weeks, depending on how much remediation your systems need. Cyber Essentials Plus adds a further one to three weeks for the technical assessment and any follow-up. If your systems are already well-managed, the process can be quicker.

Will Cyber Essentials protect my business from all cyber attacks?

No certification can guarantee complete protection. Cyber Essentials is designed to defend against the most common, commodity-level attacks — and it does that very effectively. More sophisticated, targeted attacks require additional security measures beyond the scope of Cyber Essentials. Think of it as a strong foundation, not a complete fortress.

Is Cyber Essentials only relevant for businesses working with the government?

Not at all. While government contracts brought Cyber Essentials into the spotlight, the certification is increasingly expected by private-sector clients, insurers, and partners. It's a recognised standard that signals your business takes cybersecurity seriously, regardless of who your clients are.

What happens if I fail the Cyber Essentials Plus assessment?

If the assessor finds issues during the Plus audit, you'll be given a remediation period to fix them. Once the issues are resolved, the assessor re-tests. It's not uncommon for minor issues to be flagged — the important thing is addressing them promptly. Working with an experienced provider beforehand significantly reduces the chance of unexpected failures.

Can an MSP help with Cyber Essentials certification?

Yes. Many managed service providers, including those who manage your day-to-day IT, can guide you through the entire process — from initial gap analysis to remediation to submission and assessment. Having professional support typically makes the process faster and smoother, especially for businesses without dedicated security expertise.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.