Blog Cyber Essentials

Cyber Essentials vs Cyber Essentials Plus: which does your organisation need?

22 September 2026 · 6 min read

Cyber Essentials and Cyber Essentials Plus are not two different schemes. They are two levels of the same government-backed certification, and they check your organisation against exactly the same five technical controls. The difference is not what is assessed. It is how thoroughly it is checked, and by whom. This guide explains what each level involves, where they differ in practice, and how a small organisation should decide which one it actually needs.

If you are new to the scheme entirely, it is worth reading our plain-English guide to Cyber Essentials first, which walks through the five controls in detail. This article assumes you already know roughly what Cyber Essentials is and focuses on the choice between the two levels.

What the two levels have in common

Both Cyber Essentials and Cyber Essentials Plus certify that your organisation has the same five basic controls in place: firewalls, secure configuration, security update management, user access control and malware protection. Get those right and you close off the large majority of common internet-based attacks. Neither level asks for anything beyond those five areas, so the scope of what you need to fix is identical whichever route you take.

Both certifications also last twelve months and cover the same technical ground, which means the work you do to prepare is largely the same. The gap between them opens up only at the point of assessment.

Cyber Essentials: the self-assessment route

Standard Cyber Essentials is a verified self-assessment. You complete a questionnaire describing how your organisation meets each of the five controls, a senior person signs it off as accurate, and a certification body reviews your answers and awards the certificate if they pass.

The key word is self-assessment. Nobody from the certification body logs into your systems or tests your devices. They are relying on your answers being honest and accurate. That makes standard Cyber Essentials quick and affordable, and for many small organisations it is a perfectly sensible first step. It shows that you have thought about the basics and put them in place.

Cyber Essentials Plus: the hands-on assessment

Cyber Essentials Plus starts from the same questionnaire but adds an independent technical audit. A qualified assessor actually checks your systems: they test a sample of your devices, run vulnerability scans, confirm that updates are being applied, and verify that malware protection and access controls work as you have described.

In other words, Plus does not simply take your word for it. It confirms that the controls you claim are genuinely in place and working. That independent verification is the whole point of the Plus level, and it is why it carries more weight with clients, insurers and commissioners who want assurance rather than a self-declaration.

The practical differences that matter

Level of assurance

This is the real dividing line. Standard Cyber Essentials says you have declared that the controls are in place. Plus says an independent assessor has checked and confirmed it. If a contract, a framework or a client requires proof rather than a promise, only Plus will satisfy them.

Effort and cost

Standard Cyber Essentials is cheaper and can often be completed in a matter of days once your controls are ready. Plus costs more, because it involves an assessor's time for the hands-on testing, and it takes longer to arrange and complete. The preparation work is similar, but the assessment itself is far more involved.

Timing and sequence

The two are designed to work together. In practice you achieve standard Cyber Essentials first, then pursue Plus, usually within three months of the standard certification. Doing the self-assessment first flushes out any gaps cheaply, so that by the time an assessor arrives for the Plus audit there are no surprises.

Which one should a small organisation choose?

The honest answer is that it depends on why you are certifying. If you simply want to raise your baseline security and show customers you take it seriously, standard Cyber Essentials is a strong and cost-effective starting point. If a client contract, a public-sector framework, an NHS relationship or a cyber insurance policy specifically requires it, check the wording carefully, because many now ask for Cyber Essentials Plus by name.

For regulated small organisations in health and care, Plus is increasingly the expectation rather than a nice-to-have, and it also sits comfortably alongside your Data Security and Protection Toolkit work, since much of the underlying evidence overlaps. If you are already gathering evidence for the DSPT, you are part of the way towards a smooth Plus assessment.

Getting the basics right first

Whichever level you aim for, the preparation is the same: get the five controls genuinely in place before you book any assessment. That is where most organisations lose time, discovering during the audit that updates were not being applied everywhere, or that old accounts were never removed. An independent check of your controls and your web-facing risk before you certify saves a failed assessment later.

Our audit and pricing page sets out how we can review your controls first, and you can book a free audit to find out where you stand before you commit to either level. It is far cheaper to close the gaps quietly now than to fail a Plus assessment in front of a client deadline.

Not sure which level you need?

We will review your current controls and tell you honestly whether standard Cyber Essentials or Plus fits your situation.

Book a free audit

← Back to the blog