Two certifications, one scheme, and a surprising amount of confusion between them. Cyber Essentials and Cyber Essentials Plus cover exactly the same five technical controls, which is why the names sit so close together, and yet they cost different amounts, take different lengths of time, and prove genuinely different things to the customer asking for them. Picking the wrong one is an expensive way to learn the difference.
In short: Cyber Essentials and Cyber Essentials Plus assess the same five controls: firewalls, secure configuration, security update management, user access control and malware protection. Cyber Essentials is a self-assessment questionnaire, signed off by a director and reviewed by a certification body. Cyber Essentials Plus keeps that questionnaire and adds an independent hands-on technical audit, where an assessor scans a sample of your real devices to verify the answers. You must hold Cyber Essentials before Plus, awarded within the previous three months. Choose based on what your contracts specify: where a buyer asks for Plus, self-assessment will not satisfy it.
This guide is written for businesses that have been asked for one of these by a customer, an insurer or a tender, and need to work out what is actually involved before committing budget to it. It covers what each certification verifies, what the five controls require in practice, where the real effort goes, and how to decide which level you need.
The two certifications, in plain terms
Cyber Essentials
Cyber Essentials is the UK government-backed baseline, overseen by the National Cyber Security Centre and delivered through IASME as the scheme's accreditation body. You complete a self-assessment questionnaire covering the five control themes, a board-level director signs a declaration confirming the answers are accurate, and a certification body reviews and marks the submission.
The key characteristic is that it is an assertion. No external party logs into your systems, scans a device or inspects a configuration. The certification body checks that your answers are coherent, complete and consistent with the scheme requirements, and can query or reject a submission that is not. But the underlying facts are the ones you have supplied about your own estate.
That is not a criticism of the scheme. A baseline that most organisations can realistically reach does more good across the economy than a rigorous one that few attempt, and the five controls genuinely do block the large majority of commodity internet attacks. It simply means everyone should be clear about what the badge represents.
Cyber Essentials Plus
Cyber Essentials Plus starts from exactly the same questionnaire and adds independent verification. An assessor from a certification body conducts a hands-on technical audit: vulnerability scans against a representative sample of your devices, tests that malware protection actually blocks what it should, and checks that email filtering behaves as described. The sample is chosen by the assessor, not by you.
Because the audit tests the estate described in the self-assessment, you must already hold a valid Cyber Essentials certificate, awarded within the previous three months, before the Plus audit can proceed. The two are sequential stages, not alternatives.
"The controls are identical. What you are buying with Plus is not more security, it is independent proof that the security you already claimed is genuinely there."
The five controls, and what each actually requires
The five control themes are the same at both levels, so the remediation work is the same regardless of which certification you are heading for. This is the part most businesses underestimate, because it is where the real effort lives.
Firewalls
Every device must sit behind a correctly configured firewall, and that includes the software firewall on laptops that leave the office and connect from homes, hotels and client sites. Boundary firewalls need default administrative passwords changed, administrative interfaces unreachable from the internet, and any inbound rule justified and documented. Unjustified open ports are one of the most common findings.
Secure configuration
Devices and software ship configured for ease of setup rather than security, and the control is about undoing that. Remove or disable unnecessary accounts, software and services; change every default password; and disable auto-run behaviour that executes code without the user choosing to. On a mature Microsoft estate a good deal of this is handled through Intune configuration profiles rather than device by device, which is why centrally managed estates certify so much faster than unmanaged ones.
Security update management
All software must be supported by its vendor and still receiving security updates, and high-risk or critical updates must be applied within 14 days of release. Two things fail this control repeatedly: an operating system that has passed end of support and is still in service, and a patching process that covers Windows well but leaves third-party applications, browsers, PDF readers and line-of-business software to drift. Unsupported software in scope is a hard fail rather than an observation.
User access control
Accounts must be created through an approved process, reviewed, and removed promptly when someone leaves. Administrative privilege must be granted deliberately and used only for administrative tasks, which in practice means day-to-day work does not happen in an admin account. Multi-factor authentication is required on cloud services. Leavers who still have active accounts and users with permanent local administrator rights are the two findings that come up most.
Malware protection
Devices need anti-malware protection that is active and updating, or an equivalent approach such as application allow-listing where that suits the estate better. For most Microsoft-centric businesses this is Defender, correctly configured and actually reporting, rather than installed and forgotten.
What Cyber Essentials Plus tests that Cyber Essentials does not
The Plus audit is not a paperwork review. The assessor works against a sample of live devices and looks for the gap between what the questionnaire claimed and what the estate does.
Vulnerability scanning is the core of it: authenticated scans against sampled devices to identify missing patches and unsupported software. Because the standard is that high-risk and critical updates are applied within 14 days, a device that is three months behind will be found, regardless of what the patching policy says on paper.
Malware protection is tested rather than assumed, confirming that protection is present, active and behaves correctly. Email and web filtering are checked to see whether malicious content is handled the way the self-assessment described.
The sample matters. The assessor selects which devices to test, so an estate where most machines are well managed and a handful are not cannot rely on the good ones being chosen. This is the single biggest practical difference between the two certifications, and the reason Plus is worth meaningfully more to a buyer.
The full comparison
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment method | Self-assessment questionnaire | Self-assessment plus hands-on technical audit |
| Who verifies the answers | Certification body reviews the submission | Independent assessor tests real devices |
| Technical testing | None | Vulnerability scans, malware and email filtering tests |
| Prerequisite | None | Valid Cyber Essentials awarded in the previous 3 months |
| Control themes covered | All five | All five, identical |
| Device sampling | Not applicable | Assessor chooses the sample |
| Relative effort | Lower, concentrated in remediation | Higher, remediation plus audit readiness |
| Relative cost | Lower | Higher |
| What it proves to a buyer | You have asserted the controls are in place | The controls were independently verified as working |
Which one do you actually need?
Start with the contract wording, not with a general sense of which sounds better. Where a tender or customer agreement specifies Cyber Essentials, base-level certification satisfies it. Where it specifies Plus, only the audited version does, and certifying at the wrong level means paying twice.
Beyond contractual requirements, the question is what the certificate is for. If it exists to satisfy a procurement checkbox and give you a structured reason to fix the basics, Cyber Essentials does that job well and is the sensible starting point for most businesses that have never certified. If it exists to give a customer genuine assurance, particularly where you handle their data or connect to their systems, Plus is what carries weight, because it is the version that survives the question "but did anyone check?"
There is also a sequencing argument worth taking seriously. Because Plus requires a Cyber Essentials certificate awarded within the previous three months, a business that expects to need Plus eventually is better off treating both as one project. Close the gaps once, certify, then move to the audit while the estate still matches what you described. Splitting them a year apart means doing the self-assessment twice.
Where businesses actually lose time
Almost none of the effort is in the questionnaire. It is in the estate.
The most common delay is discovering nobody has a reliable inventory of what is connected. You cannot answer questions about patching, malware protection or supported operating systems for devices you have not enumerated, and building that picture from scratch is often the longest single task in the project.
The second is unsupported software still in service, which is a hard fail rather than something to explain around. An old operating system, a line-of-business application pinned to a version that requires it, or a server that everyone knows about and nobody owns will each stop certification until resolved. Where the blocker is a legacy application rather than the operating system beneath it, application modernisation or MSIX packaging can move the application forward onto a supported platform without a rewrite.
The third is scope confusion, particularly around cloud services and personal devices. Microsoft 365 and Azure are in scope where they hold organisational data. Personal devices used for organisational work are generally in scope too. Businesses that assume otherwise tend to find out late, when the questionnaire asks a question they cannot answer.
How we approach it
We run this as a gap assessment first, because the questionnaire is not the work. We establish what is actually in the estate, test each of the five control themes against what the scheme requires, and produce a list of what needs to change before certification is realistic. Where the remediation is Microsoft-centric, which it usually is, the fixes sit in ground we already manage: identity and MFA in Entra ID, device configuration and patch compliance through Intune, and Defender for malware protection.
From there the route depends on the answer you need. If Cyber Essentials satisfies your contracts, we close the gaps and take you through the self-assessment. If you need Plus, we plan both stages inside the three-month window so the audit lands while the estate still matches the submission, and we run our own vulnerability scan against a representative sample first, so the assessor's findings are not the first time anyone has looked.
Our Cyber Essentials readiness checklist walks through the five control themes and what assessors look for, and our Cyber Essentials in 30 days write-up covers what a compressed timeline realistically involves. If certification is a supply-chain requirement rather than a one-off, our compliance packs cover the policies and evidence that sit alongside it, and the cyber security service page explains the underlying controls we manage day to day.
We work with businesses across Yorkshire and the UK from our base in Brough, East Yorkshire, including Hull, Leeds, Sheffield and York, and you can see the full coverage area if you are elsewhere in the county. If you would rather talk it through before committing to a level, get in touch and we will tell you which one your contracts actually need.
Frequently asked
What is the actual difference between Cyber Essentials and Cyber Essentials Plus?
The controls are identical. The difference is entirely in how they are proved. Cyber Essentials is a self-assessment: you answer a questionnaire about your own estate, a board-level director signs a declaration that the answers are true, and a certification body reviews the submission. Nobody from outside your organisation logs into anything or scans a device. Cyber Essentials Plus keeps that questionnaire as its foundation and then adds an independent technical audit on top, where an assessor tests a sample of your actual devices to confirm the answers hold up in practice. So Cyber Essentials tells a customer you have said the five controls are in place. Cyber Essentials Plus tells them somebody independent checked. That distinction is the entire value gap, and it is why the two certifications are priced and treated so differently in procurement, despite covering exactly the same technical ground.
Do I need Cyber Essentials before I can get Cyber Essentials Plus?
Yes, and the timing matters more than most businesses expect. You must hold a valid Cyber Essentials certificate before the Plus audit, and that certificate must have been awarded within the previous three months. This catches people out: a business that certified at Cyber Essentials in January and decides in September that a contract now requires Plus cannot simply book the audit, because the three-month window has closed and the self-assessment has to be redone first. If you already know Plus is where you need to end up, the sensible approach is to treat them as one project with two stages rather than two separate exercises a year apart. Close the gaps once, certify at Cyber Essentials, then move to the Plus audit inside the window while the estate is still in the state you just described on the questionnaire.
What are the five Cyber Essentials controls?
Firewalls, secure configuration, security update management, user access control, and malware protection. Firewalls covers the boundary between your network and the internet, including the software firewall on devices that leave the office. Secure configuration means removing the things that ship enabled by default and are not needed: default passwords, unnecessary accounts, unused software and services. Security update management requires that software is supported by its vendor and that high-risk and critical patches are applied within 14 days of release. User access control covers how accounts are created, reviewed and removed, and requires that administrative privilege is granted deliberately rather than by habit, with multi-factor authentication on cloud services. Malware protection requires anti-malware on devices, or an equivalent approach such as application allow-listing. The list has been stable for years; what changes between scheme versions is the detail of how each one is interpreted, particularly around cloud services and personal devices.
How long does Cyber Essentials take, and how long does Plus add?
The assessment itself is quick. The remediation before it is what takes the time, and it varies enormously depending on where you are starting. A business with a well-managed Microsoft 365 tenant, centrally managed devices, MFA already deployed and a working patch process can often complete the Cyber Essentials questionnaire in a matter of days. A business with unmanaged laptops, no device inventory, local administrator rights everywhere and an unsupported operating system still in service can spend a couple of months on remediation before the questionnaire is worth submitting. Cyber Essentials Plus then adds the audit itself, which is usually a day or two of assessor time depending on estate size, plus scheduling. The honest planning assumption is that the paperwork is never the bottleneck and the device estate always is, so start by finding out what you actually have.
Which one do our customers or contracts actually require?
Read the wording, because the two are not interchangeable and vague summaries cause real problems. UK central government contracts involving handling personal information or providing certain ICT services have required Cyber Essentials for years, and some specify Plus. Where a contract says Cyber Essentials without qualification, base-level certification satisfies it. Where it says Cyber Essentials Plus, only the audited version does, and no amount of self-assessment will substitute. In private-sector supply chains the requirement increasingly arrives through a customer's own procurement or insurance obligations rather than regulation, which means the wording is less standardised and worth checking carefully. If a tender is ambiguous, ask the buyer directly before you spend money, since the cost difference between the two is significant and certifying at the wrong level is an expensive way to discover the distinction.
Does Cyber Essentials cover cloud services like Microsoft 365?
Yes, and this is one of the most commonly misunderstood parts of the scheme. Cloud services you use to hold organisational data or run organisational services are in scope, which for most businesses means Microsoft 365 and Azure sit squarely inside the assessment boundary rather than outside it. That has practical consequences: multi-factor authentication on cloud accounts, sensible administrative role assignment in Entra ID, and control over how data is shared externally all become things you have to be able to evidence. Businesses sometimes assume that because a service is managed by Microsoft, its security is Microsoft's responsibility and therefore out of scope. The scheme takes the opposite view. Microsoft secures the platform; how you configure identity, access and sharing within it is yours, and that configuration is what the assessment asks about.
What happens if we fail the Cyber Essentials Plus audit?
It is not usually terminal, but the rules around retesting are time-bound. Where the assessor finds issues during the audit, there is normally a short window to fix them and be retested rather than starting the whole process again, provided the problems are remediable rather than fundamental. What causes a genuine restart is discovering during the audit that the estate does not resemble what the self-assessment described, for example unsupported operating systems still in service that were not declared, or devices nobody knew existed. The practical lesson is that the Plus audit is not the place to find out what is on your network. Run your own vulnerability scan against a representative sample of devices before the assessor does, confirm every device is on a supported and patched operating system, and check that malware protection and email filtering behave as you believe they do.




