Cyber Essentials vs Cyber Essentials Plus is really a question about proof. One lets you tell the government you meet five baseline security controls, with a senior manager signing off the answer. The other is what happens when someone actually checks whether that signature was earned.

That distinction matters more than the price difference or the extra paperwork. Plenty of UK businesses treat Cyber Essentials as the finish line. Then a client’s due diligence check, or an NHS or MOD procurement process, reveals that Plus was the certification actually required all along. Here is what separates the two, honestly, and how to decide which one your business needs.
Table of Contents
Cyber Essentials is an honesty test, not a technical one
Cyber Essentials, run by IASME on the NCSC’s behalf, assesses five controls: firewalls, secure configuration, patch management, user access control and malware protection. You answer a questionnaire, a board-level signatory approves it, and an accredited certification body reviews the answers for consistency. Nobody scans your network. Nobody logs into your laptops. If your patching is genuinely three months behind but you believe otherwise, Cyber Essentials will not tell you that.
This is not a design flaw. Self-assessment keeps the scheme affordable, from £320 to £600 + VAT depending on organisation size, and accessible to businesses with no dedicated IT security function. It is meant to raise the floor, not certify excellence. Aardwolf’s own Cyber Essentials services cover both levels if you would rather have a specialist manage the process end to end.
Cyber Essentials Plus is where the checking starts
CE+ keeps the same five controls but replaces trust with testing. A qualified assessor runs an external vulnerability scan against your internet-facing systems, flagging anything with a CVSS score of 7.0 or above as a blocker. A representative sample of your actual devices gets tested, rather than your inventory list. Assessors confirm malware protection is switched on and current. They also check that standard users cannot act as administrators, and that multi-factor authentication is genuinely enforced where it is meant to be.
The audit has to happen within three months of your Cyber Essentials pass. If the assessor finds problems, you typically get 30 days to fix them and try again. There is no equivalent second chance built into the self-assessed version, because there was never a first test to fail.
Cyber Essentials vs Cyber Essentials Plus: side-by-side comparison
| Factor | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| How compliance is proven | Your own word, board-signed | Independent technical audit |
| What’s tested | Nothing directly | External IPs, sampled devices, access controls, MFA, malware protection |
| Cost | £320 to £600 + VAT, by organisation size | Custom quote by network size |
| Certification cycle | Annual, self-assessed each time | Annual, full audit repeated each time |
Neither version is a substitute for a proper penetration test. CE+’s scan looks for known, unpatched vulnerabilities using automated tools against a fixed checklist. It will not find a logic flaw in your bespoke web application, or chain together low-severity issues the way a manual tester would. We cover that gap in more detail in Cyber Essentials and penetration testing: what your business actually needs.
Who actually gets to choose?
For a growing number of UK businesses, the choice has already been made by someone else:
- Government contracts covered by Procurement Policy Note 09/14 require at least Cyber Essentials, and Cyber Essentials Plus where sensitive data or critical services are involved.
- MOD suppliers effectively need CE+ across most of the supply chain, and certainly for anything touching OFFICIAL-SENSITIVE information or remote access to MOD systems.
- NHS Supply Chain’s current mandate requires CE+ specifically, not basic Cyber Essentials, for suppliers handling supply chain personal data or providing IT and digital services.
If nobody is asking for a specific level yet, Cyber Essentials alone is a defensible starting point, and whole-organisation certification for businesses under £20 million turnover comes with free cyber liability insurance through IASME as a genuine bonus, not a marketing add-on.
Why nobody publishes a Cyber Essentials Plus price list
IASME is upfront that basic Cyber Essentials “is just £320 to £600 + VAT” depending on organisation size, a fixed, published scale. Cyber Essentials Plus is quoted individually instead, because an assessor’s time depends on how much genuinely needs testing: the number of external IP addresses, the size of the device sample, and how many cloud services fall inside scope. A ten-person consultancy running entirely on cloud tools is a different audit from a fifty-person site with on-premise servers. Get more than one quote; the standard being tested is set by IASME either way, so price differences reflect the assessor’s approach, not a different bar to clear.
Getting ready before the assessor turns up
A little preparation changes a CE+ audit from a stressful surprise into a formality:
- List every internet-facing IP address and domain your business controls, including anything set up years ago by a provider you no longer use.
- Confirm every device due for sampling is on a supported, patched operating system.
- Check multi-factor authentication is enforced consistently across every cloud service holding company or customer data.
- Remove leftover local administrator rights from standard user accounts, a frequent hangover from informal IT setups.
The honest case for going straight to Plus
If your business handles customer payment data, sensitive personal information, or simply has not had its patching and access controls independently checked in the last year, the CE+ audit is worth doing even without a client demanding it. It will surface the gaps a questionnaire lets you overlook, on your own timeline rather than an assessor’s. A short scoping conversation beforehand can flag likely failure points before the formal audit date arrives.
Frequently asked questions
Can you skip Cyber Essentials and go straight to Plus?
No. CE+ certification must be linked to a Cyber Essentials pass on the same scope, and the technical audit has to be completed within three months of that certification.
Does passing Cyber Essentials Plus mean you don’t need a penetration test?
No. CE+ checks for known, unpatched vulnerabilities using automated scanning against a fixed standard. It does not test custom application logic or attempt the kind of manual exploitation a penetration test uses to find deeper, chained weaknesses.
What fails a Cyber Essentials Plus audit most often?
Unpatched devices assumed to be on auto-update, leftover local admin rights on standard accounts, and inconsistent multi-factor authentication across cloud services are the recurring culprits.
How often does Cyber Essentials Plus need renewing?
Every twelve months, with the full technical audit repeated each time. There is no partial renewal or carry-over from the previous year’s result.
Is Cyber Essentials Plus expensive compared to basic Cyber Essentials?
It costs more because an assessor’s time and testing tools are involved. Pricing is quoted against the size and complexity of your network rather than a fixed band. For most SMEs it remains modest next to the cost of a serious security incident.
Does the CE+ audit include cloud accounts, not just office devices?
Yes. Any cloud service holding company or customer data falls within your certification scope, whether that’s email or file storage. It gets checked for account separation and enforced multi-factor authentication alongside the physical device sample.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.