What are the differences between Cyber Essentials and Cyber Essentials Plus?
What are the differences between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials and Cyber Essentials Plus help organisations protect themselves against common online threats. Both certifications follow the same five technical controls, but they use different assessment methods and provide different levels of assurance.
Cyber Essentials uses a verified self-assessment. The organisation answers a detailed questionnaire about its devices, systems, cloud services, accounts, security settings, and working practices. A qualified assessor reviews the answers, and a director or equivalent senior representative confirms that the information is accurate.
Cyber Essentials Plus starts with the same requirements, but it adds an independent technical audit. A qualified Cyber Essentials Plus assessor tests a sample of the organisation’s systems to confirm that the controls work as described.
The key difference does not sit in the controls themselves. Cyber Essentials Plus does not ask a company to follow a separate, more advanced control set. Instead, it provides stronger assurance because an assessor checks the controls through technical testing.
UK Cyber Security Group offers Cyber Essentials and Cyber Essentials Plus certification for organisations seeking an affordable, guided route through the scheme. Its team can help a business understand the scope, identify gaps, prepare accurate answers, and get ready for technical testing.
The central difference in one sentence
Cyber Essentials confirms compliance through an independently reviewed self-assessment, while Cyber Essentials Plus confirms the same controls through a self-assessment and an independent technical audit.
That distinction matters when customers, procurement teams, insurers, investors, public bodies, and supply chain partners want evidence of cyber security.
Cyber Essentials gives them confidence that senior management has reviewed and confirmed the organisation’s answers. Cyber Essentials Plus adds direct technical verification from a qualified assessor.
Some organisations only need Cyber Essentials to meet a contract, improve their basic security, or show customers that they follow a recognised government-backed scheme. Others choose Cyber Essentials Plus because they handle sensitive information, work within demanding supply chains, support public bodies, or need stronger third-party assurance.
Neither certificate guarantees that an organisation will never suffer a cyber incident. No certification can make that promise. Both help reduce exposure to common attacks by requiring organisations to apply five practical security controls consistently.
The same five controls support both certificates
Cyber Essentials and Cyber Essentials Plus assess the same five technical control areas:
Firewalls protect devices and networks from unwanted access.
Secure configuration removes avoidable weaknesses, unnecessary accounts, unused software, and unsafe default settings.
User access control ensures people receive only the access they need and protects administrator accounts carefully.
Malware protection helps stop malicious software and untrusted applications from causing harm.
Security update management keeps operating systems, applications, firmware, and related components supported and updated.
These controls focus on common attacks rather than every possible cyber threat. They aim to close the basic routes that criminals often exploit, including weak passwords, missing updates, excessive privileges, unsafe settings, exposed services, and ineffective malware protection.
Cyber Essentials Plus does not replace these controls with a different framework. It checks whether the organisation has applied them properly.
Cyber Essentials explained
Cyber Essentials provides a government-backed baseline for cyber security. Organisations complete an online self-assessment questionnaire that covers their in-scope infrastructure and use of the five controls.
The applicant must understand its scope before answering. Scope may include laptops, desktops, servers, mobile devices, routers, firewalls, cloud services, remote working arrangements, and personally owned devices that access organisational data or services.
Accurate scope matters because the certificate only provides assurance for the infrastructure described. A company should not exclude difficult systems simply to make certification easier. Exclusions need a clear and valid reason.
A qualified assessor reviews the completed answers. The assessor may ask questions, request clarification, or identify areas that need correction. A member of senior management must also approve the declaration and confirm that the answers accurately represent the organisation.
Cyber Essentials does not include a technical vulnerability scan as part of the standard self-assessment route. The process relies on truthful, accurate answers that a qualified assessor reviews independently.
This makes Cyber Essentials accessible to small organisations while still providing meaningful assurance. It also encourages senior leaders to take responsibility for the accuracy of the application and continued compliance.
Cyber Essentials Plus explained
Cyber Essentials Plus includes the same verified self-assessment but adds independent technical checks. A qualified assessor examines the organisation’s in-scope environment and tests whether the controls operate effectively.
The audit can take place remotely, on site, or through a combination of both, depending on the organisation and its technical environment.
The assessor normally tests a representative sample of user devices and relevant systems. The assessment also considers internet gateways and servers that provide services to unauthenticated internet users.
Technical checks can include authenticated vulnerability scanning, checks for missing security updates, malware protection testing, account privilege checks, and testing of protections against common email and web-based threats.
The assessor does not simply ask whether a control exists. They look for technical evidence that the control works.
For example, an organisation may state that staff use standard accounts for normal work and separate administrator accounts for management activity. During the Plus audit, the assessor can test whether a standard user can perform an administrator action.
A company may also state that it applies important security updates within the required period. The assessor can scan sampled systems to identify missing vulnerability fixes and compare the results with the organisation’s answers.
This direct verification gives Cyber Essentials Plus its higher level of assurance.
Greater assurance rather than different requirements
Businesses sometimes assume that Cyber Essentials Plus contains more controls. It does not. Both certificates use the same five controls and the same core infrastructure requirements.
The difference lies in how the organisation demonstrates compliance.
Cyber Essentials relies on declared information that an independent assessor reviews. Cyber Essentials Plus adds technical testing that checks the declared controls against the real environment.
This makes Plus useful when a customer wants more than a written declaration. The technical audit gives the customer additional confidence that an external professional has examined the organisation’s controls.
The higher assurance may also help during supplier onboarding. Procurement teams often need evidence that a supplier manages common cyber risks. A Plus certificate can reduce uncertainty because it confirms that an assessor tested the environment rather than only reviewing answers.
What are the key requirements for achieving Cyber Essentials certification?
An organisation must apply the five Cyber Essentials controls across its declared scope.
It must use firewalls to control access between in-scope devices and untrusted networks. The organisation should remove or disable unnecessary firewall rules and protect administrative access.
Secure configuration requires the business to remove unnecessary accounts, change default credentials, disable unused services, remove unneeded software, and require authentication before users access organisational information.
User access control requires the organisation to create and manage accounts properly, limit administrator privileges, remove access that people no longer need, and protect relevant accounts with multi-factor authentication.
Malware protection requires an approved method for stopping known malware and untrusted software. Depending on the device and operating environment, the organisation may use anti-malware software, application allow listing, or sandboxing.
Security update management requires supported software and timely vulnerability fixes. High-risk and critical fixes must normally receive action within 14 days of release.
The business must describe its infrastructure accurately and answer every question honestly. Senior management must confirm that the organisation has applied the controls and will maintain them during the certification period.
Cyber Essentials Plus checks these same requirements through technical testing.
The Cyber Essentials assessment journey
The Cyber Essentials route normally begins with scoping. The organisation identifies the devices, networks, cloud services, users, and business services that need coverage.
Next comes a readiness review. The business checks whether software remains supported, security updates arrive on time, MFA protects relevant accounts, administrator rights remain limited, malware protection works, and firewall rules make sense.
The organisation then completes the online questionnaire. Clear records help at this stage. Asset lists, software records, user account information, cloud service details, firewall information, and supplier responsibilities can make the answers easier to prepare.
A qualified assessor reviews the submission. They may return questions or request changes where answers lack clarity. Once the organisation satisfies the requirements, the certification body issues the certificate.
The certificate remains valid for 12 months. The business must maintain compliance throughout that period, not only on the day it submits the assessment.
The Cyber Essentials Plus assessment journey
An organisation normally achieves Cyber Essentials before completing Cyber Essentials Plus. It must complete the Plus audit within three months of its most recent Cyber Essentials certification if it wants to use that assessment as the starting point.
Both certificates must cover the same scope. A company cannot complete Cyber Essentials for a narrow area and then claim Plus assurance for a wider environment without addressing the scope properly.
The Plus assessor agrees the audit arrangements with the organisation. Preparation may include reviewing scope, confirming device groups, identifying cloud services, arranging test accounts, and making sure relevant systems will remain available during the audit.
The assessor then performs technical checks against a representative sample. The sample commonly covers around 10 per cent of relevant user devices, although the assessor may expand testing when findings create concern.
A failed test does not always mean the whole effort ends immediately. The assessor explains the issue and follows the scheme process for remediation and retesting. However, the organisation must correct problems across the full affected scope rather than only changing the individual sampled device.
This point matters. A sample represents a wider group. Fixing only the device that the assessor tested would not show effective control across the organisation.
What the Plus audit checks in practice
The audit looks for practical evidence across the five controls.
Firewall testing may check internet-facing exposure, gateway protection, administrative access, and whether public services match the declared scope.
Security update checks may use authenticated scans to identify missing vulnerability fixes on sampled devices, servers, and relevant cloud infrastructure.
Malware protection checks may confirm that appropriate protection operates on user devices and applicable servers. The assessor may use safe test files or controlled checks rather than real malware.
User access checks may test whether standard users can run administrator processes. The assessor may also review cloud administrator accounts and authentication controls.
Email and web protection checks may examine whether the environment blocks common malicious content and known unsafe destinations.
The assessor records findings and decides whether the organisation meets the scheme requirements. This testing creates stronger independent assurance but does not amount to a full penetration test.
Cyber Essentials Plus is not a penetration test
A Cyber Essentials Plus audit checks compliance with a defined set of controls. A penetration test looks for exploitable weaknesses through a wider or more targeted security assessment.
The Plus audit follows a standard test specification. It checks whether the organisation has applied the Cyber Essentials controls correctly across its declared scope.
A penetration test may explore web applications, networks, APIs, cloud configurations, mobile applications, or other agreed targets in greater depth. The tester may try to combine weaknesses and demonstrate how an attacker could exploit them.
Both services have value, but they answer different questions.
Cyber Essentials Plus asks whether the organisation meets the scheme’s technical baseline.
A penetration test asks whether a skilled tester can find and exploit weaknesses within an agreed target.
Businesses should avoid treating one as a complete substitute for the other.
Which certificate offers the right level of assurance?
Cyber Essentials works well for organisations that want to establish a recognised baseline, meet an initial customer requirement, improve security discipline, or begin their certification journey.
Cyber Essentials Plus suits organisations that need stronger independent evidence. This often includes suppliers handling sensitive information, businesses working with public bodies, technology providers, managed service providers, and companies whose customers require technical verification.
Some contracts specify Cyber Essentials, while others require Cyber Essentials Plus. The organisation should read each requirement carefully and confirm that the requested scope matches the service or contract.
A business may also choose Plus voluntarily. Customers increasingly ask suppliers to prove that controls work rather than merely state that they exist. Plus can support that conversation.
The best choice depends on the required assurance, customer expectations, contractual obligations, risk exposure, and internal readiness.
Why a business may begin with Cyber Essentials
Cyber Essentials gives organisations a practical starting point. The self-assessment process helps the business understand its infrastructure and identify weaknesses.
Small organisations often discover outdated devices, forgotten administrator accounts, missing MFA, unsupported applications, excessive user privileges, or unclear supplier responsibilities while preparing their answers.
Correcting these issues provides real value even before the certificate arrives.
Cyber Essentials also creates a structured annual review. Renewal encourages the business to revisit its scope, devices, accounts, services, and controls.
For a company that has not followed a formal cyber security framework before, Cyber Essentials provides a clear and manageable route.
Why a business may progress to Cyber Essentials Plus
Cyber Essentials Plus confirms that an independent professional has tested the controls. This can strengthen trust with customers, procurement teams, partners, and insurers.
The Plus audit also gives the organisation useful feedback. Technical testing can reveal differences between documented processes and real system behaviour.
For example, policy may require timely updates, while a scan reveals that several devices have missed important fixes. The organisation may believe users lack administrator access, while testing identifies an unexpected privilege. A cloud service may support MFA, but some accounts may not use it.
These findings help the organisation correct weaknesses before attackers exploit them.
Plus therefore provides both external assurance and an opportunity to improve internal security.
How can I prepare my small business for Cyber Essentials assessment?
Start by defining the scope. List the devices, cloud services, routers, firewalls, servers, remote workers, and personally owned devices that access organisational information.
Review operating systems and applications to confirm that vendors still support them. Remove software that no longer receives security fixes or take approved action to manage it outside the scope where the rules allow.
Check security updates across all relevant systems. High-risk and critical fixes should receive action within 14 days.
Review user and administrator accounts. Remove accounts that no longer have a valid purpose. Limit administrator access and use separate accounts for everyday work where appropriate.
Enable MFA on administrator accounts and internet-accessible services wherever the service makes it available. Check email, cloud storage, finance tools, remote access, website dashboards, password managers, and business applications.
Confirm that malware protection works on each relevant device group. Review firewall rules and remove unnecessary exposure.
Keep evidence. Asset records, screenshots, supplier confirmations, update reports, account reviews, and security dashboards can help the organisation answer the questionnaire accurately.
UK Cyber Security Group can support preparation by reviewing the environment, explaining the requirements, and helping the business correct gaps before submission.
Preparing specifically for Cyber Essentials Plus
Plus preparation should go beyond completing the questionnaire. The organisation needs to confirm that its real systems match its answers.
Run an internal review across the full scope rather than focusing only on devices likely to enter the audit sample.
Check update status on every device group. Review firewall exposure. Test malware protection. Confirm user privileges. Check MFA coverage. Review unsupported software and old accounts.
Speak with third-party IT providers early. The assessor may need information or temporary access related to cloud services, firewalls, servers, endpoint management, or security tools.
Make sure staff understand that an assessor may ask them to perform normal tasks on sampled devices. Clear communication reduces confusion during the audit.
Avoid temporary audit-only fixes. The organisation must maintain the controls throughout the certification period. A setting that only remains active during testing does not create meaningful compliance.
What software solutions support compliance with Cyber Essentials standards?
Several software categories can help businesses manage the five controls.
Endpoint management tools can provide visibility of devices, operating systems, applications, configuration, and update status.
Mobile device management can help control phones and tablets that access business services.
Identity platforms can manage accounts, MFA, access rules, and administrator privileges.
Password managers can help staff use strong, unique credentials.
Endpoint protection tools can help stop malware and unsafe applications.
Vulnerability management tools can identify missing fixes and known weaknesses before a Plus assessor finds them.
Firewall and cloud security dashboards can help organisations review internet exposure, rules, and administrative access.
Asset management and compliance platforms can organise devices, owners, evidence, responsibilities, and review dates.
Technology alone does not create compliance. The organisation still needs clear ownership, accurate scope, good records, and regular review. Choose tools that the business can maintain and understand.
Certification validity and ongoing responsibility
Cyber Essentials and Cyber Essentials Plus certificates remain valid for 12 months. Both require annual renewal.
The organisation must maintain the controls throughout the year. Current scheme declarations reinforce this responsibility.
A certificate does not excuse later security drift. New devices, new accounts, supplier changes, cloud migrations, staff departures, and software changes can all affect compliance.
Businesses should review the controls regularly rather than waiting for renewal. Monthly or quarterly checks can make the next assessment much easier.
Useful checks include update compliance, MFA coverage, administrator accounts, firewall rules, unsupported software, malware protection status, and changes to scope.
Can I renew my Cyber Essentials certification through an online service?
Yes. Cyber Essentials uses an online self-assessment process, so organisations can complete renewal through the secure assessment portal provided by their certification body.
Renewal should reflect the current business environment. Do not copy old answers without checking them.
Review all devices, cloud services, internet gateways, users, administrator accounts, suppliers, and remote working arrangements. Confirm that every answer remains accurate.
Cyber Essentials Plus also requires annual renewal. The organisation completes the applicable Cyber Essentials assessment and undergoes another technical audit.
A renewed Plus certificate gives customers current assurance that an assessor has tested the controls again. This matters because technology and threats change quickly.
UK Cyber Security Group can support both initial certification and annual renewal, helping businesses identify changes before they create assessment problems.
The commercial value of stronger assurance
Certification can support more than technical security. It can also help with tenders, supplier onboarding, contract reviews, customer questionnaires, and wider trust.
Cyber Essentials shows that an organisation follows a government-backed baseline. Cyber Essentials Plus adds technical verification.
For procurement teams, this distinction can influence supplier risk decisions. A customer with lower-risk requirements may accept Cyber Essentials. A customer handling sensitive data or critical services may request Plus.
The certificate should match the service under consideration. A broad certificate may give customers more confidence than one covering a limited subset, although a focused scope can still make sense when it clearly matches the contracted service.
Businesses should communicate scope accurately and avoid suggesting that a certificate covers areas outside its stated boundary.
Which companies provide Cyber Essentials certification services in the UK?
IASME serves as the NCSC’s delivery partner for the Cyber Essentials scheme and licenses a network of certification bodies across the UK and Crown Dependencies.
Approved certification bodies employ qualified assessors who review Cyber Essentials submissions and issue certificates when organisations meet the requirements.
Certification bodies that offer Cyber Essentials Plus must also employ appropriately qualified Plus assessors. These assessors complete additional training and meet technical competence requirements.
UK Cyber Security Group provides Cyber Essentials and Cyber Essentials Plus certification services. It supports businesses through scoping, preparation, assessment, remediation, and renewal.
Before choosing a provider, confirm that it operates as an approved certification body for the service you need. Look for clear guidance, responsive support, current scheme knowledge, and experience with organisations similar to yours.
Which UK-based firms offer Cyber Essentials consultancy services?
UK organisations can seek support from certification bodies, cyber security consultancies, managed IT providers, and NCSC-assured Cyber Advisors.
UK Cyber Security Group offers consultancy and certification support for Cyber Essentials and Cyber Essentials Plus. Its services can help organisations understand the requirements, define scope, review security controls, prepare evidence, and resolve weaknesses.
Good consultancy should simplify the process without weakening it. A provider should explain why each control matters and help the business build sustainable practices.
Avoid support that focuses only on completing the questionnaire. Accurate answers matter, but the real goal involves protecting the organisation from common attacks.
For Plus, choose support with practical technical knowledge. The provider should understand vulnerability scanning, endpoint protection, firewalls, accounts, cloud services, update management, and audit preparation.
Common misunderstandings
One common misunderstanding says that Cyber Essentials Plus uses more advanced controls. Both certificates assess the same controls.
Another misconception treats Cyber Essentials as an unverified declaration. A qualified assessor independently reviews the submission, and senior management approves its accuracy.
Some businesses assume Plus checks every device. The assessor normally uses a representative sample, then makes a judgement about the wider scope.
Others view Plus as a penetration test. It follows a defined technical audit process and does not replace a broader security test.
Another mistake involves treating certification as permanent. Both certificates expire after 12 months.
Businesses may also believe that passing Cyber Essentials automatically guarantees a Plus pass. The technical audit can reveal gaps that the self-assessment did not identify.
A practical decision guide
Choose Cyber Essentials when you need a recognised security baseline, want to improve basic controls, face an initial customer requirement, or need an accessible first step.
Choose Cyber Essentials Plus when a contract requires it, customers want technical verification, your organisation handles sensitive information, or stronger supplier assurance provides commercial value.
Begin with accurate scoping in either case. A weak or confusing scope reduces the value of the certificate.
Maintain the controls after certification. Annual renewal should confirm ongoing good practice rather than trigger a last-minute repair project.
Use the process to improve security. The certificate matters, but the reduced exposure to common cyber attacks provides the greatest value.
A readiness checklist for both certificates
Before applying, confirm the following:
All in-scope operating systems and applications receive vendor support.
High-risk and critical vulnerability fixes receive action within 14 days.
Relevant accounts use MFA where available.
Administrator access remains limited and controlled.
Former staff and suppliers no longer retain unnecessary access.
Firewalls protect every device that connects to the internet.
Remote working arrangements meet the controls.
Malware protection operates across applicable devices.
Cloud services appear accurately in the scope.
Personally owned devices receive proper consideration.
Senior management understands the declaration.
Evidence supports the answers.
For Plus, also confirm that systems can pass technical testing across the whole scope, not only on a few selected devices.
Building confidence through the right certificate
Cyber Essentials and Cyber Essentials Plus share the same goal: helping organisations protect themselves from common online attacks.
Cyber Essentials provides assurance through a verified self-assessment. Cyber Essentials Plus adds technical testing by a qualified assessor.
The Plus certificate therefore provides greater assurance, but it does not introduce a separate control framework.
The right route depends on your organisation’s contracts, customers, risk exposure, and assurance needs. Many businesses begin with Cyber Essentials and progress to Plus as customer expectations grow.
UK Cyber Security Group offers an affordable and practical route through both certifications. With clear preparation, accurate scope, and well-maintained controls, businesses can use Cyber Essentials to strengthen security, improve customer confidence, and support future growth.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










