It looks like you're visiting from the United States. Would you like to view our US site?

Visit US site
.

Certified vs Verified: Cyber Essentials vs Cyber Essentials Plus

Most UK organisations have heard of Cyber Essentials by now. It comes up in tender documents, insurance renewals and supplier onboarding packs, and for a lot of businesses it has quietly become part of the cost of doing business. What has changed recently is the question people are asking. It is no longer "should we get certified?" but something more specific: do we need the base certification, or do we need Plus? If you are weighing up Cyber Essentials vs Cyber Essentials Plus, this blog is designed to help you make that call with confidence rather than guesswork.

The starting point is a fact that surprises a lot of people. Both certifications assess exactly the same five technical controls. Neither one asks you to put additional security measures in place. What separates them is how your compliance is checked, and by whom.

That single distinction carries real commercial weight. It drives the difference in cost, the scope of the assessment, the time it takes and, crucially, what the certificate signals to clients, insurers and supply chain partners. It matters more than it used to, because the pressure is building. Public sector contracts, Ministry of Defence and NHS supply chains and a growing number of large private sector organisations are now specifying Cyber Essentials Plus by name. Turning up with the base certificate when the buyer wanted Plus is an expensive mistake to make halfway through a tender.

Over the next few sections we will cover the core difference between the two certifications, how each assessment actually works in practice, what they cost, the return on the investment, and a straightforward decision framework for choosing the right level for your organisation.

The same controls, two different levels of assurance

Both Cyber Essentials and Cyber Essentials Plus are built on the same five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. There is no extended control set for Plus, no additional policies to write and no separate standard to meet. If you can pass Cyber Essentials, you already have the building blocks for Plus.

We have covered those five controls in detail elsewhere, so if you want a full breakdown of each one, start with our practical guide to what is Cyber Essentials and come back to this piece for the comparison.

The defining difference is not what is assessed. It is how.

Cyber Essentials is a verified self-assessment. You answer a structured questionnaire, declare that your controls are in place, and a qualified assessor reviews what you have submitted.

Cyber Essentials Plus is independently tested. A qualified assessor gets hands on with your systems and verifies that those controls genuinely work in practice, not just on paper.

There is one nuance worth flagging, because it catches organisations out. IASME sets the pass bar slightly higher for Plus. Minor non-compliances that would be accepted at the Cyber Essentials level need to be remediated before a Plus certificate can be issued. Passing Cyber Essentials is not a guarantee that you would sail through the Plus audit tomorrow.

Cyber Essentials vs Cyber Essentials Plus at a glance

Cyber Essentials

Cyber Essentials Plus

Assessment method

Online self-assessment questionnaire

Hands-on technical audit, on-site or remote

Who reviews it

Qualified assessor reviews your submission

Qualified assessor tests your systems directly

Pass bar

Minor non-compliances may be accepted

Higher bar, non-compliances must be remediated

Prerequisite

None

Valid Cyber Essentials certificate, achieved within the last three months

Indicative cost

Lower, questionnaire based

Higher, includes booked assessor time and testing

Typical timeline

Days for a well-prepared organisation

Three to six weeks for the combined journey

Level of assurance

Self-declared, verified

Independently tested and evidenced

Validity

12 months

12 months

How each assessment actually works

Cyber Essentials: the verified self-assessment

The process is straightforward, but it rewards preparation.

You begin by defining the scope of the assessment, deciding which parts of your organisation, networks and devices are included. You then complete a structured online questionnaire covering your IT infrastructure and how you meet each of the five controls.

Before submission, a senior board-level representative has to sign to confirm that the answers are accurate. This is not a formality. It puts accountability for the declaration at the top of the organisation.

A qualified assessor from an IASME Certification Body, such as Consider IT, then reviews your submission. They may come back with questions, ask for clarification or request supporting evidence. Once the requirements are satisfied, your certificate is issued. For an organisation that has done the groundwork, this can happen within days.

The groundwork is the part that makes the difference. A readiness or gap assessment beforehand will tell you where your control gaps sit while you still have time to close them, and it significantly improves first-time pass rates. Our free Cyber Security Health Assessment is built for exactly that purpose.

Cyber Essentials Plus: the independent technical audit

Cyber Essentials Plus is not a standalone certification. You must hold a valid Cyber Essentials certificate first, and the Plus audit has to take place within three months of achieving it. Miss that window and you are back to the beginning.

The audit itself is conducted by a qualified assessor, either on-site or remotely, and typically includes:

  • External vulnerability scanning of your internet-facing IP addresses and systems

  • Sample device testing across a representative selection of in-scope devices, covering each operating system type in use, including desktops, laptops, servers, tablets and mobile phones

  • Malware protection checks, including test files sent by email and downloaded through a web browser to observe exactly how your systems respond

  • Account privilege testing to confirm that users cannot carry out administrator functions from a standard account

  • Multi-factor authentication verification across your cloud services, for both standard and administrator accounts, confirming that MFA is genuinely enforced rather than simply claimed

  • Patching checks, verifying that high and critical severity patches have been applied within 14 days of release

If the assessor identifies any non-compliance, you have 30 days to remediate it before reassessment. Complete the audit successfully and you hold Cyber Essentials Plus, the highest level of assurance within the scheme.

What does Cyber Essentials vs Cyber Essentials Plus cost?

Pricing varies by organisation size and by certification body, so treat the figures below as a guide. For an accurate quote tailored to your business, just ask.

The cost structure follows the assessment method. Cyber Essentials is the lower-cost option because it is primarily questionnaire based. Cyber Essentials Plus costs more because it involves booked assessor time, technical scanning and device testing, and the price scales with the number and variety of devices in scope.

Organisation size

Cyber Essentials

Cyber Essentials Plus

Micro (under 10 employees)

£320£

£1,499

Small (under 50 employees)

£440

£1,999

Medium (under 250 employees)

£500

£2,499

Large (over 250 employees)

£600

Scoped individually

Consider IT certification pricing, correct at the time of writing and exclusive of VAT. Larger organisations are quoted individually because the scope of the Plus audit varies with the number and range of devices in use.

If you are pursuing Plus, budget for both certifications. You cannot buy Plus in isolation.

There is a third line to consider, and it is the one that most often determines whether the first attempt succeeds. Certification fees cover the assessment itself, not the work of getting ready for it. If your team is confident that the five controls are already in place, you can go straight to certification. If you would rather have someone walk you through it, our guided support option covers help completing the self-assessment questionnaire, a pre-audit walkthrough before the Plus assessment, and free rescans where they are needed. For organisations without a dedicated internal security resource, it is usually money well spent.

Two further costs are routinely overlooked. The first is remediation. If the gap assessment uncovers unsupported software, inconsistent patching or missing MFA, fixing those things has a cost in licences, hardware or engineering time, and it is often larger than the certification fee itself. The second is re-assessment. If a submission does not pass first time, many certification bodies charge again. We do not. Free retests after remediation are included at both levels.

Worth weighing on the other side of the ledger: eligible UK organisations with turnover under £20 million get cyber liability insurance included as part of the certification fee. It is a genuine benefit built into the price rather than an add-on, and it is one that many organisations do not realise they are already paying for.

The business case: why the investment pays off

The numbers behind the scheme make the argument fairly comfortably.

Organisations holding Cyber Essentials certification are 95% less likely to make a cyber insurance claim. That is a substantial reduction in real-world risk, and it explains why so many insurers now factor certification directly into their underwriting decisions and premiums.

80% of common cyber breaches are preventable through the basic controls that both certifications cover. The NCSC is explicit that the scheme is designed to stop high-volume, low-sophistication attacks, which is precisely the category most SMEs actually face.

69% of certified businesses report that certification makes them more competitive, particularly in procurement and tender situations where buyers are actively asking for it.

For Cyber Essentials Plus specifically, there is an additional layer of return. Independent verification cuts down the time your team spends completing client security questionnaires, because you can point to an audited certificate instead of writing another 40-page response. It strengthens your position in competitive tenders. And it satisfies enterprise and public sector buyers who have stopped accepting self-declaration as sufficient evidence.

This is a return that compounds. Certification runs on an annual cycle, so each renewal adds another year to a verifiable track record of security compliance. Three years in, that record becomes a genuine differentiator in due diligence.

When to choose Cyber Essentials and when to go Plus

Choose Cyber Essentials if:

  • Clients or contracts ask for "Cyber Essentials" without specifying Plus

  • You are bidding for general public sector work where the base certification satisfies the requirement

  • You are new to formal cyber security certification and want to establish a solid foundation first

  • You want a cost-effective, government-backed baseline that demonstrates good cyber hygiene to clients and insurers

  • You want to qualify for the cyber liability insurance included with certification, if eligible

Choose Cyber Essentials Plus if:

  • A client, contract or procurement framework explicitly requires Plus

  • You supply the Ministry of Defence, the NHS or other regulated public sector bodies

  • You sit in a supply chain where a major organisation mandates CE+ from its partners

  • You handle sensitive personal data, financial records or confidential client information and need independent assurance rather than self-declaration

  • You want the strongest possible third-party validation for enterprise procurement, due diligence or tenders

If you are not sure which level your clients or contracts actually require, do not guess and do not over-buy. We can help you identify the right scope and level before you commit any budget. Get in touch and we will talk it through.

Who is mandating Cyber Essentials Plus?

The requirement landscape has shifted noticeably over the past few years.

All UK Government contracts that involve handling personal data require at least Cyber Essentials as a baseline. That is a formal procurement requirement, not a preference, and it applies across Public Sector IT Services suppliers of every size.

Defence sector contracts frequently go further and mandate Cyber Essentials Plus, with the MOD increasingly specifying it across multiple tiers of its supply chain rather than just at prime contractor level.

NHS and wider health sector supply chains are moving in the same direction, particularly for suppliers handling clinical or patient data.

Large private sector organisations are following. St. James's Place is a well-known example, having mandated Cyber Essentials Plus across a partner network of more than 2,800 businesses. When a decision like that is made at the top of a supply chain, it lands on hundreds of SMEs at once, usually with a deadline attached.

We see this most acutely in legal, financial services, utilities, energy and professional services, where client due diligence is already rigorous and where a single failed security review can cost a long-standing relationship.

The direction of travel is clear. What was a differentiator five years ago is becoming a baseline expectation, especially at supply chain level. Getting ahead of that now is considerably less disruptive than scrambling to meet a requirement that appears in a contract renewal with six weeks' notice.

From assessment to certificate: what to expect on the timeline

Cyber Essentials. From initial gap assessment to certificate in hand, a well-prepared organisation can typically achieve certification within a matter of days. Where gaps exist, add remediation time. That is the variable that determines everything else.

Cyber Essentials Plus. Allow additional time. The Plus audit needs to be booked with an assessor and must be completed within three months of your Cyber Essentials certification. End to end, a combined Cyber Essentials and Cyber Essentials Plus journey usually takes between three and six weeks, depending on how much remediation is required and how quickly the audit can be scheduled.

The recommended sequence is:

  1. Gap assessment

  2. Remediation

  3. Cyber Essentials submission and certification

  4. Cyber Essentials Plus audit, within three months

  5. Cyber Essentials Plus certification

Both certifications run on a 12-month cycle and must be renewed annually. Plan for it as a recurring operational commitment rather than a one-off project, and build the renewal date into your compliance calendar the day you certify.

Why choose Consider IT for Cyber Essentials and Cyber Essentials Plus?

We are an NCSC Assured Service Provider, an IASME Certifying Body and a CREST member. That combination means we are qualified and licensed to certify you at both levels, not simply to guide you towards someone else who can.

We are also Cyber Essentials Plus certified ourselves, so we operate to the same standard we help our clients meet. Alongside that we hold ISO 27001 for information security, ISO 22301 for business continuity, ISO 9001, ISO 14001 and ISO 20000-1, and we are members of the UK Cyber Security Council. For buyers running due diligence on their own suppliers, that matters: the organisation certifying you has been independently audited too.

For Plus, our technical team carries out vulnerability and penetration testing against external firewalls, internet gateways and a sample of workstations. It is an expert-led assessment rather than a box-ticking exercise, and where we find something, we explain what it means and how to fix it.

What clients tell us makes the difference:

  • End-to-end guidance, from initial scoping through to the certificate being issued

  • Practical help interpreting and completing the assessment questionnaire

  • Support identifying and resolving control gaps before submission, not after a failure

  • Free re-tests if certification is not achieved first time

We work across Scotland and the wider UK from our Edinburgh, Glasgow and London offices, with the kind of local, responsive support that suits SMEs, professional services firms and regulated sector organisations. If you want to see the full picture of what we offer, our Cyber Essentials Services page sets it out.

Start your Cyber Essentials journey today

To bring it back to the core distinction: when you compare Cyber Essentials vs Cyber Essentials Plus, you are not comparing two different security standards. Both cover the same five technical controls. The difference is whether your compliance is self-declared or independently verified by a qualified assessor, and that single distinction is what drives the difference in cost, assessment scope and the assurance value your certificate carries with clients, insurers and supply chain partners.

Neither certification is a permanent fix. Both require annual renewal, and both work best as part of a broader, proactive approach to cyber security rather than as a badge collected once and forgotten.

The right choice depends on your clients, your contracts, your sector and your appetite for risk. If you are not sure where to begin, begin with a clear and honest picture of where your organisation stands today.

Take our free Cyber Security Health Assessment to understand your current position before you start the certification process.

Or get in touch and we will help you work out which level is right for your business.

  • Posted on: August 25th, 2026

Share this on social media

© 2026 Consider IT Limited – All Rights Reserved
Registered office: Waterview House, 37 Shore, Edinburgh, EH6 6QU. Company Number: SC320341 | VAT number: GB 930 1862 42
Consider IT is a trading name of Consider IT Limited