Somewhere between the tender document and the insurance renewal, the question sharpens: is Cyber Essentials enough, or do we need Plus? The two certifications share a name, a logo family and the same five technical controls, which makes the difference easy to misjudge in both directions. Businesses buy Plus they did not need at three times the cost; businesses bid with basic certification and discover the contract specified Plus in a clause nobody read.
The distinction is actually clean, and it is about evidence, not standards. Here is the comparison that settles which one your business needs.
The same standard, verified differently
Both certifications assess your business against the identical five controls: firewalls, secure configuration, user access control, malware protection and security update management (the current Danzell question set applies to both; our Cyber Essentials checklist walks through each control).
The difference is who checks, and how:
Cyber Essentials (basic)
A verified self-assessment. Your business answers the questionnaire, a board member signs that the answers are true, and a licensed assessor reviews what you have written. Nobody tests your systems directly; the certification rests on your declared answers surviving expert scrutiny. Turnaround after submission is typically days.
Cyber Essentials Plus
The same questionnaire, plus an independent technical audit. An assessor tests a sample of your systems directly: authenticated vulnerability scans of representative devices, checks that malware protection actually blocks test files, that email and browser defences stop the standard attack file types, and that the controls you declared are demonstrably operating. It is hands-on verification, scheduled with your business, and it must be completed within three months of passing basic Cyber Essentials, which is a prerequisite.
The one-line version: basic certifies what you say; Plus certifies what an auditor saw.
Cost and effort compared
Cyber Essentials: the IASME assessment fee is banded by organisation size, from around £300 +VAT for micro businesses to £500 to £600 +VAT for large ones. With systems already in shape, the effort is mostly careful form-filling.
Cyber Essentials Plus: the basic fee, plus an audit priced by device count: typically £1,500 to £2,500 +VAT for smaller estates (up to about 20 devices), rising with scale. Effort is higher too: audit scheduling, assessor access to sample machines, and fixing anything the scan finds within the audit window.
Preparation costs are where the real budget lives for both, and they depend on your starting point rather than the certification level; our Cyber Essentials cost guide breaks down realistic first-year totals.
Timescales follow the same pattern: a prepared business can hold basic certification within two to three weeks, while Plus projects typically run twelve to sixteen weeks end to end, dominated by preparation and audit logistics.
Which one do you actually need?
Work from the demand, not the brochure:
Basic Cyber Essentials satisfies: most private-sector supplier questionnaires, the general run of insurer requirements, many public-sector contracts, and every “show us you take security seriously” conversation. It is the sensible default first certification for a small business, and for many it is all that is ever demanded.
Plus is specified by: the MOD supply chain (broadly mandatory), a growing share of central and local government tenders, NHS-adjacent work, some regulated-sector clients, and prime contractors pushing their own obligations downstream. The pattern to notice: the closer your customers are to government or critical infrastructure, the more likely the word “Plus” appears in the requirement.
Choose Plus without being asked when: certification is partly a marketing asset in a security-sensitive market (an audited badge simply argues better), or when you want independent confirmation that your controls genuinely operate rather than merely exist on paper. That second reason is underrated: the Plus audit is the cheapest competent penetration of your defences you will ever commission.
If no current contract demands Plus, the pragmatic route is: certify basic now, structured so the Plus audit can bolt on within the three-month window if a tender lands. That sequencing costs nothing extra and removes the panic scenario where a Plus requirement arrives with a six-week deadline.
The mistakes we see
Three recurring ones. Businesses buying Plus for credibility nobody asked for, at 3 to 5 times the cost, when basic would have ticked every live requirement. Businesses missing the three-month rule and having to re-do basic certification before the Plus audit. And businesses treating either certificate as the finish line: both expire after twelve months, requirements evolve (the current question set is stricter on MFA than its predecessor), and the renewal scramble is a fixture of Februaries everywhere. Our certification support exists mostly to delete that scramble.
Frequently asked questions
Is Cyber Essentials Plus a different standard from Cyber Essentials?
No; identical controls and question set. Plus adds independent technical testing (vulnerability scans, malware and email defence checks on sampled devices) instead of relying on verified self-assessment alone.
Do I need Cyber Essentials before Cyber Essentials Plus?
Yes. Basic certification is the prerequisite, and the Plus audit must complete within three months of it. Planned as one project, the sequence is painless; discovered late, it adds weeks.
How much more does Plus cost?
The audit adds roughly £1,500 to £2,500 +VAT for small estates on top of the banded basic fee, scaling with device count. Preparation costs depend on your systems, not the level.
Which certification do government tenders require?
It varies by contract: many accept basic, an increasing number (and most MOD work) specify Plus. Read the requirement precisely, and check whether it must be held at bid time or by contract start; that difference decides your timeline.
Does Cyber Essentials Plus involve a penetration test?
Not a full penetration test: it is a defined audit of the five controls, including vulnerability scanning of sampled devices and tests of malware and email defences. Narrower than a pen test, but genuinely hands-on, and it does fail businesses whose paperwork was optimistic.
Which one do insurers want?
Most insurer questionnaires are satisfied by basic certification today, though requirements are tightening year on year. Check your renewal terms; where a policy names Plus, that is the answer.
Settle it against your actual contracts
The right level is written in your customers’ requirements, your tender pipeline and your insurance terms, and reading those against the certification rules takes us about an hour. Our free IT health check includes that review plus an audit of how far your systems are from either certification, with fixed prices for the gap. Get in touch with the tender or questionnaire in hand, and we will tell you exactly which box it needs ticked.