🛡️ NCSC-backed certification scheme

Governance, Compliance & Assurance

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Both certifications prove you meet the UK Government's five baseline technical controls — but they check for it in very different ways. Here's exactly what separates them, real examples of who needs which, and how to decide for your organisation.

📅 Updated September 2026 ⏱️ 9 min read ✍️ Reviewed by the Sophlee Compliance Team

If you've been told your organisation needs "Cyber Essentials" but you're not sure whether that means the standard certificate or Cyber Essentials Plus (CE+), you're not alone — it's one of the most common questions we get asked at Sophlee. The short version: Cyber Essentials is a self-assessed questionnaire verified by an external certification body, while Cyber Essentials Plus adds a hands-on technical audit of your actual systems. Below, we break down exactly what that means in practice.

At A Glance

Cyber Essentials vs Cyber Essentials Plus

Both schemes are run under the UK Government's Cyber Essentials framework, overseen by the National Cyber Security Centre (NCSC) and delivered through accredited certification bodies. The certificate you end up with looks similar — the work behind it doesn't.

CategoryCyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessed questionnaireSelf-assessment plus independent hands-on technical audit
Verified byReviewed & signed off by an accredited assessorVulnerability scans and on-site/remote testing carried out by a qualified assessor
Typical timeframeA few days once the questionnaire is complete1–3 weeks, including scheduling the technical audit
Evidence requiredAnswers to ~70 questions across 5 control areasSame questionnaire, plus live testing of devices, servers and cloud accounts
Best suited toSMEs starting their compliance journey; low-risk supply chain requirementsOrganisations handling sensitive data, bidding for higher-value contracts, or wanting independently verified assurance
RenewalAnnuallyAnnually (Cyber Essentials must be current to renew CE+)
Relative costLower — see current pricingHigher, reflecting the added audit time — see current pricing

Good to know: you can't go straight to Cyber Essentials Plus without a valid, current Cyber Essentials certificate in place first — CE+ builds on and verifies what you've already declared, it doesn't replace it.

The Foundations

The five controls both certifications are built on

Whether you go for Cyber Essentials or Cyber Essentials Plus, you're being assessed against the same five technical control areas defined by the NCSC. CE+ simply checks that they're actually working, rather than taking your word for it.

🧱

Firewalls

Boundary firewalls and internet gateways configured to block unauthorised access.

⚙️

Secure Configuration

Devices and software set up to reduce vulnerabilities — no default passwords, unused accounts removed.

🔑

User Access Control

Accounts only given the access people actually need, with admin rights tightly controlled.

🦠

Malware Protection

Anti-malware software or application allow-listing active across all devices.

🔄

Security Update Management

Operating systems and applications kept patched and up to date, with unsupported software removed.

Decision Guide

Which one does your organisation need?

Choose Cyber Essentials if…

  • This is your first cyber security certification
  • A client or funding body asks for "Cyber Essentials" specifically, not CE+
  • You want a fast, affordable way to demonstrate baseline good practice
  • You're bidding for government contracts that only require the standard certificate
  • You want to build good habits before committing to an independent audit

Choose Cyber Essentials Plus if…

  • You handle personal, financial or sensitive data at scale
  • A contract, insurer or regulator specifically requires independently verified assurance
  • You're bidding for higher-value public sector or defence-adjacent contracts
  • You want genuine confidence your controls work, not just that they're documented
  • You've previously held Cyber Essentials and are ready for the next step

Real-World Examples

Three organisations, three different answers

Education

A 3-school Multi-Academy Trust

The trust needs to evidence basic cyber hygiene for its local authority and cyber insurance renewal, but has a small IT team and a tight budget. Their biggest risk is unpatched laptops and shared admin logins across sites.

Verdict: Start with Cyber Essentials to close the fundamentals quickly and affordably, then plan CE+ once monitoring and asset control mature.

Professional Services

A 40-person accountancy firm

The firm processes client financial data and has been asked by its insurer for "independently verified" cyber controls following a rise in claims across the sector. Staff work from a mix of office and home devices.

Verdict: Cyber Essentials Plus — the hands-on audit gives the insurer (and the firm's clients) real assurance the controls work, not just that they're documented.

Government Supply Chain

A manufacturer bidding for an MOD contract

The tender documentation lists Cyber Essentials Plus as a mandatory requirement before contract award, given the sensitivity of the data the manufacturer will handle as a subcontractor.

Verdict: Cyber Essentials Plus is non-negotiable here — check the tender wording carefully, as many defence and public sector contracts specify CE+ by name.

How It Works

What actually happens during each assessment

1

Questionnaire

You (or Sophlee, on your behalf) complete the Cyber Essentials self-assessment questionnaire covering all five control areas.

2

Review & sign-off

An accredited assessor reviews your answers. Once approved, your Cyber Essentials certificate is issued.

3

Technical audit (CE+ only)

A qualified assessor runs vulnerability scans and hands-on checks against a sample of your devices, servers and cloud accounts.

4

Certificate issued

Once everything passes, your certificate is issued and listed on the IASME/NCSC certification register.

Sophlee holds IASME Assurance status and manages the whole process for you — from the initial questionnaire through to the technical audit — as part of our wider Governance, Compliance & Assurance service.

FAQ

Common questions about Cyber Essentials & CE+

Does Cyber Essentials Plus include Cyber Essentials?

Yes. You must hold a current, valid Cyber Essentials certificate before you can be assessed for Cyber Essentials Plus — CE+ verifies the same five controls, it doesn't replace the underlying certificate.

Can I skip straight to Cyber Essentials Plus?

No. The Cyber Essentials self-assessment must be completed and passed first, typically as part of the same engagement, before the technical audit for CE+ can take place.

How long is a Cyber Essentials or CE+ certificate valid for?

Both certifications last 12 months from the date of issue and must be renewed annually to remain current.

What happens if we fail part of the Cyber Essentials Plus audit?

You'll be given the chance to remediate the specific issue and be retested, rather than starting the whole process again — this is a normal part of most CE+ engagements.

Is Cyber Essentials a legal requirement?

It isn't a general legal requirement, but many government contracts, grant funding bodies, insurers and larger clients now require it (or CE+) as a condition of doing business — always check your specific contract or tender wording.

Do remote and hybrid workers affect which certification we need?

They can. Home working devices and cloud services are in scope for both certifications, and organisations with a lot of remote access often find the CE+ technical audit gives more meaningful assurance than the questionnaire alone.

Not sure which certification fits your organisation?

Tell us a bit about your sector, your contracts and your current setup, and we'll recommend the right starting point — then manage the whole certification process for you.

Let's talk it through

+44 (0) 1785 512210

support@sophlee.com

Contact Sophlee

Reviewed and updated by the Sophlee Compliance Team — September 2026. Certification requirements can change; always check current NCSC/IASME guidance for the latest scheme rules.