Governance, Compliance & Assurance
Cyber Essentials vs Cyber Essentials Plus: What's the Difference?
Both certifications prove you meet the UK Government's five baseline technical controls — but they check for it in very different ways. Here's exactly what separates them, real examples of who needs which, and how to decide for your organisation.
If you've been told your organisation needs "Cyber Essentials" but you're not sure whether that means the standard certificate or Cyber Essentials Plus (CE+), you're not alone — it's one of the most common questions we get asked at Sophlee. The short version: Cyber Essentials is a self-assessed questionnaire verified by an external certification body, while Cyber Essentials Plus adds a hands-on technical audit of your actual systems. Below, we break down exactly what that means in practice.
At A Glance
Cyber Essentials vs Cyber Essentials Plus
Both schemes are run under the UK Government's Cyber Essentials framework, overseen by the National Cyber Security Centre (NCSC) and delivered through accredited certification bodies. The certificate you end up with looks similar — the work behind it doesn't.
| Category | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessed questionnaire | Self-assessment plus independent hands-on technical audit |
| Verified by | Reviewed & signed off by an accredited assessor | Vulnerability scans and on-site/remote testing carried out by a qualified assessor |
| Typical timeframe | A few days once the questionnaire is complete | 1–3 weeks, including scheduling the technical audit |
| Evidence required | Answers to ~70 questions across 5 control areas | Same questionnaire, plus live testing of devices, servers and cloud accounts |
| Best suited to | SMEs starting their compliance journey; low-risk supply chain requirements | Organisations handling sensitive data, bidding for higher-value contracts, or wanting independently verified assurance |
| Renewal | Annually | Annually (Cyber Essentials must be current to renew CE+) |
| Relative cost | Lower — see current pricing | Higher, reflecting the added audit time — see current pricing |
Good to know: you can't go straight to Cyber Essentials Plus without a valid, current Cyber Essentials certificate in place first — CE+ builds on and verifies what you've already declared, it doesn't replace it.
The Foundations
The five controls both certifications are built on
Whether you go for Cyber Essentials or Cyber Essentials Plus, you're being assessed against the same five technical control areas defined by the NCSC. CE+ simply checks that they're actually working, rather than taking your word for it.
Firewalls
Boundary firewalls and internet gateways configured to block unauthorised access.
Secure Configuration
Devices and software set up to reduce vulnerabilities — no default passwords, unused accounts removed.
User Access Control
Accounts only given the access people actually need, with admin rights tightly controlled.
Malware Protection
Anti-malware software or application allow-listing active across all devices.
Security Update Management
Operating systems and applications kept patched and up to date, with unsupported software removed.
Decision Guide
Which one does your organisation need?
Choose Cyber Essentials if…
- This is your first cyber security certification
- A client or funding body asks for "Cyber Essentials" specifically, not CE+
- You want a fast, affordable way to demonstrate baseline good practice
- You're bidding for government contracts that only require the standard certificate
- You want to build good habits before committing to an independent audit
Choose Cyber Essentials Plus if…
- You handle personal, financial or sensitive data at scale
- A contract, insurer or regulator specifically requires independently verified assurance
- You're bidding for higher-value public sector or defence-adjacent contracts
- You want genuine confidence your controls work, not just that they're documented
- You've previously held Cyber Essentials and are ready for the next step
Real-World Examples
Three organisations, three different answers
A 3-school Multi-Academy Trust
The trust needs to evidence basic cyber hygiene for its local authority and cyber insurance renewal, but has a small IT team and a tight budget. Their biggest risk is unpatched laptops and shared admin logins across sites.
Verdict: Start with Cyber Essentials to close the fundamentals quickly and affordably, then plan CE+ once monitoring and asset control mature.
A 40-person accountancy firm
The firm processes client financial data and has been asked by its insurer for "independently verified" cyber controls following a rise in claims across the sector. Staff work from a mix of office and home devices.
Verdict: Cyber Essentials Plus — the hands-on audit gives the insurer (and the firm's clients) real assurance the controls work, not just that they're documented.
A manufacturer bidding for an MOD contract
The tender documentation lists Cyber Essentials Plus as a mandatory requirement before contract award, given the sensitivity of the data the manufacturer will handle as a subcontractor.
Verdict: Cyber Essentials Plus is non-negotiable here — check the tender wording carefully, as many defence and public sector contracts specify CE+ by name.
How It Works
What actually happens during each assessment
Questionnaire
You (or Sophlee, on your behalf) complete the Cyber Essentials self-assessment questionnaire covering all five control areas.
Review & sign-off
An accredited assessor reviews your answers. Once approved, your Cyber Essentials certificate is issued.
Technical audit (CE+ only)
A qualified assessor runs vulnerability scans and hands-on checks against a sample of your devices, servers and cloud accounts.
Certificate issued
Once everything passes, your certificate is issued and listed on the IASME/NCSC certification register.
Sophlee holds IASME Assurance status and manages the whole process for you — from the initial questionnaire through to the technical audit — as part of our wider Governance, Compliance & Assurance service.
FAQ
Common questions about Cyber Essentials & CE+
Does Cyber Essentials Plus include Cyber Essentials?
Yes. You must hold a current, valid Cyber Essentials certificate before you can be assessed for Cyber Essentials Plus — CE+ verifies the same five controls, it doesn't replace the underlying certificate.
Can I skip straight to Cyber Essentials Plus?
No. The Cyber Essentials self-assessment must be completed and passed first, typically as part of the same engagement, before the technical audit for CE+ can take place.
How long is a Cyber Essentials or CE+ certificate valid for?
Both certifications last 12 months from the date of issue and must be renewed annually to remain current.
What happens if we fail part of the Cyber Essentials Plus audit?
You'll be given the chance to remediate the specific issue and be retested, rather than starting the whole process again — this is a normal part of most CE+ engagements.
Is Cyber Essentials a legal requirement?
It isn't a general legal requirement, but many government contracts, grant funding bodies, insurers and larger clients now require it (or CE+) as a condition of doing business — always check your specific contract or tender wording.
Do remote and hybrid workers affect which certification we need?
They can. Home working devices and cloud services are in scope for both certifications, and organisations with a lot of remote access often find the CE+ technical audit gives more meaningful assurance than the questionnaire alone.
Not sure which certification fits your organisation?
Tell us a bit about your sector, your contracts and your current setup, and we'll recommend the right starting point — then manage the whole certification process for you.
Reviewed and updated by the Sophlee Compliance Team — September 2026. Certification requirements can change; always check current NCSC/IASME guidance for the latest scheme rules.