Cyber Essentials vs Cyber Essentials Plus

Same five controls, different level of proof. Cyber Essentials is a verified self-assessment: you answer the question set and an assessor reviews your answers. Cyber Essentials Plus adds an independent technical audit: an assessor tests a sample of your devices, scans your systems and verifies the controls actually work. One is a declaration; the other is evidence.

This guide is written by RedSecLabs, an IASME-licensed Certification Body for Cyber Essentials (Plus assessments launching soon, with readiness consultancy available now). It covers exactly what the Plus audit adds, the real cost and time difference under the 2026 rules, and which contracts, insurers and frameworks require which level, so you buy the right one first time.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Which Path Fits Your Contracts?

Tell us what your customers are asking for and we’ll recommend the right sequence, with fixed-fee quotes for both routes.

You’ll get our Danzell readiness checklist by reply. No mailing lists, ever.

5
Same five technical controls at both levels
£320+
Basic certification from (micro, +VAT)
1–3 days
Typical Plus audit duration on site or remote
3 months
Window to complete Plus after basic certification
12 months
Both certificates valid for one year

The difference in one table

 Cyber EssentialsCyber Essentials Plus
How it is verifiedVerified self-assessment questionnaire, reviewed and marked by an assessorIndependent hands-on technical audit of a device sample plus the same questionnaire
What is testedYour answers against the current question setPatch levels, malware defences, browser and email protections, account separation, external vulnerability scan
Typical cost (2026)£320–£600 +VAT by organisation sizeRoughly £1,400–£4,000 +VAT depending on device sample and sites
TimelineDays, driven by how fast you can answer accuratelyAudit booked after basic passes; must complete within 3 months of the basic certificate
Assurance levelYou attest controls are in placeAn assessor has verified controls operate on real devices
Commonly required byMany UK public sector tenders, supply-chain questionnaires, cyber insurance baselinesMOD contracts handling identifiable information, NHS suppliers in many trusts, councils and primes raising the bar

What the Plus audit actually involves

The assessor agrees a sample of your in-scope devices, workstations, laptops, mobile devices and servers, sized to your estate. On each sampled device they verify patching is inside the 14-day window for high and critical updates, malware protection is active and configured, and standard users cannot execute unsigned or untrusted files. They test that your browsers and email clients block known-malicious file types, attempt benign test payloads to confirm defences respond, and run an authenticated check of account separation so day-to-day work is not done with admin rights. An external vulnerability scan of your internet-facing services completes the picture. Fail items can be fixed and re-verified inside the audit window, which is why preparation matters more than perfection on day one.

Under the 2026 requirements (the Danzell question set from 27 April 2026), the same evidence standard applies at both levels, but only Plus checks it on real machines. If your controls genuinely operate, Plus is an inexpensive way to prove it; if they do not, Plus finds out before an attacker does.

Which one do you need?

Choose Cyber Essentials when a contract, framework or insurer simply asks for "Cyber Essentials" with no level specified, when you need a fast, low-cost baseline to unblock a tender, or as the mandatory first step, since Plus always requires a current basic certificate first.

Choose Cyber Essentials Plus when the requirement names it explicitly, MOD DEFCON 658 supply chains, many NHS and local-authority contracts, and a growing set of enterprise procurement checklists, when your customers ask how controls are verified rather than whether they exist, or when you want independent evidence your IT provider has actually done what they report.

Because Plus must be completed within three months of the basic certificate, the cost-efficient route is to plan both together: we certify the basic level, run Plus readiness on your device sample, and schedule the audit inside the window so one project covers the year.

Get the Sequence Right Before Spending

Book a call and we’ll read your actual contract requirements with you, then recommend basic certification now, Plus readiness, or the combined route, priced fixed before you commit.

Cyber Essentials vs Plus: FAQs

Yes. Plus always builds on a current basic certificate, and the audit must be completed within three months of it. The efficient route is to book both as one project so the audit lands inside the window.

No. The Plus audit verifies the five Cyber Essentials controls operate on a sample of real devices, plus an external vulnerability scan. A penetration test goes far deeper and is scoped separately; many organisations do both for different audiences.

Individual fail items can usually be remediated and re-verified within the audit window. Systemic failures, for example patching outside the 14-day window across the estate, mean fixing the process first and re-testing.

Basic certification runs £320–£600 +VAT by organisation size under the 2026 fee tiers. Plus typically adds £1,400–£4,000 +VAT depending on device sample, sites and complexity. Get a fixed quote before committing.

MOD contracts involving identifiable information (DEFCON 658 supply chains), many NHS trusts and local authorities, and a growing set of enterprise procurement checklists name Plus explicitly. If the requirement just says Cyber Essentials, basic satisfies it.

Yes. The Danzell question set applies from 27 April 2026 at both levels; Plus additionally verifies the same requirements on real devices. Certificates issued under Willow remain valid until their expiry.
📞 Call us Book a call