Cyber Essentials vs Cyber Essentials Plus: which do you need?
Both test the same five controls. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent hands-on technical audit. Here's how to choose.

Cyber Essentials comes in two levels, and the choice between them trips people up because the technical requirements are exactly the same. Both certify the five Cyber Essentials controls. What differs is how thoroughly your claims are checked, and that difference is the whole point. If you're new to the scheme, start with what Cyber Essentials is; if you already know that, here's how to pick a level.
The difference in one line
- Cyber Essentials is a verified self-assessment. You complete a questionnaire, and an IASME-licensed certification body reviews your answers before issuing the certificate.
- Cyber Essentials Plus is the same self-assessment plus an independent technical audit. A qualified assessor tests a sample of your actual systems and devices to confirm the controls are genuinely in place.
Cyber Essentials asks you to state that the controls are implemented. Cyber Essentials Plus has someone check.
What the Plus audit actually involves
The Plus audit is hands-on, not paperwork. An assessor typically:
- samples a representative set of devices and reviews their configuration, patch levels and malware protection first-hand,
- runs vulnerability scans against your internet-facing services and a sample of end-user devices,
- tests that your controls behave as claimed, for example that a device really does block a malicious file or that updates are being applied in practice.
Because it's evidence-led, Plus also carries a higher pass bar. On the self-assessed Cyber Essentials, an organisation can sometimes still certify with a minor non-compliance. On Plus, anything the assessor finds has to be remediated (usually within 30 days) before you can pass. Same controls, stricter proof.
They build on each other
Plus isn't a separate track; it builds on the self-assessment. In practice you complete the Cyber Essentials questionnaire first, then the technical audit follows, normally within a few months. Both certificates are valid for 12 months, so whichever level you choose, it's an annual cycle.
Which one should you get?
It usually comes down to who is asking and why:
- Choose Cyber Essentials if you need a recognised baseline quickly, want to satisfy a customer's basic security question, or are meeting a contract that specifies Cyber Essentials without the Plus. It's faster and cheaper.
- Choose Cyber Essentials Plus if a government contract or an enterprise customer specifically requires it, if you want independent proof rather than self-declared assurance, or if you're using the certificate as serious evidence of due diligence, for example to a regulator or an insurer.
On that last point: some cyber insurers treat Plus more favourably, because an independent audit is stronger evidence that your controls work. It can smooth premiums and reduce the risk of a claim being disputed on the grounds that a control wasn't really in place.
A sensible pattern for many organisations is to do Cyber Essentials first to get certified and unblock immediate requirements, then move to Plus when a contract demands it or when you want the stronger assurance. Just don't assume the basic self-assessment will satisfy a buyer who has asked for Plus by name; they've asked for the audit for a reason.
The constant either way
Whichever level you pick, the certificate only reflects controls that are actually true across your scope, and Plus will find the gaps between what you claimed and what's really configured. That's easier to survive when the controls are maintained continuously rather than reconstructed before each audit. ResiliencePilot keeps them current and evidenced year-round. See the Cyber Essentials solution, the Cyber Essentials hub, or book a demo.