Cyber Essentials and Cyber Essentials Plus assess exactly the same five controls. The difference is not what is required of you — it is who checks, and how. One is a self-assessment that an assessor marks; the other adds a technical audit of your actual machines. Here is the comparison in full, followed by what that difference is worth to a buyer looking at your certificate.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Controls assessed | The same five | The same five |
| How it is verified | Verified self-assessment — you answer, an assessor marks | Self-assessment plus hands-on technical audit |
| Vulnerability scan | None at this level | Internal and external scans |
| Device testing | None | Random sample, typically around 10% of in-scope systems |
| Independent declaration | A board member signs that answers are true | Assessor verifies against the live estate |
| Assessment fee | Published: £320–£600 + VAT by organisation size | Quoted individually |
| Validity | 12 months | 12 months |
| Typical use | Meets many procurement thresholds | Required where a contract specifies audited assurance |
What is Cyber Essentials?
Cyber Essentials is the UK government's baseline cyber security certification, owned by the NCSC and delivered by IASME as its official delivery partner. It certifies that five technical controls are in place: firewalls, secure configuration, security update management, user access control, and malware protection.
At the base level it is a verified self-assessment. You complete a question set about how your organisation is configured, a board member signs a declaration that the answers are true, and a qualified assessor marks the submission. There is no scan and nobody looks at your estate. That sounds weak until you notice the two things holding it up: you need to be compliant on nearly all questions to pass, and unsupported software anywhere in scope is an automatic fail rather than a finding.
What is Cyber Essentials Plus?
Cyber Essentials Plus starts from that same question set and adds a technical audit. IASME defines the audited estate as three things: a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users. Against that, an assessor runs internal and external vulnerability scans and tests a random sample of systems — IASME puts this at typically around 10 per cent — then decides whether more testing is needed.
That last clause matters. A messy sample expands the audit rather than concluding it.
The audit can be run remotely or in person, at the certification body's discretion.
The sequencing rule that saves you money
The Cyber Essentials question set is part of the Plus process. If you achieved the verified self-assessment less than three months before certifying to Plus, you do not repeat the questionnaire stage.
Leave it longer and you complete — and pay for — that work twice. If you know you need Plus, plan both as a single project rather than as two events a year apart.
Which one do you actually need?
You need the base certificate if a customer or contract asks for "Cyber Essentials" without qualification, or you want a defensible security floor with modest effort. It is sufficient for a large share of UK public sector procurement thresholds.
You need Plus if a contract specifically says so. That is genuinely the main driver, and it is worth reading the requirement carefully rather than assuming — the two are frequently conflated in supplier questionnaires, including by the people sending them.
You should consider Plus anyway if your estate is complex enough that you are not confident your self-assessment answers are true. The audit finds the gap between what an organisation believes about itself and what is running. Most organisations that fail Plus fail on something they sincerely believed was in place.
What the difference means when you are the buyer
If you are on the receiving end of a certificate from a supplier, the distinction is the whole point — and it is routinely over-read in both directions.
A base certificate is a self-declaration that an assessor marked, backed by a board member's signature. That is meaningful. It is not evidence that anybody tested anything.
A Plus certificate is evidence that a qualified assessor scanned and sampled a real estate on a specific day.
Neither tells you what you probably want to know, which is four things the certificate does not state:
- What was in scope. A company can certify a defined sub-network, and the system you are buying may sit outside it. Ask for the scope statement, not the certificate.
- When it was issued. Both levels last 12 months, and IASME delists organisations that have not certified within the year.
- Which level it is. They look similar and are described interchangeably far too often.
- What has changed since. The certificate describes one day. Nothing in the scheme watches the supplier for the following 364.
That last point is not a criticism of the scheme — annual point-in-time certification is doing exactly what it was designed to do. It is an argument that a certificate is a floor in your supplier assessment rather than the conclusion of it.
Cost, briefly
The base assessment fee is published by IASME and banded by organisation size: £320 + VAT for micro organisations (0–9 staff), £440 + VAT for small (10–49), £500 + VAT for medium (50–249) and £600 + VAT for large (250+). Plus has no published price because the audit consumes assessor time that scales with the size and complexity of your network — IASME will return quotes from three certification bodies.
Both are annually renewable, and renewal is a fresh assessment at the same band rather than a discounted administrative step.
Fees verified against IASME on 23 August 2026.
The short version
Same controls, same question set, same 12-month validity, same automatic-fail rule on unsupported software. Plus adds scanning and sampling, costs more, and produces assurance somebody else checked. If a contract names it, you need it. If you are reading a supplier's certificate, ask for the scope statement and the date before you decide what it proves.
