Cyber Essentials or Cyber Essentials Plus?
The two are not alternatives, and the difference is not how secure you have to be. It is who checks — and under the current scheme, the checking got noticeably harder to game.
Organisations usually meet this question because a contract or a funder has asked for one of them and nobody is quite sure which. The good news is that the underlying security requirements are the same. The difference is entirely in the verification.
The short version
Cyber Essentials is a self-assessment. You answer the question set about how your organisation is configured, a senior person signs to confirm it is accurate, and a qualified assessor at a certification body marks the answers.
Cyber Essentials Plus takes the same requirements and adds an independent technical audit. An assessor examines a sample of your actual devices and systems to verify that what you said is true — vulnerability scanning, checking patch levels, testing malware protection and confirming account configuration.
Plus is not a replacement for the base certification — it builds on it. You need a valid Cyber Essentials certification in place first, and the Plus audit follows within a defined window after it. Treat the two as one sequence with a deadline in the middle rather than as two separate decisions.
What changed for Plus under the current scheme
The 2026 update was prompted partly by evidence that some larger organisations were using workarounds to get through Plus. Two of those routes have been closed.
Selective updating. It was possible to bring just the devices likely to be sampled fully up to date shortly before the audit, leaving the rest of the estate behind. Update management compliance now involves a second sampling stage, which makes patching the sample rather than the estate a much less reliable strategy.
Changing answers after the fact. Amending self-assessment answers once the audit had revealed a problem has also been tightened. The self-assessment is now expected to be an accurate account at the point it was signed, not a draft to be reconciled later.
Alongside this, the director declaration requirement was strengthened. The practical implication is straightforward: the person signing is confirming something they should have verified, not something they hope is true.
Plus is now much closer to what it always claimed to be — a check that the whole estate genuinely meets the standard. If your organisation was planning to tidy up a representative laptop the week before the assessor visits, that plan no longer works. Remediate the estate, then book the audit.
What the Plus audit involves
The assessor works with a representative sample of your in-scope devices rather than every machine, with the sample scaling to the size and variety of your estate. Broadly they will scan devices for known vulnerabilities and check that missing patches are within the required window, test that malware protection behaves as claimed, verify account separation and control of administrative privilege, and check cloud service configuration against what was declared.
This is why the base certification has to be right first. If the self-assessment described a state of affairs that does not exist on the machines, the audit finds it — and the routes previously used to smooth that over have narrowed.
Who actually needs Plus
Most organisations do not. Plus is typically required where you are handling other people's sensitive data or working somewhere the assurance bar is set higher — certain public sector and defence supply chain contracts, some NHS and health-related work, some insurers as a condition of cyber cover, and a growing number of larger corporates imposing it on suppliers who touch their systems or data. That last category is expanding, partly because the NCSC has been actively encouraging large companies to build Cyber Essentials into their supply chains.
The practical answer is almost always written down somewhere. Read the contract clause, the tender document or the funding condition and see which one it names. If it says Cyber Essentials, the base certification is what is being asked for, and certifying to Plus voluntarily is a business decision rather than a requirement.
If you are bidding for work that might require Plus, find out before you bid rather than after you win. Both certifications take time, they happen in sequence, and an audit cannot be conjured up in the week before a contract start date.
Cost and effort
The base certification carries an assessment fee set by the certification body and scaled to organisation size, plus whatever remediation you need — which for most small organisations is configuration time rather than new equipment.
Plus costs materially more, because it involves an assessor's time carrying out the audit, and the fee varies with the size and complexity of the estate rather than being a flat figure. Get a quote based on your actual device numbers rather than working from a headline price.
The bigger difference is effort. The self-assessment can largely be done from a desk. Plus requires devices to be made available, people to be around, and the estate to be genuinely in the state you described.
Both last twelve months
Certification is annual. That matters for two reasons: an organisation that certifies once and forgets will find its certificate has quietly expired the week a customer asks for it, and the requirements themselves change between scheme years — the current question set is stricter than the one it replaced, and the next may be stricter again. Diarise the renewal at the point you certify, and check what has changed before you start it.
How to decide
Read what has actually been asked for. If nothing has been asked for and you are certifying because it is sensible — for the discipline, for insurance, or to be ready when a customer asks — the base certification is almost always the right starting point. It delivers the same five controls, and it is the foundation Plus is built on anyway.
If a contract does specify Plus, plan backwards from the date you need it: the audit, the base certification before that, remediation across the whole estate before that, and the scoping decision before all of it. Our guide to why applications fail covers what that remediation usually involves.
Not sure which one your contract is asking for?
Send us the clause. We will tell you which certification it requires, what it would take in your case, and whether it is realistic in the time you have — no charge for that conversation.
Take the free readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Scheme requirements, fees and audit arrangements are set by the NCSC and IASME and are reviewed periodically. This guide reflects the Danzell question set and version 3.3 of the Requirements for IT Infrastructure. Confirm the current requirements and fees for the year in which you certify.