Cyber Essentials and Cyber Essentials Plus get mentioned in the same breath so often that it's easy to assume Plus is just a fancier version of the same thing. It isn't quite that simple, the two exist for different situations, and picking the right one matters both for your budget and your timeline.
Cyber Essentials: a verified self-assessment
Standard Cyber Essentials certification is based on a self-assessment questionnaire, covering the same five technical controls either way:
1. Firewalls
2. Secure configuration
3. Security update (patch) management
4. User access control
5. Malware protection
You (or your IT provider, on your behalf) complete the questionnaire honestly, it's reviewed by a certification body, and — assuming everything checks out — certification is issued. There's no independent technical audit of your actual systems; it relies on the accuracy of what's declared.
**Typical turnaround:** 1–2 weeks once the underlying controls are genuinely in place.
Cyber Essentials Plus: the same controls, independently verified
Cyber Essentials Plus covers the identical five controls, but adds a hands-on technical audit carried out by a qualified assessor — vulnerability scans, sample device checks, and verification that what was declared in the self-assessment is actually true in practice.
**Typical turnaround:** Longer than standard Cyber Essentials, since it depends on scheduling the technical audit, and any gaps found during it need remediating before certification is issued.
So which one do you actually need?
For most small and medium businesses, standard Cyber Essentials is enough — it satisfies the majority of tender requirements, supplier accreditation requests, and cyber insurance conditions. Cyber Essentials Plus tends to get specifically requested by:
- Larger enterprise clients with stricter supply chain security requirements
- Higher-risk sectors (financial services, healthcare, legal)
- Public sector contracts above a certain value or sensitivity
If nobody has explicitly asked you for Cyber Essentials Plus by name, standard Cyber Essentials is very likely the right starting point.
A common misconception worth clearing up
Neither certification is a one-off achievement — both need renewing every 12 months, because the threat landscape (and your own IT environment) keeps changing. A business that let its certification lapse two years ago isn't "still certified" in any meaningful sense, even if the certificate is still framed on the wall.
Getting started
The best first step isn't picking a certification level in the abstract — it's finding out where your business actually stands against the five controls today. That tells you realistically how far away certification is, and whether Plus makes sense for your situation.
Evoogic Ltd provides hands-on Cyber Essentials and Cyber Essentials Plus support for businesses across Milton Keynes, Bedford, Northampton, Buckingham, Leighton Buzzard and Aylesbury — assessing, remediating and submitting on your behalf. Book a free readiness check to find out exactly where you stand.