Post
29 May 2026

Cyber Essentials vs Cyber Essentials Plus: What's the Difference?

Both are UK government-backed certifications, but they're not interchangeable. Here's what actually separates Cyber Essentials from Cyber Essentials Plus, and how to know which one your business needs.


Cyber Essentials and Cyber Essentials Plus get mentioned in the same breath so often that it's easy to assume Plus is just a fancier version of the same thing. It isn't quite that simple, the two exist for different situations, and picking the right one matters both for your budget and your timeline.


Cyber Essentials: a verified self-assessment


Standard Cyber Essentials certification is based on a self-assessment questionnaire, covering the same five technical controls either way:


1. Firewalls

2. Secure configuration

3. Security update (patch) management

4. User access control

5. Malware protection


You (or your IT provider, on your behalf) complete the questionnaire honestly, it's reviewed by a certification body, and — assuming everything checks out — certification is issued. There's no independent technical audit of your actual systems; it relies on the accuracy of what's declared.


**Typical turnaround:** 1–2 weeks once the underlying controls are genuinely in place.


Cyber Essentials Plus: the same controls, independently verified


Cyber Essentials Plus covers the identical five controls, but adds a hands-on technical audit carried out by a qualified assessor — vulnerability scans, sample device checks, and verification that what was declared in the self-assessment is actually true in practice.


**Typical turnaround:** Longer than standard Cyber Essentials, since it depends on scheduling the technical audit, and any gaps found during it need remediating before certification is issued.


So which one do you actually need?


For most small and medium businesses, standard Cyber Essentials is enough — it satisfies the majority of tender requirements, supplier accreditation requests, and cyber insurance conditions. Cyber Essentials Plus tends to get specifically requested by:


- Larger enterprise clients with stricter supply chain security requirements

- Higher-risk sectors (financial services, healthcare, legal)

- Public sector contracts above a certain value or sensitivity


If nobody has explicitly asked you for Cyber Essentials Plus by name, standard Cyber Essentials is very likely the right starting point.


A common misconception worth clearing up


Neither certification is a one-off achievement — both need renewing every 12 months, because the threat landscape (and your own IT environment) keeps changing. A business that let its certification lapse two years ago isn't "still certified" in any meaningful sense, even if the certificate is still framed on the wall.


Getting started


The best first step isn't picking a certification level in the abstract — it's finding out where your business actually stands against the five controls today. That tells you realistically how far away certification is, and whether Plus makes sense for your situation.


Evoogic Ltd provides hands-on Cyber Essentials and Cyber Essentials Plus support for businesses across Milton Keynes, Bedford, Northampton, Buckingham, Leighton Buzzard and Aylesbury — assessing, remediating and submitting on your behalf. Book a free readiness check to find out exactly where you stand.


Need help with this in your business?

Evoogic Ltd provides IT Managed Services and Cyber Essentials certification for SMEs across Milton Keynes and the surrounding area.

Book a free review