Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Guides
Security

Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?

A plain-English guide to the two Cyber Essentials levels — how they differ, what the assessment involves, and how to choose the right one for your business.

A Streatham accountancy practice we spoke to had just lost a tender. Not on price, not on service — on a single line in the supplier requirements: “must hold Cyber Essentials Plus.” They had never heard of it, had six weeks to sort it out, and weren’t sure whether they needed the standard version, the Plus version, or both. If that sounds familiar, you’re in the right place.

Cyber Essentials is a UK government-backed scheme that certifies your business against a set of basic security controls. It comes in two levels, and the difference between them trips up a lot of owners. This guide explains what each one actually is, how the assessment differs, and how to decide which you need — without the jargon.

What Cyber Essentials covers

Both levels certify the same five technical controls. Get these right and you shut down the large majority of everyday cyber attacks:

  • Firewalls — a properly configured boundary between your network and the internet.
  • Secure configuration — devices and software set up safely, with default passwords and needless features removed.
  • User access control — the right people have the right access, and no more; admin rights are limited.
  • Malware protection — anti-malware in place and kept current across your machines.
  • Security update management — operating systems and apps patched promptly, before known holes get exploited.

None of this is exotic. It’s the security hygiene every business should already have. The certificate simply proves you do. If some of these controls are shaky, that’s normal — most businesses find a few gaps on first assessment, and closing them is the real value of the exercise. Sound cyber security is mostly these basics, done consistently.

The real difference: self-assessment vs independent audit

Here’s the part that matters.

Cyber Essentials (the standard level) is a verified self-assessment. You answer a questionnaire about how your systems are configured, a senior person signs it off, and a certification body reviews your answers. It confirms you’ve told them you meet the standard.

Cyber Essentials Plus covers the exact same five controls — but adds an independent technical audit. A qualified assessor checks a sample of your devices hands-on: they test that patching is genuinely up to date, that malware protection works, that a test phishing-style email is handled safely. It confirms your controls actually work in practice, not just on paper.

So Plus isn’t a higher or stricter standard. It’s the same standard, independently verified. Think of standard Cyber Essentials as “we’ve told you we do this,” and Plus as “someone checked.”

Which one should you choose?

For most businesses, the honest answer is: start with standard Cyber Essentials, and go to Plus only when there’s a reason to.

Standard Cyber Essentials is right when you want a solid security baseline, need to reassure clients you take this seriously, or are bidding for work that asks for “Cyber Essentials” without specifying Plus. It’s also the sensible first step even if Plus is your eventual goal — you can’t sit Plus without meeting the standard anyway.

Cyber Essentials Plus is right when a contract, tender or framework explicitly requires it — public-sector and larger private buyers increasingly do — or when your insurer asks for it, or when you handle sensitive client data and want genuine outside verification. Regulated fields feel this most: an accountancy firm or a law firm holding confidential client records benefits from being able to prove its controls work, not just claim it.

The trap to avoid is going for Plus when nobody’s asking for it, or dismissing it right up until a deadline lands on your desk — like that Streatham practice. Check your contracts and tender pipeline before you decide.

A practical checklist before you certify

Whichever level you’re aiming for, the groundwork is the same. Run through this first:

  1. List every device that touches business data — office PCs, laptops, phones, and home-working machines. All of them are in scope, which surprises people.
  2. Check everything is patched. Operating systems and key apps should be on supported, up-to-date versions. Old, unsupported software is the most common reason businesses fail.
  3. Remove leftover admin rights. Day-to-day accounts shouldn’t have administrator access; separate the two.
  4. Confirm malware protection is active on every machine, not just most of them.
  5. Tidy up user accounts — disable ex-staff logins, enforce multi-factor authentication, kill any shared passwords.
  6. Get your firewall and router configuration reviewed, including default passwords on the hardware itself.

If that list makes you wince slightly, you’re not alone — and it’s exactly the kind of tidy-up that managed IT support keeps on top of quietly, so certification becomes a formality rather than a scramble. Doing the work also makes your business genuinely safer, which is the point that outlasts any certificate.

Getting it done without the stress

Cyber Essentials is very achievable for a small business, and worth doing whether or not a contract demands it. The most common mistake we see is leaving it until a client or tender forces the issue, then rushing the underlying fixes.

If you’d like a hand — whether that’s readying your systems for the standard assessment, preparing for a Plus audit, or just working out which level a particular contract actually needs — we’re happy to talk it through in plain terms. Get in touch and we’ll tell you honestly where you stand and what the gap looks like.

Frequently asked questions

How long does Cyber Essentials certification last?

Both levels are valid for twelve months, then you re-certify. That yearly rhythm exists for a reason — your staff, devices and software change over a year, and the certificate is only meaningful if it reflects how things are set up now. Plan for it as an annual task, not a one-off.

Do we need Cyber Essentials Plus if we already have Cyber Essentials?

Not automatically. Plus is the same standard with an independent technical audit on top. You need it when a contract, tender or insurer specifically asks for Plus, or when you want outside verification that your controls actually work rather than just a self-declaration. If nobody's asking and you simply want the baseline, standard Cyber Essentials is enough.

Will certification disrupt our day-to-day work?

The standard level shouldn't — it's a questionnaire about how things are configured, answered from the office. Plus involves a short hands-on assessment of a sample of your devices, which we schedule around you. The bigger effort is usually the tidy-up beforehand, and that work makes your systems safer regardless of the certificate.

Related services

Free · no obligation

Want a hand with any of this?

Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.