Join our Newsletter — 33% off our NHI Course

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment based certification that is reviewed by an external certifying body. Cyber Essentials Plus includes the same self-assessment, but adds a hands-on technical evaluation of the organisation’s controls. For buyers, the difference is assurance depth: the Plus level tests whether the stated controls actually operate as intended, not just whether they are documented.

Why the difference matters when you are choosing a certification level

cyber essentials and Cyber Essentials Plus are not competing schemes with different control goals. They are two assurance levels for the same baseline, and the practical difference is how much confidence a buyer, insurer, or regulator can place in the result. The basic level tells you the organisation says it has implemented the required controls; the Plus level adds independent technical checking of those controls in operation. For procurement, that distinction often matters more than the badge itself. An organisation can be policy-complete and still have gaps in real configurations, exposed assets, or inconsistent patching. That is why the UK National Cyber Security Centre’s Cyber Essentials overview is useful context before comparing the assurance levels.

For the organisation being assessed, Plus usually carries more effort, more evidence, and a greater need for control maturity across endpoints and internet-facing systems. For the buyer, it reduces reliance on self-declared assurance and gives a stronger signal that the controls are not only written down but also testable in practice. In practice, many security teams discover that the gap between documented control and working control only becomes visible when a technical test is applied rather than during questionnaire review.

How the two levels differ in practice

Cyber Essentials focuses on a defined set of technical hygiene controls, typically around boundary firewalls, secure configuration, access control, malware protection, and patch management. The organisation completes a self-assessment, then an external certifying body reviews that submission against the scheme requirements. That makes the base level useful as a lightweight governance checkpoint, especially for suppliers that need a recognised baseline without opening their environment to a deeper assessment.

Cyber Essentials Plus keeps the same underlying scope but adds hands-on validation. The assessor does not simply read answers; they test whether the controls work as claimed. That may include checking device security settings, sampling endpoints, validating patch status, and confirming that exposed weaknesses are not present on the in-scope systems. The key practical point is that Plus measures operational reality, so it is better suited to environments where control drift, inconsistent deployment, or incomplete endpoint management would materially change the assurance picture. If an organisation cannot reliably show that its standard build, update cadence, and access restrictions are applied consistently, the self-assessment level can overstate confidence.

  • Cyber Essentials is best understood as “declare and review.”
  • Cyber Essentials Plus is best understood as “declare, review, and verify.”
  • Both levels depend on the same baseline controls, but Plus checks whether those controls actually exist on real systems.
  • Plus is therefore more sensitive to implementation gaps, not just policy gaps.

That is also why the scheme can be attractive to buyers who need a practical assurance threshold rather than a purely paper-based one. The difference is not about adding more control categories; it is about reducing the chance that hidden configuration errors, unpatched endpoints, or weak admin practices go unnoticed. Where this breaks down is in organisations that treat the certificate as a substitute for ongoing control management, because the assessment is a snapshot, not continuous monitoring.

Where buyers, suppliers, and assessors should be careful

Tighter assurance often increases assessment effort, remediation work, and operational disruption, so organisations have to balance confidence against cost and preparation time. That tradeoff becomes important when a supplier is pursuing certification primarily to satisfy procurement rather than to improve its control posture.

One common variation is assuming that Plus is simply “more of the same.” It is not. The difference is that technical validation can expose local exceptions, unmanaged devices, or inconsistent hardening that a questionnaire will not surface. Another edge case is scope misunderstanding: if the certified environment is narrow, buyers may overread the result and assume it covers the whole organisation. The scheme only assures what was assessed, so the scope statement matters as much as the certificate itself.

There is also a practical governance question. If a customer is using Cyber Essentials Plus as a supplier gate, the real decision is whether it wants a baseline declaration or a stronger check that the supplier can sustain the controls in production. Guidance across the market is consistent that Plus provides stronger assurance, but there is no consensus that it is necessary for every supplier relationship. The right choice depends on the sensitivity of the service, the exposure of the systems in scope, and how much trust the buyer needs to place in the supplier’s own control reporting.

For teams comparing the two, the useful question is not which badge is “better” in abstract terms, but whether the extra verification is needed to support the decision being made. If the answer depends on real control operation rather than claimed control design, Plus is the stronger fit.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS 4 — Secure Configuration of Enterprise Assets and Software Both levels hinge on whether baseline configuration is actually enforced.
CIS 7 — Continuous Vulnerability Management Plus-style testing is most sensitive to patching and exposure gaps.
CIS 12 — Network Infrastructure Management The scheme depends on firewall and boundary control operation, not just policy.
Recommendation — Verify and harden baseline configurations on assessed systems before relying on certification. Prioritise patch verification and exposure review for in-scope assets before assessment. Validate boundary and perimeter control settings against the declared security baseline.
NIST CSF 2.0 PR.AC — Identity Management, Authentication and Access Control Assurance depends on whether access controls operate as claimed across real systems.
PR.IP — Information Protection Processes and Procedures The question contrasts documented process with operational control verification.
Recommendation — Test access enforcement on in-scope systems rather than relying on policy statements. Align written procedures with technical evidence that the controls are implemented consistently.

Practitioner Guidance

What to prioritise: Decide first whether you need supplier self-attestation or independently checked technical assurance. If the certificate will influence procurement, third-party trust, or risk acceptance, treat the verification depth as the real decision point rather than the label.

What to verify: Confirm the exact scope, the systems tested, and whether the certificate reflects the environment you are actually relying on. A narrow but well-controlled scope is more useful than a broad claim that does not map to the service you buy.

Common mistake: Treating the basic level as if it proves operating effectiveness. It does not. It proves a reviewed assertion, while the Plus level is the one that gives you direct evidence that the controls are present and functioning.

Practitioner takeaway: Use Cyber Essentials when you need a recognised minimum baseline, but use Plus when the decision depends on whether the controls are demonstrably real rather than merely described.