Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?

TLDR: In short, Cyber Essentials Plus has the same requirements as the standard Cyber Essentials but requires an external audit. Want more detail? Keep reding this article!

If you've been asked for Cyber Essentials by a customer, an insurer or a public sector buyer, you've probably noticed there are two versions. Cyber Essentials and Cyber Essentials Plus. The first is a self-assessment questionnaire whereas Plus involves an assessor testing your systems. They have the same requirements but the costs can be very different, so it's worth understanding which Cyber Essentials certification your business needs.

What does Cyber Essentials certification actually cover?

Cyber Essentials is a UK government-backed scheme that focuses on five basic technical controls that block the large majority of common attacks:

  • Firewalls — controlling what can reach your network from the internet

  • Secure configuration — removing default passwords, unused accounts and software you don't need

  • User access control — making sure staff only have the access their job requires, and that admin accounts are separate from day-to-day logins

  • Malware protection — antivirus or equivalent on every device

  • Security update management — patching critical and high-risk updates within 14 days

Standard Cyber Essentials is a self-assessment questionnaire. You answer the questions honestly, a director signs it off and a certification body reviews your answers. If something isn't up to scratch they'll come back and tell you. Certification lasts 12 months and the questionnaire needs to be completed again for the renewal.

One benefit many businesses don't realise is that Cyber Essentials can include free cyber liability insurance, provided your organisation meets the eligibility criteria and is fully in scope for certification. Both Cyber Essentials and Cyber Essentials Plus includes the insurance.

What's different about Cyber Essentials Plus?

It's the same five controls and the same questions but the difference is verification.

With Plus, an assessor carries out hands-on technical testing. They take a sample of your devices, run vulnerability scans, check patch levels, test whether malicious files can reach a user and confirm MFA is enforced. For the users selected, there's often a 15 minute appointment with the assessor to cover these checks.

A few notes on Plus:

  • You need to pass the standard self-assessment first, and the Plus audit must happen within three months of that

  • Every device type in scope gets sampled meaning if you have a mix of Windows laptops, Macs, iPhones and Androids, each type will need to be assessed

  • Cost scales with the number of devices and locations, it usually starts at around £1200-£1500 for the Plus assessment

  • If you fail a Plus audit you'll typically be given a window to fix the issues and retest. The most common failures are related to software that hasn't been updated.

Do I need Cyber Essentials or Cyber Essentials Plus?

For most 10 to 100 person firms, standard Cyber Essentials is the often right starting point. It's affordable, it can usually be completed in a few weeks, and it satisfies the majority of commercial requests.

You'll likely need Plus if:

  • You're bidding for central government contracts that handle personal or sensitive information

  • You're in a defence or MOD supply chain, which matters locally given how many Plymouth engineering and manufacturing firms work alongside Babcock and the dockyard

  • A large corporate customer has specified Plus in their supplier terms

  • Your insurer or a regulator has asked for independently verified controls

We usually recommend starting with standard Cyber Essentials, getting everything in good shape and moving to Plus later if a customer or contract requires it. Even if Plus isn't required, it doesn't prevent you from completing it to show your customers that you take security seriously and have verified measures in place to protect their data.

How long does certification take?

Starting from scratch? We'd normally suggest allowing four to eight weeks, although every business is different. If your systems are already well managed and up to date, it can often be completed much sooner.

This is where having someone handle the technical side pays off. Our managed IT support and cyber security services are already aligned with the controls required for Cyber Essentials. That means there's no extra charge from us when it comes to renewing your certification. You'll simply pay the standard IASME certification fee.

Do you need Cyber Essentials certification quickly?

Give us a call and we'll have a conversation about your setup and provide a timeline to get you certified.

Not sure which level you need?

If you're unsure whether Cyber Essentials or Cyber Essentials Plus is the right fit, we'd be happy to help.

We'll take a look at your requirements, explain what's involved, and give you a realistic idea of the timescales and costs.

No obligation, no hard sell, just straightforward advice from a local team that's helped businesses across Plymouth, Devon and Cornwall achieve certification.

Next
Next

Are you paying for Microsoft 365 licences you don't use?