Cyber Essentials vs Cyber Essentials Plus: Which Does Your Business Need?
If a contract or tender has asked you for “Cyber Essentials,” the first question is usually: standard, or Plus?

Standard Cyber Essentials
This is a self-assessment, verified by a qualified assessor. You confirm — accurately — that your organisation has the five core controls in place: firewalls and routers, secure configuration, security update management, user access control, and malware protection. It’s a genuinely useful baseline, and for many contracts, it’s all that’s required.
Cyber Essentials Plus
This adds an independent technical audit on top of the same five controls — an external vulnerability scan, and typically an on-site or remote check that the controls are actually working as described, not just documented as working. It costs more and takes longer, because someone is actually testing your setup rather than taking your word for it.
Cyber Essentials vs Cyber Essentials Plus: which one do you actually need?
That depends entirely on what’s asking for it. Some public sector contracts and supply-chain requirements specifically mandate Plus; plenty of others are satisfied with standard. The costly mistake is guessing — either paying for Plus when standard would have satisfied the requirement, or submitting standard when the tender needed Plus and getting bounced back to redo it.
What happens if you’re not ready yet
Neither certification expects perfection on day one — a gap assessment against the five controls tells you exactly what needs fixing before you submit, so you’re not finding out through a failed assessment.
How long does each take?
Standard Cyber Essentials is typically the quicker route, since it’s a self-assessment questionnaire verified by an assessor rather than an external technical test. Cyber Essentials Plus takes longer because it adds that independent vulnerability scan and on-site or remote testing on top — build in extra time if a tender deadline is driving your timeline.
Does it expire?
Yes — both certifications run for twelve months from the date they’re issued, so it’s a yearly renewal rather than a one-off exercise. Building the five controls into how you actually run IT, not just how you pass the assessment once, makes each renewal far less work than the first one.
FAQ
Do public sector contracts always require Plus?
No — some public sector contracts and supply-chain requirements specifically mandate Plus, but plenty of others are satisfied with standard Cyber Essentials. Check the exact wording of what’s been asked for before you commit to either.
Can Efficient IS help us get ready before we submit?
Yes — we run gap assessments against the five controls and hands-on remediation for both Cyber Essentials and Cyber Essentials Plus, so you know exactly what needs fixing before you submit rather than finding out through a failed assessment.
What the gap assessment actually involves
A gap assessment against the five controls typically takes a working day or two for a small business, and produces a specific list rather than a generic report: which firewall rules need tightening, which devices are missing security updates, where user access is broader than it needs to be, and so on. Working through that list before submitting for either certification is almost always faster and cheaper than submitting early, failing, and having to remediate under time pressure with a tender deadline already looming. Treating the assessment as a genuine health check, rather than a formality on the way to a badge, is what makes the annual renewal easy rather than a repeat of the first year’s work. Most gaps found in a first assessment are quick to fix once identified, a missing update policy, a firewall rule left too permissive, rather than requiring new hardware or significant spend.
Not sure which one your contracts need?
We run gap assessments and hands-on remediation for both levels.












