Cyber Essentials vs Cyber Essentials Plus: Which Does Your Business Need?
If a contract or tender has asked you for “Cyber Essentials,” the first question is usually: standard, or Plus?
Standard Cyber Essentials is a self-assessment, verified by a qualified assessor. You confirm — accurately — that your organisation has the five core controls in place: firewalls and routers, secure configuration, security update management, user access control, and malware protection. It’s a genuinely useful baseline, and for many contracts, it’s all that’s required.
Cyber Essentials Plus adds an independent technical audit on top of the same five controls — an external vulnerability scan, and typically an on-site or remote check that the controls are actually working as described, not just documented as working. It costs more and takes longer, because someone is actually testing your setup rather than taking your word for it.
Which one do you actually need? That depends entirely on what’s asking for it. Some public sector contracts and supply-chain requirements specifically mandate Plus; plenty of others are satisfied with standard. The costly mistake is guessing — either paying for Plus when standard would have satisfied the requirement, or submitting standard when the tender needed Plus and getting bounced back to redo it.
What happens if you’re not ready yet. Neither certification expects perfection on day one — a gap assessment against the five controls tells you exactly what needs fixing before you submit, so you’re not finding out through a failed assessment.
Not sure which one your contracts need?
We run gap assessments and hands-on remediation for both levels.












