ESSENTIAL GUIDANCE · COMPARISON · 8 min read
Part of Foundation insights →Cyber Essentials vs Cyber Essentials Plus: which certification does your organisation need?
How the two Cyber Essentials certification levels differ, when Plus is requested and how to choose a proportionate route.
How the two Cyber Essentialsi certification levels differ, when Plus is requested and how to choose a proportionate route.
Need an acronym translated?Open the cyber glossary →Both levels assess the same five controls
Cyber Essentials and Cyber Essentials Plusi are built around firewalls, secure configuration, security update management, user access control and malware protection. Both require an accurate, agreed scope. Plus is not a different list of basic controls; it provides a higher level of assurance by independently testing whether the declared controls operate in practice.
Cyber Essentials uses verified self-assessment
For the basic certification, the organisation answers the assessment questions and a qualified assessor reviews the submission through an authorised certification body. This can provide a proportionate baseline for many organisations, supplier requirements and procurement conversations. The answers remain the applicant's responsibility, so scope, evidence and technical accuracy matter.
Cyber Essentials Plus adds technical verification
Plus includes hands-on checks using a representative sample of the in-scope environment under the scheme's current test specification. Organisations must first hold Cyber Essentials before progressing to Plus within the applicable scheme process. The independent assessment provides stronger evidence that the controls described in the self-assessment have been implemented.
Customer and tender requirements often decide
Choose the level that satisfies the contractual or assurance requirement rather than assuming more is always necessary. A customer, government contract, insurer or supply-chain programme may state a specific level. Where no external requirement exists, consider the sensitivity of services, the value of independent verification and whether the organisation is ready to sustain the controls after certification.
Prepare for the route you actually need
Basic certification may require substantial remediation if the scope contains unsupported devices, weak administration or inconsistent updating. Plus adds technical preparation, sampling and coordination. Pentesys Foundation supports scope definition, readiness review, prioritised remediation and evidence preparation, with Plus pre-assessment support where needed. Formal certification remains with an authorised certification body.




