Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
Cyber Essentials is the baseline scheme that proves you have the basic cyber‑hygiene controls in place, while Cyber Essentials Plus adds an independent technical verification of those controls. You need Cyber Essentials if you are just starting to formalise security or have modest risk, but you’ll need Cyber Essentials Plus if you handle sensitive data, must meet higher contractual requirements, or want to demonstrate a stronger level of assurance to customers. In short, the choice depends on the level of confidence you need to show and the risk profile of your business.
What is Cyber Essentials?
Cyber Essentials is a UK government‑backed scheme that sets out five core security controls:
- Boundary firewalls and internet gateways – protect your network from unauthorised access.
- Secure configuration – ensure devices and software are set up securely.
- User access control – limit privileges to the minimum required.
- Malware protection – keep anti‑virus and anti‑malware solutions up to date.
- Patch management – apply security updates promptly.
The assessment is a self‑declaration questionnaire that you complete and submit to an accredited certification body. If the questionnaire is approved, you receive a Cyber Essentials certificate issued via an accredited body.
What is Cyber Essentials Plus?
Cyber Essentials Plus builds on the basic scheme by adding a hands‑on technical audit. After you submit the same self‑assessment, an independent testing team conducts on‑site (or remote) checks to verify that the controls are truly in place and operating correctly.
The technical audit includes:
- Vulnerability scanning of your external internet‑facing services.
- Testing of your firewall configuration against recognised best practice.
- Verification that patch management processes are applied to a representative sample of devices.
- Assessment of user account management and privileged access.
Successful completion results in a Cyber Essentials Plus certificate, again issued via an accredited body, and provides a higher level of assurance to partners and clients.
Key Differences at a Glance
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment type | Self‑declaration questionnaire | Self‑declaration + independent technical audit |
| Cost | Lower – covers only the questionnaire fee | Higher – includes testing fees and possible travel costs |
| Time to certify | Usually a few weeks | Typically 4‑6 weeks, depending on audit scope |
| Level of assurance | Basic – demonstrates you have the required controls | Enhanced – proves those controls work in practice |
| Typical use cases | Start‑ups, SMEs with limited data, organisations needing a quick baseline | Businesses handling personal or financial data, public sector contracts, supply‑chain requirements |
How to Decide Which Scheme Fits Your Business
Consider the following factors when choosing between the two schemes:
- Data sensitivity: If you store or process personal data, payment information, or intellectual property, the extra verification of Plus can be a valuable risk mitigator.
- Client or contract requirements: Some public‑sector contracts and larger private‑sector agreements specifically request Cyber Essentials Plus as a condition of tender.
- Budget and resources: The Plus assessment requires more time and money. For many small businesses, Cyber Essentials alone provides a solid foundation without stretching limited budgets.
- Future growth plans: If you anticipate scaling quickly or entering markets where higher assurance is expected, starting with Plus can save you a repeat assessment later.
- Internal expertise: Companies with mature IT teams may find the self‑assessment straightforward, whereas those lacking expertise often benefit from the external verification that Plus offers.
In practice, many UK SMEs begin with Cyber Essentials to establish a security baseline, then upgrade to Plus once they have grown or when a specific contract demands it.
Preparing for the Assessment
Regardless of the scheme you choose, preparation is key. Solvbeat can help you get ready without the guesswork.
1. Run a free website security scan
Our online scanner checks for common vulnerabilities, missing patches, and misconfigurations that are directly relevant to the Cyber Essentials controls. Use the results as a checklist for remediation.
2. Review the five control areas
- Firewalls: Confirm that only required ports are open and that default passwords have been changed.
- Secure configuration: Harden operating systems, disable unnecessary services, and enforce strong password policies.
- User access: Implement the principle of least privilege and regularly review account rights.
- Malware protection: Deploy reputable anti‑virus solutions on all endpoints and ensure they receive automatic updates.
- Patch management: Set up a routine to test and apply vendor security patches within a reasonable timeframe.
3. Document your processes
The questionnaire asks for evidence of policies and procedures. Keep simple, up‑to‑date documents that describe how each control is implemented and who is responsible.
4. Choose an accredited certification body
Only accredited bodies can issue the official certificates. Solvbeat does not provide certification, but we can recommend reputable bodies and guide you through the submission process.
5. Plan for the technical audit (if pursuing Plus)
Schedule the audit during a low‑impact period, ensure key staff are available to answer questions, and have remote access ready for the testing team.
By following these steps, you’ll reduce the likelihood of surprise findings during the assessment and increase the chances of a smooth certification journey.
Ready to see where your current security posture stands? Run a free scan →