Cyber Essentials Plus covers the same five controls as Cyber Essentials. The difference is that an independent assessor tests your live systems to verify the controls actually work. This gives stronger assurance to clients, insurers and partners.
Last time we covered the basics of Cyber Essentials and why the certification is worth having. This week we look at the next step up. If you already understand the scheme and are weighing whether to go further, the real question is what the "Plus" actually buys you, and whether your business needs that extra level of proof.
Prefer to watch?
Cyber Essentials Plus is the audited version of the government-backed Cyber Essentials scheme, overseen by the National Cyber Security Centre and delivered through IASME. It is built on exactly the same five technical controls as the standard certification: firewalls, secure configuration, user access control, malware protection and security update management.
The difference is not what is assessed but how. Standard Cyber Essentials is a self-assessment: you answer a questionnaire and a certification body reviews your answers. Cyber Essentials Plus keeps that self-assessment and then adds an independent assessor who tests your live systems to confirm the controls are genuinely in place and working.
Standard Cyber Essentials is your business stating that it meets the requirements. Cyber Essentials Plus is an independent expert checking that it does. Both are valid for 12 months, and both are based on the same requirements, so nothing you learned about the basics goes to waste.
The gap between the two is assurance. With self-assessment, the confidence rests on your own honesty and understanding. With Plus, a qualified assessor has looked at your actual devices and confirmed the picture. For a client, insurer or procurement team, that hands-on verification carries noticeably more weight.
What the technical audit involves
The Plus audit is a practical test rather than a paperwork exercise. An assessor works from a representative sample of your systems and typically covers:
The assessor samples across the different types of device and operating system your people use, so the results reflect your real estate rather than one tidy example machine. For multi-site businesses this matters: the audit is meant to represent the whole organisation, so a strong setup at head office will not paper over a weaker one at a branch.
For many businesses the standard certification is enough. You would look at Plus where you need to prove your security to someone else, not just assert it.
The most common driver is winning and keeping contracts. A growing number of tenders, particularly in the public sector, supply chains and regulated industries, ask for Cyber Essentials Plus specifically. It can also strengthen your position on cyber insurance, and it reassures partners who are increasingly wary of supply-chain risk. If your customers are trusting you with their data or systems, independent verification is a straightforward way to demonstrate you take that seriously.
It is worth being clear about what the certification is and is not. Cyber Essentials Plus is a strong, verified baseline of essential controls. It is not a complete security strategy on its own, and it does not replace ongoing monitoring, staff training and layered defences. It proves the fundamentals are in place, which is exactly what it is designed to do.
Standard Cyber Essentials uses fixed fees based on organisation size, currently ranging from around £300 plus VAT for the smallest organisations up to £450 plus VAT for medium-sized ones. Cyber Essentials Plus costs more because you are paying for an assessor's time on top of that, and the fee varies with your size, the number of devices and how many sites are in scope. It typically runs into the low thousands.
On timing, you need to hold a valid standard Cyber Essentials certification first, and the Plus audit should take place within three months of it. In practice, allow several weeks end to end once you factor in preparation, remediation of anything the assessor flags, and scheduling. Businesses that are already well organised and patched move through it far more quickly.
One current point to note: since the scheme update in April 2026, multi-factor authentication must be enabled on every cloud service that supports it, and high-risk and critical security updates must be applied within 14 days. These are now pass-or-fail requirements, so they are worth checking before you book an audit.
Use this simple test. If nobody is asking you to prove your security, standard Cyber Essentials is the right place to start. If someone is, whether a contract, a client or an insurer, choose Cyber Essentials Plus. Everything in the section above is really about who you need to convince.
Many businesses treat the two as a journey rather than a choice: certify to the standard first, tighten anything that needs attention, then upgrade to Plus when a tender or client makes it worthwhile. For multi-site and medium-sized organisations especially, getting every location to the same standard is the part worth planning for early.
If you would like help deciding which level fits your business, or getting audit-ready, our cyber security team can guide you through it. Talk to us about Cyber Essentials Plus.
Is Cyber Essentials Plus worth it?
For businesses that need to prove their security to clients, insurers or partners, yes. The independent audit gives assurance that a self-assessment cannot, and it is often a requirement for public-sector and supply-chain contracts.
Do I need standard Cyber Essentials before Plus?
Yes. You must hold a valid Cyber Essentials certification first, and the Plus audit should take place within three months of it.
How long does Cyber Essentials Plus last?
Twelve months, the same as standard Cyber Essentials. You renew annually to stay certified.
What does the Plus audit actually check?
An independent assessor tests a sample of your live systems, including external and internal vulnerability scans, malware protection and multi-factor authentication on cloud services, to confirm the five controls are genuinely working.
How much does Cyber Essentials Plus cost?
More than the standard certification, because it includes an assessor's time. The exact fee depends on your size, number of devices and sites, and typically runs into the low thousands plus VAT.
Sources: NCSC: Cyber Essentials overview, IASME: Cyber Essentials, IASME: April 2026 scheme changes.