Cyber Essentials vs Cyber Essentials Plus: what is the difference and which do you need?
Both certifications cover the same five technical controls. The difference is in how those controls are assessed — and what that means for the commercial weight of the certificate.
The difference in one sentence.
Cyber Essentials is self-assessed and externally verified. Cyber Essentials Plus is independently tested by a technical assessor on your actual systems.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Controls covered | Firewalls, secure configuration, access control, malware protection, patch management | Same five controls |
| How it is assessed | Questionnaire completed by organisation, verified remotely by assessor | Technical testing performed by assessor on live systems |
| Evidence produced | Organisation declares controls are in place | Assessor confirms controls work under test conditions |
| Preparation required | Controls must be in place and accurately described | Controls must hold up to technical testing — not just described |
| Typical cost | Lower | Higher — reflects additional testing effort |
| Commercial signal | Baseline supply chain, government contracts, insurance requirements | Where buyers need technical verification, not just declaration |
Which one do you need?
The answer depends entirely on what your buyers, contracts or commercial environment require — not on which sounds more impressive. Cyber Essentials satisfies the majority of supply chain, government contracting and cyber insurance requirements. Cyber Essentials Plus is appropriate when a specific buyer, framework or contract asks for independently verified technical assurance rather than self-assessment.
If you are unsure which applies to your situation, the fastest route to clarity is usually to look at exactly what the buyer or contract specifies. Many organisations assume they need CE+ when CE alone is sufficient — and vice versa.
Do you need Cyber Essentials before you can do Cyber Essentials Plus?
No. You can pursue CE+ directly without holding Cyber Essentials first. However, the preparation work for CE+ is more demanding than for CE alone, and organisations that have not previously gone through the CE process may find it useful to use CE as a baseline check before the technical testing begins.
Can you have CE+ without CE?
Yes — CE+ is a standalone certification. It includes the same five controls and produces a certificate in its own right. You do not need to hold Cyber Essentials first, though many organisations achieve CE as a baseline before pursuing CE+.
Does CE+ expire?
Yes. Both Cyber Essentials and Cyber Essentials Plus require annual renewal. The controls and environment are re-assessed each year. This is important because the threat landscape and your technology environment change over time.
What if we fail the CE+ technical test?
A failed assessment identifies the specific gaps. YDC helps clients remediate those gaps and retest. The goal is to go into the assessment with a strong enough baseline that the pass is the expected outcome rather than a surprise — which is why preparation matters as much as the assessment itself.
Check what your buyer or contract actually specifies.
YDC helps organisations identify the right certification route and prepares them to pass — not guess.