cyber essentials vs cyber essentials plus

When comparing Cyber Essentials vs Cyber Essentials Plus, it is important to understand that a Cyber Essentials Plus badge is not simply a more advanced version of the same certificate. It is proof of a different kind, checked in a different way, and mixing the two up is how businesses end up buying the wrong one.

What Is the Difference Between Cyber Essentials and Cyber Essentials Plus?

Standard Cyber Essentials is a verified self-assessment. A business answers a detailed questionnaire about its firewalls, its patching, its access controls, and an independent certifying body checks the answers make sense before issuing the certificate. Nobody logs into the network to confirm it.

Cyber Essentials Plus does. The difference between Cyber Essentials and Cyber Essentials Plus comes down to that single point. A qualified assessor runs vulnerability scans against the actual devices, tests the configuration directly, and confirms the five controls are genuinely in place rather than accurately described. Same five controls both times. Completely different level of proof behind them.

How Do You Decide Which Level Your Organisation Needs?

Start with who is asking. Standard Cyber Essentials satisfies most insurers, most private sector due diligence checks, and plenty of smaller supply chain requirements on its own. Cyber Essentials Plus gets specified explicitly in a growing number of public sector tenders and larger enterprise contracts, the kind where a self-declared questionnaire is not considered sufficient proof anymore.

Read the actual tender document or the actual client requirement before assuming. Businesses regularly certify to standard level, lose a bid over it, then certify to Plus a year later once the same requirement shows up on the next tender. If there is any doubt over which level a contract actually specifies, it is worth being able to check Cyber Essentials certification status and level against the public IASME register rather than guessing from memory. Checking first saves a year.

Some sectors lean towards Plus by default rather than by contract requirement. Firms in law handle client financial detail and privileged case material that insurers and regulators expect protected to a higher standard than a self-assessment can demonstrate, which is why so many solicitors move to Plus even without a specific tender asking for it. Accountants sit in a similar position. Holding financial records for dozens or hundreds of clients at once makes a practice a specific target, not just a general one, and that alone pushes many towards the higher level. Care providers, charities and education settings tend to stay at standard unless a commissioning body says otherwise, since the pressure there usually comes from safeguarding data rather than procurement rules. Worth checking the full picture for your own sector on our sectors page rather than assuming.

Is Cyber Essentials Plus Harder to Get?

Yes, and it should be. A self-assessment can be filled in accurately by someone who understands the questions. A technical audit does not care how well the questionnaire was completed. It tests the network directly, and a firewall rule that looks fine on paper but is misconfigured in practice gets caught either way.

That is exactly why Plus carries more weight. Businesses that pass standard Cyber Essentials with genuinely well-managed systems usually pass Plus without major surprises. Businesses that scraped through the questionnaire with some gaps glossed over tend to find out about them during the Plus audit instead of during an actual breach, which is the better of the two ways to find out.

What Is the Cost Difference Between Them?

Standard Cyber Essentials certification typically costs between £300 and £500 for most small businesses, covering the assessment fee alone. Cyber Essentials Plus certification runs considerably higher, typically £1,500 to £3,000 for a small business environment, because of the added technical audit and the assessor time it involves.

Neither figure includes remediation. An environment that needs work before it meets the five controls will cost more regardless of which level gets chosen, and that remediation cost usually dwarfs the difference between the two certification fees anyway.

Is There a Way to Have Constant Monitoring of the Cyber Essentials Controls?

Both certificates describe a snapshot. Standard or Plus, the assessment confirms the five controls were met on the day it happened, not the day after. Orbit, Lift Off IT’s active compliance software, checks devices and settings against the Cyber Essentials controls continuously rather than once a year, and flags the moment something drifts rather than waiting for the next renewal to find it.

That matters more for Plus than for standard certification, since a technical audit finds configuration drift that a questionnaire never would. Running Orbit alongside either certificate means the annual reassessment confirms what is already known to be true, instead of turning up problems nobody caught in the eleven months since the last check. Full detail on how Orbit works sits on our Cyber Essentials certification page.

Plus Does Not Add New Controls, Just Harder Proof

Worth saying plainly, because it trips a lot of businesses up when they are deciding. Cyber Essentials Plus is not a more secure version of Cyber Essentials with extra controls bolted on. It is the identical five controls, checked to a higher standard of evidence. A business already meeting all five properly gains nothing technically by moving to Plus. What it gains is a certificate that a public sector buyer or a large enterprise client is willing to accept without asking further questions.

That is not a small thing if the certificate is being used to win contracts, but it is worth knowing before paying several times more for a badge that does not change what is actually protecting the network.

Whether the right answer is standard Cyber Essentials certification, Cyber Essentials Plus certification, or working out which one applies before spending anything, that is exactly the conversation Lift Off IT has with Liverpool businesses across care, education, accountancy, law and beyond every week. Our cyber security services cover what happens once either certificate is in place, and our complete guide to Cyber Essentials certification in Liverpool breaks down what the process actually involves. Get in touch to talk through which level fits the business, or book a free review and find out where the current setup actually stands against the five controls.

Contact Us