article
Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
Cyber Essentials vs Cyber Essentials Plus: Which Certification Does Your UK Business Need?
If you’re a UK organisation handling sensitive data or competing for government contracts, the question isn’t whether you need Cyber Essentials certification—it’s whether the basic Cyber Essentials self-assessment alone is sufficient, or if Cyber Essentials Plus with independent technical audit is mandatory. The difference is significant: basic certification costs £300–£600 and relies on your own questionnaire responses, while Plus adds £1,200–£2,500 for hands-on vulnerability scanning, patch audits, and malware testing by approved third parties. At TechTweek Infotech, we’ve guided 50+ UK clients through both schemes as an AWS Advanced Consulting Partner, and the distinction often determines whether you win contracts, satisfy insurers, and meet post-Brexit compliance frameworks overseen by the NCSC, ICO, and FCA.
The Five Core Controls: What Both Certifications Share
Before diving into differences, recognise that both Cyber Essentials and Cyber Essentials Plus enforce the same five foundational technical controls, developed by the UK National Cyber Security Centre (NCSC):
- Secure configuration: Hardening devices, disabling unnecessary services, and removing default credentials across all endpoints.
- Access control: Enforcing role-based permissions, multi-factor authentication (MFA), and preventing privilege escalation.
- Malware protection: Deploying anti-malware and anti-virus solutions on all devices with automatic updates enabled.
- Patch management: Applying security updates to operating systems, applications, and firmware within 14 days of release for critical patches.
- Secure and monitored configuration: Maintaining device inventories, logging administrative actions, and monitoring for unauthorised changes.
These controls align with UK GDPR (data protection), the Data Protection Act 2018, FCA expectations for financial services firms, and supply-chain security mandates across sectors including defence, healthcare, and local government in London, Manchester, Edinburgh, and beyond.
Cyber Essentials: Self-Assessment, Speed, and Limited Assurance
How Basic Certification Works
Cyber Essentials relies on a self-assessment questionnaire (SAQ) completed by your organisation. You answer questions about your security practices, submit your responses to an approved certification body, and receive certification within 1–2 weeks. Costs typically range from £300 to £600 GBP, making it affordable for SMEs across the UK.
When Basic Certification Suffices
- Your organisation does not hold government contracts or sensitive Crown data.
- You operate in low-risk sectors with minimal customer data exposure (e.g., non-financial professional services).
- You’re building a security foundation before scaling to Plus.
- Budget constraints prevent Plus investment, and your supply-chain partners don’t mandate Plus.
Key Limitations
The self-assessment model carries inherent risk: there is no independent verification of your answers. Your IT team may unknowingly misstate patch status, misidentify unsupported software, or misunderstand MFA deployment scope. Insurers and procurement teams increasingly view basic certification as low-assurance, and major contracts—particularly in defence, energy, and critical national infrastructure—explicitly require Plus.
Cyber Essentials Plus: Hands-On Audit, Mandatory for Government Work
What the Independent Audit Adds
Cyber Essentials Plus mandates an independent, accredited third-party audit lasting 2–4 weeks post-submission. The auditor conducts:
- Vulnerability scans: Network and device scanning of a sample of your IT estate (typically 10–20% of devices).
- Authenticated patch checks: Logging in to systems to verify patches were applied within the 14-day window and malware signatures are current.
- Malware and browser testing: Running controlled malware samples and email phishing simulations to verify detection.
- Configuration verification: Confirming default accounts are disabled, administrative access is logged, and MFA is functional.
- Evidence review: Examining audit logs, configuration baselines, and IT asset inventories.
Upon successful audit, you receive Plus certification valid for 12 months, at which point re-audit is required.
When Plus Is Mandatory
- Ministry of Defence (MoD) contracts: Defence Baseline and Defence Security Accreditation (DSA) pathways require Plus; many MoD supply-chain tiers now demand it.
- Government digital service procurement: Central, local authority, and NHS contracts increasingly specify Plus or equivalent.
- Critical national infrastructure (CNI): Energy, water, transport, and communications sectors under NCSC CNI guidelines.
- Financial services: FCA-regulated firms and their tier-1 service providers; insurance underwriters increasingly mandate Plus for cyber cover.
- Data processors handling NIS2 Directive data: Post-Brexit, UK organisations handling data subject to the NIS2 Directive (via Standard Contractual Clauses or International Data Transfer Agreements) face Plus expectations from EU clients.
- Supply-chain leverage: Tier-1 firms (e.g., Rolls-Royce, BAE Systems, HSBC) contractually require Plus from subcontractors.
Cost and Timeline
Plus certification typically costs £1,200–£2,500 GBP depending on estate size and audit complexity. Timeline: initial assessment (1 week), audit execution (2–4 weeks), remediation and re-audit if failures occur (2–8 weeks). Total path-to-certification: 5–12 weeks. At TechTweek Infotech, our UK clients in Manchester and London often frontload Plus to avoid contract delays.
Common Plus Audit Failures and How to Avoid Them
1. Unsupported or End-of-Life Software
Issue: Organisations run Windows 7, Internet Explorer 11, or legacy SQL Server instances that no longer receive vendor patches. Auditors flag these immediately.
Solution: Conduct a software inventory 6–8 weeks before audit. Identify unsupported platforms and plan migration (upgrade to Windows 10/11, migrate databases). TechTweek’s managed IT services help UK clients in finance and healthcare execute migrations without business disruption.
2. Patches Not Applied Within 14 Days
Issue: Critical patches released by Microsoft or Adobe are not deployed within 14 days. Auditors verify patch dates in system logs.
Solution: Implement automated patch management. Configure Windows Update, WSUS (Windows Server Update Services), or third-party tools (Intune, Jamf) to auto-deploy patches within 14 days. Create a documented patch policy and maintenance window schedule; communicate to stakeholders.
3. Administrator Accounts Misused or Poorly Logged
Issue: Domain admin credentials are shared, used for daily work, or administrative actions are not centrally logged.
Solution: Enforce privilege access management (PAM). Deploy Microsoft Privileged Access Workstations (PAWs), role-based access controls (RBAC), and enable Windows Event Logging for all administrative logons. Regularly audit log files (retained for ≥90 days).
4. Multi-Factor Authentication Not Consistently Enforced
Issue: MFA is implemented for email but not VPN, cloud apps, or sensitive on-premises systems.
Solution: Enforce MFA organisation-wide via Azure AD Conditional Access, Okta, or similar. Require MFA for remote access (VPN), email, cloud applications (Microsoft 365, AWS, Salesforce), and any system handling personal or confidential data.
5. Malware Protection Definitions Out of Date
Issue: Antivirus signatures are weeks old because auto-updates are disabled or managed endpoints have gone offline.
Solution: Verify auto-update is enabled on all devices. Use endpoint detection and response (EDR) tools (e.g., Microsoft Defender for Endpoint) to monitor malware protection status centrally. Generate compliance reports 1–2 weeks pre-audit.
Cost Comparison and Decision Framework
| Factor | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Cost | £300–£600 | £1,200–£2,500 |
| Timeline | 1–2 weeks | 5–12 weeks |
| Verification | Self-assessment only | Independent hands-on audit |
| Market Acceptance | SMEs, non-regulated sectors | Government, finance, CNI, supply-chain |
| Insurance Support | Limited; may not cover claims | Enhanced; many insurers require or discount |
| Validity | 3 years | 12 months (annual re-audit) |
How to Decide
Choose basic Cyber Essentials if:
- You operate in non-regulated sectors with low data sensitivity.
- Your supply-chain partners do not mandate Plus.
- You’re building baseline security maturity with budget constraints.
- You plan to upgrade to Plus within 12 months as revenue grows.
Choose Cyber Essentials Plus if:
- You pursue government, defence, or critical infrastructure contracts.
- Your financial services regulator (FCA) or insurance underwriter expects it.
- Major customers or supply-chain partners require Plus explicitly.
- You handle personal data under UK GDPR or post-Brexit IDTA/SCC arrangements with EU entities.
- You operate in healthcare, energy, transport, or telecommunications sectors.
FAQ: Cyber Essentials vs Cyber Essentials Plus
Q: Can I get Cyber Essentials Plus without basic certification first?
A: Yes. Plus is a standalone certification. However, many organisations start with basic to validate their security posture, then pursue Plus within 6–12 months once remediation is complete. This staged approach can reduce audit failure risk and spreads cost.
Q: How often must I renew Cyber Essentials Plus?
A: Annual re-audit is required. Basic Cyber Essentials is valid for three years, but as organisations change, re-assessment is recommended every 12–18 months to stay current with NCSC guidance and security threats.
Q: Does Cyber Essentials Plus replace ISO 27001?
A: No. Plus is prescriptive and controls-focused; ISO 27001 is a broader information security management system (ISMS) standard. Many UK organisations pursue both: Plus for market compliance and ISO 27001 for enterprise-grade maturity and customer confidence. TechTweek advises combining them for regulated sectors.
Q: What if Plus audit finds failures?
A: You enter a remediation phase (typically 4–8 weeks). The auditor verifies fixes and re-tests sampled controls. Only after successful re-audit do you receive Plus certification. Plan remediation budget and timeline accordingly.
Q: Is Plus certification affected by post-Brexit data transfers?
A: Cyber Essentials Plus itself is a UK NCSC scheme and unaffected by Brexit. However, if you handle EU personal data, you must comply with UK GDPR and maintain Standard Contractual Clauses (SCCs) or International Data Transfer Agreements (IDTAs) with your EU partners. Plus certification demonstrates your commitment to these controls, but doesn’t replace SCC/IDTA compliance. The ICO and NCSC provide post-Brexit guidance on both.
Next Steps: Assess and Act
Whether you’re a Manchester-based manufacturing firm seeking supply-chain approval, a London fintech navigating FCA expectations, or an Edinburgh healthcare provider managing NHS data, the Cyber Essentials vs Cyber Essentials Plus decision is strategically critical. Start by auditing your regulatory obligations (FCA, ICO, NCSC), reviewing customer and partner contracts for certification mandates, and assessing your current security maturity against the five core controls.
If Plus is your path—or if you’re unsure which level fits your risk profile—explore TechTweek’s Cyber Essentials Plus Certification service. As an AWS Advanced Consulting Partner with 24/7 follow-the-sun support across UK, EU, and global time zones, we guide organisations through pre-audit readiness, remediation, and successful certification. We’ve helped 50+ UK clients in finance, defence, healthcare, and critical infrastructure achieve Plus certification, often accelerating their path to contracts worth multiples of the certification cost.
Work with Techtweek
DevOps, cloud & compliance — CERT-In empanelled, AWS Advanced Partner.
Book a consultation