Cyber Essentials

Cyber Essentials vs Cyber Essentials Plus

The UK government-backed scheme has two levels built on the same five controls. The difference is who checks.
Certifyi compliance team · Updated September 2026
Short answer. Cyber Essentials is a verified self-assessment: you answer a question set covering five technical controls and a certification body reviews your answers. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by an assessor, including vulnerability scans, checks of a sample of devices, and tests of malware protection, and must be completed within three months of the basic certificate. Both are renewed annually.

The five controls

Scope, and the parts people get wrong

Scope covers every device that connects to the internet in the certified organisation or sub-set, including home-working laptops, mobile phones that access company data, and cloud services. Bring-your-own devices are in scope if they touch organisational data. The most common failures are unsupported operating systems on a forgotten device, missing MFA on a cloud service, and patch windows longer than fourteen days.

What Plus adds

Cyber EssentialsCyber Essentials Plus
MethodSelf-assessment questionnaire, signed by a board member, reviewed by an assessorSame questionnaire, plus an assessor-led technical audit
Technical testsNoneExternal vulnerability scan, authenticated internal scan of sampled devices, malware protection and email/browser tests
TimingAny time; valid 12 monthsWithin 3 months of the basic certificate; valid 12 months
Typical fitSmall organisations, first certification, supplier onboardingPublic-sector contracts handling personal or sensitive data, larger suppliers, insurance requirements

Which one do contracts require?

UK central government contracts that involve handling personal information or providing certain ICT services require Cyber Essentials at minimum, and many specify Plus. NHS and defence supply-chain contracts increasingly require Plus. If your buyers are in the UK public sector, plan for Plus from the start so the technical audit does not surprise you three months later.

Beyond Cyber Essentials

Cyber Essentials is deliberately narrow: five controls, no risk assessment, no management system. Organisations that outgrow it usually move to ISO 27001, which contains all five controls and adds governance. In Certifyi the Cyber Essentials question set and ISO 27001 sit on the same control library, so evidence for patching, MFA and malware protection is collected once and answers both.

Cyber Essentials, answered

The questionnaire takes a few hours if the controls are in place, and certification bodies typically respond within days. Plus depends on assessor availability and scope; allow a few weeks.

Yes. Cloud services that hold organisational data are in scope, and MFA is required on them where the service supports it.

Yes. The scheme is UK-run but any organisation can certify. It is most relevant if you sell into the UK public sector or to UK companies that require it of suppliers.

You are given a short window to remediate and re-test the failed items. If the window passes, the assessment restarts.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top