Back to All Articles
Cyber Security

Cyber Essentials vs Cyber Essentials Plus: Understanding the Real Difference

12 October 2025 4 min read

On paper, Cyber Essentials and Cyber Essentials Plus look like a minor naming variation. In practice, the gap between them is significant — and understanding it properly will save you from either over-investing too early or under-preparing for a contract that actually needs the higher tier.

Self-Assessment Has Its Place — And Its Limits

Base Cyber Essentials is completed via a self-assessment questionnaire, verified by a qualified assessor reviewing your answers. It's a genuinely useful baseline, fast to achieve, and sufficient for a large share of contracts. But it relies on your own representation of your controls being accurate.

What Independent Testing Actually Adds

Cyber Essentials Plus involves an assessor actually testing your systems — vulnerability scanning, configuration checks, verification that patches are genuinely applied rather than just claimed. It's the difference between saying your controls work and proving it.

Which One Your Contracts Actually Require

Higher-sensitivity engagements — government, critical infrastructure, financial services, anything handling particularly sensitive personal data — increasingly specify Plus as the minimum. For most standard commercial security contracts, base Cyber Essentials remains sufficient.

Don't assume you need Plus by default, but don't assume base-level is always enough either. Check what your specific target contracts actually specify before committing the additional time and cost.

Need Help With This?

Our compliance team can walk you through exactly what your business needs.

Book Free Consultation