Cyber Essentials vs Cyber Essentials Plus

Same five controls, two levels of proof. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds an independent, hands-on technical audit. Here's the real difference — and how to tell which one you're being asked for.

Cyber Essentials
Verified self-assessment
CE Plus
Independent technical audit
IASME fee (CE)
£320–£600 + VAT
CE Plus
Priced by device count

The one difference that matters

Both certifications assess the same five technical controls. The difference is how they're checked:

  • Cyber Essentials is a self-assessment questionnaire (the 2026 ‘Danzell’ question set), reviewed and verified by a licensed certification body. You declare how you meet the controls; an assessor marks it.
  • Cyber Essentials Plus includes everything in Cyber Essentials, then adds an independent, hands-on audit: an assessor runs external vulnerability scans and tests an authenticated sample of your devices, verifying patching and MFA for themselves rather than taking your word for it.

Self-declared versus independently tested — that single difference explains the extra cost and the extra weight buyers give Plus.

What it costs

The base Cyber Essentials fee is set by IASME and banded by size: roughly £320 + VAT (micro) up to £600 + VAT (large). Cyber Essentials Plus is priced by each certification body according to how many devices are in scope — commonly £1,500–£8,000 + VAT, on top of the base fee. See our cost explainer for the full picture.

Which one are you being asked for?

Read the exact wording of the contract, tender or insurer's form. Many private-sector clients accept Cyber Essentials. Larger primes, most public-sector higher-risk contracts (PPN 014), defence supply chains, NHS DTAC for critical systems, and some insurers specify Plus. If it just says ‘Cyber Essentials’ without ‘Plus’, the self-assessed level is usually enough. We check it with you rather than selling you up by default.

A note on the 2026 rules

From April 2026 both levels tightened: missing MFA on an in-scope cloud service is now an automatic fail, as is leaving critical or high-risk patches unapplied beyond 14 days. For CE Plus, your self-assessment answers are locked before the technical test begins, a failed device sample triggers a stricter re-test, and a second failure can revoke the underlying certificate. Getting it right first time matters more than it used to.

Common questions

Is Cyber Essentials Plus just a harder version?

It's the same five controls, but independently tested rather than self-declared. Plus adds an assessor running scans and checking a sample of your actual devices, so it carries more weight in due diligence.

Can I get Plus without doing Cyber Essentials first?

No — Cyber Essentials Plus builds on a verified self-assessment. In practice we do them together: you complete and pass the self-assessment, then the technical audit follows.

Why is Cyber Essentials Plus so much more expensive?

Because it involves real assessor time: external scans and hands-on testing of a device sample. Base Cyber Essentials is a reviewed questionnaire, so it costs far less. Plus pricing rises with the number of devices in scope.

How do I know which level my client wants?

Read the wording. ‘Cyber Essentials Plus’ means the audited level; ‘Cyber Essentials’ on its own usually means the self-assessed one. If it's ambiguous, we help you confirm before you spend.

Related

Not sure which level you need?

Send us the requirement and we'll tell you honestly whether Cyber Essentials or CE Plus covers it — before you spend.