Skip to main content
Meridian Grove IT
Compliance

Cyber Essentials vs Cyber Essentials Plus: what actually changes

Rachel Voss · 2 June 2026 · 6 min read

Cyber Essentials is a self-assessed questionnaire. Cyber Essentials Plus is that same set of controls, independently verified by an assessor through hands-on technical testing of your actual systems. That distinction matters more than it sounds.

What Plus actually verifies

Where standard Cyber Essentials asks whether you have, for example, up-to-date anti-malware software, Cyber Essentials Plus has an assessor actually test it, attempting to run known malware samples against a sample of your devices to confirm the protection genuinely works as described, not just as documented.

The same pattern holds across the five core control areas: firewalls, secure configuration, user access control, malware protection, and patch management. Self-assessment tells you what a business believes is true. Plus tells you what an independent assessor confirmed is true.

Why it's increasingly a contractual requirement

We've seen a clear shift over the past two years: procurement teams at larger organisations, and increasingly insurers setting cyber liability premiums, are asking specifically for Cyber Essentials Plus rather than accepting the standard certification. If your business bids for contracts with public sector bodies, larger enterprises, or organisations handling sensitive data, this is often no longer optional.

What the process actually involves

A typical Plus certification runs four to six weeks from readiness assessment to certificate issue: an initial gap assessment against the current control requirements, a period of remediation for anything that doesn't yet meet the standard, and then the assessor's on-site or remote technical testing itself.

The most common gap we find isn't exotic. It's usually inconsistent patch management across a mix of company-owned and BYOD devices, or multi-factor authentication that's enabled for some accounts but not enforced organisation-wide.

If you're weighing up whether Plus is worth the additional cost and time over standard certification, the honest answer depends on who's asking to see it. If a specific client or insurer has asked for it by name, there's no substitute. If you're pursuing it proactively, it's still the stronger signal of genuine, tested resilience rather than a completed form.

Get one useful email a month

Security and infrastructure guidance, no sales fluff.