Here’s a number worth knowing first. Organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance, according to the NCSC’s review of the scheme’s first decade. That comes from the insurer’s own data, so it counts claims, not every breach. It’s still striking for a scheme built on just five controls: firewalls, secure configuration, user access control, malware protection and patching.
You can prove those five controls in two ways. With basic certification, you fill in a questionnaire. With Plus, an assessor tests your real systems. The difference between Cyber Essentials and Cyber Essentials Plus matters more this year, because the v3.3 “Danzell” question set went live on 27 April 2026. It’s stricter on cloud services, multi-factor authentication, and patching.
Below, we have compared Cyber Essentials vs Cyber Essentials Plus on method, cost, audit depth, and pass bar. Then we will discuss how the Plus process works and which level your contract or insurer really wants.
What Are Cyber Essentials?
So, what is Cyber Essentials in practice? It’s the government-backed baseline scheme the NCSC launched in 2014, and IASME now runs it for them. You answer a questionnaire about the five controls. A certification body marks it, and someone senior signs the declaration.
Here’s the thing: nobody tests anything. The certificate reflects how you describe your setup, not how an outsider would find it. That’s a real limitation. But it’s still useful, because plenty of teams find a forgotten admin account or an unsupported laptop while filling the form in. Fees are fixed by IASME and exclude VAT. The certificate lasts 12 months, so you renew every year.
What Is Cyber Essentials Plus?
Same requirements, different checker. Instead of reading your answers, a certification body audits your environment. IASME’s own comparison says the audit can run on site or remotely. It includes vulnerability scans of your scoped systems and tests on a sample of devices, like servers, laptops, tablets, and phones.
That’s where your policy meets reality. You say critical patches go on within 14 days, so the assessor goes and looks at the machines.
You can’t skip straight to Plus, because it sits on top of the basic certificate. But if you sit the audit within three months of your last Cyber Essentials certificate, you don’t repeat the questionnaire. The IASME FAQ covers that rule.
How many people bother? The NCSC’s Annual Review 2025 counts 39,790 basic certificates and 12,850 Cyber Essentials Plus certifications in 2024 to 2025. Roughly one in four certified organisations picked the audited route.
The 5 Technical Controls Both Levels Share
| Control Area | What It Requires | How a Plus Assessor Typically Tests It |
|---|---|---|
| Firewalls | Boundary firewalls on internet-connected devices, default passwords changed, unneeded services blocked | External scan of internet-facing systems for unexpected open services |
| Secure configuration | Devices and software set up to reduce vulnerabilities, with unused accounts and functions removed | Configuration checks on the sampled devices |
| User access control | Unique accounts, access limited to those who need it, tightly restricted admin rights | Account review on sampled devices and MFA checks on cloud services |
| Malware protection | Anti-malware active on applicable devices, or application allow-listing | Confirmation that protection is running on the sampled devices |
| Security update management (patching) | High and critical vulnerabilities fixed within 14 days of a fix becoming available. | Scan results and device checks looking for unpatched vulnerabilities |
In Cyber Essentials vs. Cyber Essentials Plus, Plus doesn’t add a sixth control or lower any threshold. It just checks the same five far harder.
Cyber Essentials vs. Cyber Essentials Plus: Key Differences
| Factor | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessment questionnaire, marked by a certification body | Technical audit by a certification body |
| Cost | Fixed by IASME: £320 to £600 ex VAT, depending on headcount | Quoted individually by each certification body |
| Audit depth | No contact with your systems | Vulnerability scans plus hands-on testing of a device sample |
| Pass bar | Every requirement met. Certification body guides call missing cloud MFA and missed 14-day patches automatic fails under v3.3 | No qualifying vulnerabilities in the scans and device checks. Guides report up to three months to fix findings and retest |
| Prerequisite | None | A Cyber Essentials certificate, ideally under three months old |
| Validity | 12 months | 12 months |
Cyber Essentials Plus Requirements and Certification Process
Here’s the usual route from booking to certificate for Cyber Essentials Plus requirements.
| Step | What Happens | Your Job |
|---|---|---|
| 1. Prerequisite | You hold a current Cyber Essentials certificate | Aim to start the audit within three months of it |
| 2. Scoping | You agree on what’s covered with the certification body | List networks, servers, user devices and cloud services |
| 3. Scans | The assessor scans your internet-facing systems and a sample of internal devices | Fix obvious gaps before the scan date |
| 4. Device testing | They check patches, accounts, malware protection, and configuration, on site or remotely | Have your devices reachable and your admins available |
| 5. Remediation | You fix whatever they flag | Ask your body how long the window is, because providers differ |
| 6. Certificate | You receive Cyber Essentials Plus, valid for 12 months | Diarise the renewal |
Scope causes more delays than any other step. Leave out a system that belongs in, and the audit can stall halfway. Pull in old machines nobody maintains, and your sample fails on kit you could’ve retired.
What Changed With v3.3 “Danzell”
Forensic Control’s summary of v3.3 and Cyphere’s breakdown agree on the main changes. Danzell replaced the Willow question set on 27 April 2026.
- Cloud is in scope. Microsoft 365, Google Workspace, and similar services that hold business data can’t sit outside the boundary anymore.
- MFA everywhere it’s offered. One cloud account without MFA can fail you.
- Patching means more than installers. Registry edits, configuration changes, and scripts count as vendor-recommended fixes.
- Scoping is stricter. Any internet-connected device is in scope unless you document technical segregation.
Cyphere also says security assessments already under way can finish under Willow until 27 October 2026. That’s one source, so ask your certification body which rules apply to you.
What Weak Evidence Looks Like Next to Plus-Ready Evidence
A line like “we patch critical updates within 14 days and staff know the policy” is fine for a questionnaire. A Plus assessor won’t accept it, because nothing shows which device updated on which day.
Plus-ready evidence is different. You hand over a scan report from the audit window with no unpatched critical or high findings on the sampled devices. You add a patch log showing an install date for each one. Now the assessor can trace your policy to a machine they’ve checked themselves.
Want someone to look over that evidence first? Qualysec can review it with you before the assessor turns up!
Which One Does Your Organisation Actually Need?
I’d start with basic certification for most teams. Plus is worth having, but if you sit the audit before your patching and accounts are tidy, you’ll probably fail the first time and pay twice.
Basic Cyber Essentials is often enough when:
- No client, tender or insurer names Plus
- You bid for UK government work that only asks for the base certificate
- You’re early in building a security programme
You’ll need Plus when:
- A client, prime contractor or public sector tender names it
- Your insurer wants independently verified controls, not a self-declaration
- You handle sensitive data, and a self-assessment wouldn’t survive due diligence
- Leadership wants proof the controls work in practice
Read the contract wording carefully. “Cyber Essentials” and “Cyber Essentials Plus” aren’t interchangeable. Send the wrong certificate and your bid can drop out at the compliance check, long before anyone reads your technical answers.
How Qualysec Supports Your Cyber Essentials Plus Readiness
A retest costs money and weeks, so the cheapest moment to find a gap is before the assessor does. Qualysec’s work with UK organisations centres on three things.
Pre-Audit Vulnerability Scanning
Qualysec runs internal and external vulnerability scans of the kind a Plus assessor uses. For this reason, unpatched systems and exposed services show up in your own report instead of your audit findings.
Danzell Scope and MFA Check
Qualysec reviews your scope against the v3.3 rules, including cloud services and MFA coverage across every user account. In practice, this catches the single forgotten account or excluded SaaS tool that would otherwise fail the assessment.
Evidence Pack and Retest
Qualysec helps you assemble the scan reports and patch logs an assessor expects, then re-scans after your team fixes the findings. As a result, you can confirm the fixes held before the audit date arrives.
Conclusion
Cyber Essentials vs Cyber Essentials Plus isn’t a question of better or worse. Both test the same five controls, but only one sends an assessor to check them. That real Cyber Essentials vs Cyber Essentials Plus difference now decides which tenders you can enter and, in some cases, which insurance terms you can get.
So read what your contract or insurer asks for by name. Then tidy your patching, accounts and cloud settings until you’d pass the first time, because v3.3 treats some single misses as automatic fails.
Ready to test that? Book a readiness review with Qualysec and find the gaps before the assessor does!
Frequently Asked Questions
1. What is Cyber Essentials?
It’s the UK government-backed baseline scheme, launched by the NCSC in 2014 and run by IASME. You answer a questionnaire on five technical controls, and a certification body marks it. Fees run from £320 to £600 ex VAT, depending on your headcount.
2. What is Cyber Essentials Plus?
It’s the same scheme with a real check added. A certification body scans your scoped systems and tests a sample of your devices, on site or remotely. You need a basic certificate first. Do the audit within three months of it, and you skip the questionnaire.
3. What is the difference between Cyber Essentials and Cyber Essentials Plus?
Nothing about the controls. Both cover the same five. The difference is who checks them: you, through a questionnaire, or an assessor, through scans and hands-on device testing. Plus fees are quoted individually.
4. What are the Cyber Essentials Plus requirements?
You need a current Cyber Essentials certificate, an agreed scope, vulnerability scans of that scope and a technical check of a device sample. Since 27 April 2026, v3.3 also wants cloud services in scope and MFA wherever a service offers it.
5. How long does Cyber Essentials Plus certification last?
12 months, the same as basic certification. Then you renew by passing the audit again. Start early, because new question sets can change what the assessor expects.






