If you’ve looked into Cyber Essentials, you’ve probably noticed there are two versions. Basic Cyber Essentials and Cyber Essentials Plus. The basic version gets more attention because it’s cheaper and faster. But if you’re supplying to the NHS, bidding on certain government contracts, or working in specific sectors like defence supply chains, Cyber Essentials Plus is often what’s actually required. This guide covers what the difference actually involves and whether it’s worth pursuing beyond when you’re contractually required to.

What Basic Cyber Essentials Gives You

Basic Cyber Essentials is a self-assessment. You answer a questionnaire about five control areas: firewalls, secure configuration, user access control, malware protection, and patch management. The answers are verified by an assessor from an IASME-accredited body, but they’re verified against what you’ve told them, not against what your systems actually do. The process typically takes a few days and costs somewhere between £300 and £500 plus the IASME verification fee.

It’s worth having. The five controls address a significant proportion of common attack vectors, and the certification signals to clients and partners that you’ve at least thought seriously about the basics. For most small business purposes, it’s sufficient.

What Cyber Essentials Plus Adds

Here’s where it gets materially different. Cyber Essentials Plus includes all the same controls, but the assessor actually tests whether your systems comply rather than just checking your answers. That means technical vulnerability scanning of your network-facing systems, a hands-on assessment of a sample of your devices, and verification that your patch levels, configuration settings, and access controls work as you’ve described.

The assessment is typically remote these days, though on-site options exist. The assessor will scan your external-facing IP addresses and a selection of internal systems. They’ll check that updates are applied, that malware protection is functioning, that multi-factor authentication is in place where it should be. If anything fails, you get a remediation window, but the bar is genuinely higher than self-assessment.

The cost reflects this. Cyber Essentials Plus typically runs from £1,500 to £5,000 depending on the size of your organisation and the number of systems in scope. For a small business with ten employees and straightforward IT, the lower end of that range is realistic. For a company with complex network architecture or multiple sites, expect more.

When You Actually Need It

The clearest trigger is contractual requirement. Central government contracts for certain categories require Cyber Essentials Plus, not basic. NHS Digital supply chain requirements frequently specify Plus. If you’re tendering in defence or some local authority frameworks, check the tender specification carefully.

Beyond mandatory requirements, there are situations where the additional credibility is worth the cost. If you’re moving into enterprise sales where procurement teams run vendor due diligence, Cyber Essentials Plus gives you a verification that procurement departments recognise as independent rather than self-reported. It also tends to reduce the number of security questionnaires you have to fill in manually, because the certificate answers many of the questions those forms ask.

Cyber liability insurance is the other factor. Some insurers offer meaningful premium reductions for Cyber Essentials Plus holders. If your premium is significant, it’s worth asking your broker whether the Plus certification would change your rate before you decide whether to pursue it.

The Practical Differences in Preparation

If you’re already compliant with basic Cyber Essentials, the preparation for Plus isn’t dramatic. The main things to check are that patching really is current across all in-scope devices (not just on paper), that your firewall configuration is actually restricting inbound traffic as described, and that your admin account controls work as specified.

The places where businesses trip up in Plus assessments are usually around patching. A device with a missed update, a software installation that’s reached end-of-life, or a test machine that was excluded from your update schedule can cause a failure. Before the assessment, run your own internal scan to find anything that’s fallen behind. Tools like OpenVAS or a commercial vulnerability scanner will surface the same issues the assessor will find.

Multi-factor authentication configuration is another common stumbling block. The Cyber Essentials controls require MFA for cloud services, and the Plus assessment will verify this is actually enabled and enforced, not just available as an option that users can bypass.

Choosing an Assessor

Assessors for Cyber Essentials Plus must be accredited through IASME, which holds the scheme on behalf of the NCSC. The IASME website lists accredited bodies. Compare quotes from two or three, and ask specifically what’s included in the scope, how they handle remediation if something fails, and what their typical timeline is from assessment to certificate.

Some certification bodies offer a pre-assessment gap analysis, which can be useful if you’re not confident about where you stand. It costs extra but reduces the risk of a failed full assessment, which costs money and time to remediate and resubmit.

Is It Worth Doing Without a Contract Requirement?

To be honest, for most small businesses without a specific contractual or sector requirement, the cost-benefit case for Plus over basic isn’t straightforward. The basic certificate gives you most of the positioning value with insurers and enterprise clients. Plus gives you independent verification rather than self-assessment, which matters in some procurement contexts and less in others.

If you’re planning to grow into markets where Plus is routinely expected, getting certified sooner rather than later means the controls become embedded rather than added in a rush before a contract deadline. That’s probably the strongest argument for it as a proactive choice. Otherwise, start with basic, maintain compliance, and upgrade when a contract or client specifically asks for it.