Cyber Readiness Pro
Back to guides

About certification

Cyber Essentials vs Cyber Essentials Plus: what's the difference?

Cyber Essentials ("Basic") is a self-assessment: you answer a detailed questionnaire covering the same five control areas (firewalls, secure configuration, patching, access control, and malware protection) and a certification body reviews and verifies your answers remotely. Cyber Essentials Plus covers the same five areas, but replaces self-reporting with independent technical verification: an assessor actually scans and tests a sample of your real devices, rather than taking your word for it.

Basic is enough to satisfy most supplier questionnaires, contract clauses, and insurer requirements, and it's the faster, cheaper route to get certified. Plus tends to get specified for higher-risk sectors or larger contracts (health, defence, and some public-sector frameworks) where a buyer wants proof, not just a signed declaration, that the controls are actually in place.

Most small and medium businesses start with Basic, since it's what almost every contract actually asks for, and only move to Plus if a specific client or tender requires it. Run the free 5-minute readiness check to see where you stand against the Basic controls either way, since they're the same foundation for both.