For most small businesses, standard Cyber Essentials is what customers and insurers are asking for, and Plus is worth the extra only when a contract names it or you hold particularly sensitive data. That is the short answer. The longer one depends on who you sell to, so it is worth understanding what the two certificates really prove.
The first thing to know is that they are the same standard. Both cover the same five controls: firewalls, secure configuration, security updates, user access control and malware protection. Plus, does not add a single extra rule. The difference is who checks that you are following them.
What each one involves
Standard Cyber Essentials is a verified self-assessment. You answer a questionnaire about how your IT is set up, a director signs a declaration that the answers are true, and a certification body reviews it. Nobody visits or touches your systems. You are telling the assessor what you do, and they are checking that your answers meet the standard.
Cyber Essentials Plus is the same questionnaire followed by an independent technical audit. An assessor scans your network from the outside and the inside, tests a sample of your devices, and checks that multi-factor authentication really is switched on for your cloud services. You have to hold the standard certificate first, and the audit has to be completed within three months of it.
 | Cyber Essentials | Cyber Essentials Plus |
How it is checked | Self-assessment reviewed by an assessor | Self-assessment plus hands-on technical testing |
What it proves | You say the controls are in place | Someone independent confirmed they are |
Effort | Days to a few weeks, mostly preparation | Longer, with audit time and likely fixes |
Cost | Lower, tiered by company size | Noticeably higher, priced on scope |
Renewal | Every 12 months | Every 12 months |
Plus also became less forgiving in April 2026. Your self-assessment is now locked once testing starts, so you cannot quietly correct an answer when the audit finds a problem. If you fail on patching, the retest covers the original devices plus a fresh random sample, and a second failure can cost you the standard certificate as well as the Plus one.
What your customers want
Most private sector customers who ask about security want to see the standard certificate. It usually turns up as a line in a supplier questionnaire or a tender: “Do you hold Cyber Essentials?” A yes, with a certificate number, gets you through. Larger enterprises increasingly push this down to their smaller suppliers, so it can arrive without warning.
Plus tends to be named when the work is more sensitive. Think financial services, healthcare, legal work, or anything where you will have access to a customer’s systems. If a customer has not said which level they need, ask them. It is a normal question, and it stops you paying for more than the contract requires.
What the public sector wants
Central government contracts that involve handling personal data or providing IT services generally require standard Cyber Essentials as a minimum. For many suppliers that is the whole reason they certified in the first place.
Plus is typically reserved for higher-risk work. Defence contracts and some NHS work involving patient data are the common examples, and the requirement often flows down to subcontractors too. The level will be stated in the tender documents, so check before you bid, because Plus is not something you can pick up in a week.
What your insurer wants
Insurers mostly care about the controls, not the badge. Cyber insurance proposal forms ask about MFA, patching, backups and admin accounts, which are largely the things Cyber Essentials already covers. Holding the standard certificate makes those forms quicker and more truthful to complete, and some insurers look on it favourably when pricing.
It is rare for an insurer to insist on Plus for a small business. There is also a perk many people miss: UK organisations with a turnover under £20 million can get free cyber insurance with their certification. The government’s own figures say businesses with the controls in place make 92% fewer insurance claims, which tells you why insurers are interested.
So, which one should you go for?
Start with standard Cyber Essentials unless something specific tells you otherwise. You need it before you can do Plus anyway, it satisfies most customers and insurers, and it gets the real security work done. Everything you fix for the standard certificate counts towards Plus later.
Go for Plus if a contract or tender names it, if you handle sensitive data such as health or financial records, or if you want independent proof and not only your own word. Some businesses also choose it as a selling point, because being able to say an auditor tested your systems carries more weight than a questionnaire.
One honest warning. Plus exposes the gap between what a business believes about its IT and what is really there. If you would not be confident with an assessor picking laptops at random, sort that out first. It is far cheaper to find the problems yourself than during a paid audit.