VMHOSTS NEWS

Cyber Essentials vs Cyber Essentials Plus: which one do your customers and insurers really want?

Not sure whether the standard certification is enough or if the audited version is worth the extra investment? Here's what customers, insurers and public sector buyers are really looking for.

For most small businesses, standard Cyber Essentials is what customers and insurers are asking for, and Plus is worth the extra only when a contract names it or you hold particularly sensitive data. That is the short answer. The longer one depends on who you sell to, so it is worth understanding what the two certificates really prove.

The first thing to know is that they are the same standard. Both cover the same five controls: firewalls, secure configuration, security updates, user access control and malware protection. Plus, does not add a single extra rule. The difference is who checks that you are following them.

What each one involves

Standard Cyber Essentials is a verified self-assessment. You answer a questionnaire about how your IT is set up, a director signs a declaration that the answers are true, and a certification body reviews it. Nobody visits or touches your systems. You are telling the assessor what you do, and they are checking that your answers meet the standard.

Cyber Essentials Plus is the same questionnaire followed by an independent technical audit. An assessor scans your network from the outside and the inside, tests a sample of your devices, and checks that multi-factor authentication really is switched on for your cloud services. You have to hold the standard certificate first, and the audit has to be completed within three months of it.

 

Cyber Essentials

Cyber Essentials Plus

How it is checked

Self-assessment reviewed by an assessor

Self-assessment plus hands-on technical testing

What it proves

You say the controls are in place

Someone independent confirmed they are

Effort

Days to a few weeks, mostly preparation

Longer, with audit time and likely fixes

Cost

Lower, tiered by company size

Noticeably higher, priced on scope

Renewal

Every 12 months

Every 12 months

Plus also became less forgiving in April 2026. Your self-assessment is now locked once testing starts, so you cannot quietly correct an answer when the audit finds a problem. If you fail on patching, the retest covers the original devices plus a fresh random sample, and a second failure can cost you the standard certificate as well as the Plus one.

What your customers want

Most private sector customers who ask about security want to see the standard certificate. It usually turns up as a line in a supplier questionnaire or a tender: “Do you hold Cyber Essentials?” A yes, with a certificate number, gets you through. Larger enterprises increasingly push this down to their smaller suppliers, so it can arrive without warning.

Plus tends to be named when the work is more sensitive. Think financial services, healthcare, legal work, or anything where you will have access to a customer’s systems. If a customer has not said which level they need, ask them. It is a normal question, and it stops you paying for more than the contract requires.

What the public sector wants

Central government contracts that involve handling personal data or providing IT services generally require standard Cyber Essentials as a minimum. For many suppliers that is the whole reason they certified in the first place.

Plus is typically reserved for higher-risk work. Defence contracts and some NHS work involving patient data are the common examples, and the requirement often flows down to subcontractors too. The level will be stated in the tender documents, so check before you bid, because Plus is not something you can pick up in a week.

What your insurer wants

Insurers mostly care about the controls, not the badge. Cyber insurance proposal forms ask about MFA, patching, backups and admin accounts, which are largely the things Cyber Essentials already covers. Holding the standard certificate makes those forms quicker and more truthful to complete, and some insurers look on it favourably when pricing.

It is rare for an insurer to insist on Plus for a small business. There is also a perk many people miss: UK organisations with a turnover under £20 million can get free cyber insurance with their certification. The government’s own figures say businesses with the controls in place make 92% fewer insurance claims, which tells you why insurers are interested.

So, which one should you go for?

Start with standard Cyber Essentials unless something specific tells you otherwise. You need it before you can do Plus anyway, it satisfies most customers and insurers, and it gets the real security work done. Everything you fix for the standard certificate counts towards Plus later.

Go for Plus if a contract or tender names it, if you handle sensitive data such as health or financial records, or if you want independent proof and not only your own word. Some businesses also choose it as a selling point, because being able to say an auditor tested your systems carries more weight than a questionnaire.

One honest warning. Plus exposes the gap between what a business believes about its IT and what is really there. If you would not be confident with an assessor picking laptops at random, sort that out first. It is far cheaper to find the problems yourself than during a paid audit.

READ OUR LATEST BLOG POSTS & articles

Cyber Essentials vs Cyber Essentials Plus: which one do your customers and insurers really want?

Not sure whether the standard certification is enough or if the audited version is worth the extra investment? Here’s what customers, insurers and public sector buyers are really looking for.

Cloud vs On-Prem Servers in 2026: Is On-Prem still viable?

Discover why infrastructure decisions are no longer a simple cloud-versus-on-prem debate.

What does an MSP actually do? A complete guide to IT Managed Services

Discover what a Managed Service Provider (MSP) does, from IT support and Microsoft 365 management to cybersecurity, backups, disaster recovery and strategic technology planning.

FREE Office 365 Security Health Check

As businesses move to agile mobile solutions such as Office 365, cyber criminals are exploiting this choice, to many Office 365 is new technology platform. Once a business has migrated key services to these always on services they become dependent on their availability and make the assumption the platform is secure by default.