Cyber Essentials vs Cyber Essentials Plus: Which Does Your Business Need?
- Jason Patey
- Jul 12
- 4 min read

If your business has been asked for Cyber Essentials certification recently, you're not alone. We've taken five businesses through Cyber Essentials so far this year, two of whom went on to achieve Cyber Essentials Plus — and in almost every case, the push came from the same place: a customer or supplier further up the chain asking for proof of security before signing or renewing a contract.
That's the reality of Cyber Essentials in 2026. It has quietly become the entry ticket for supply chains, public sector work, and increasingly, cyber insurance. The question we get asked most isn't "should we get certified?" — it's "which level do we actually need?"
Here's the honest answer.
What Cyber Essentials covers
Cyber Essentials is the UK Government's baseline cyber security standard, backed by the National Cyber Security Centre (NCSC). It certifies that your business has five technical controls in place:
Firewalls — a security boundary between your network and the internet
Secure configuration — devices and software set up to minimise vulnerabilities
Access control — the right people have the right level of access, and no more
Malware protection — defences that catch malicious software before it causes harm
Security update management — software patched and supported, with nothing running out of support
Certification is a verified self-assessment: you answer a detailed question set about your setup, a director signs a declaration, and a licensed assessor reviews your answers. The assessment fee is tiered by company size, starting at £320 + VAT for micro businesses and rising to £600 + VAT for large organisations. UK businesses with under £20m turnover that certify their whole organisation also get £25,000 of cyber liability insurance included.
What Cyber Essentials Plus adds
Cyber Essentials Plus covers exactly the same five controls — but instead of taking your word for it, an independent assessor tests them.
That means external vulnerability scans of your internet-facing systems, hands-on checks of a sample of your laptops, servers and mobile devices, and verification that your malware protection and patching actually work in practice. You need a valid Cyber Essentials certificate first (achieved within the previous three months), and the audit is quoted individually based on the size and complexity of your setup — for most SMEs, typically £1,500–£3,000 + VAT on top of the base certification.
The certificate you receive carries more weight for one simple reason: it's been independently verified, not self-declared.
So which one do you need?
Start with who's asking. If a customer, supplier or tender requires certification, they will usually specify the level — Ministry of Defence contracts and some larger enterprise supply chains mandate Plus, while most commercial contracts accept standard Cyber Essentials.
If nobody's asking yet, our advice is straightforward:
Cyber Essentials is the right starting point for almost every small business. It forces you to fix the basics that stop the majority of common attacks, it satisfies most contractual requirements, and it's affordable.
Cyber Essentials Plus is worth the step up if you handle sensitive client data (legal, financial, healthcare), bid for public sector or defence work, or want the strongest possible answer when a prospect asks about your security. Independently audited beats self-assessed in any due diligence conversation.
Two of the five businesses we certified this year went on to Plus, and both did so because their customers asked for it. We expect that trend to continue — requirements in supply chains only ever move in one direction.
What certification is actually like (from this year's cohort)
Here's what we've learned taking businesses through the process in 2026.
For businesses already on a managed IT plan with us, certification was genuinely light work. The five controls — patching, access control, malware protection, secure configuration, firewalls — are things a properly managed environment already has in place. The assessment mostly involved evidencing what was already true.
One of this year's Cyber Essentials Plus certifications was a brand-new client, and that was a different story. Their environment needed real remediation work before it would pass an independent audit — unsupported software, patching gaps, access control tidying. We got them there, and now that the foundations are in, keeping them certified next year will be a fraction of the effort. That's the pattern with Cyber Essentials: the first year is the climb, and staying certified is much easier than getting certified.
The lesson for any business considering it: your certification cost depends far less on the assessment fee than on the state of your IT going in.
How Pebble IT can help
We're a Cyber Essentials and Cyber Essentials Plus certified MSP ourselves, and we guide businesses across Hertfordshire, Essex and London through both levels — from a readiness review of your current setup, through remediation, to the assessment itself. If you've been asked for certification, or you want to get ahead before you are, book a call and we'll tell you honestly which level fits and what it'll take to get there.
Frequently asked questions
How long does Cyber Essentials certification take?
For a well-maintained IT environment, the self-assessment can be completed in days. If remediation is needed — replacing unsupported software, fixing patching gaps, tightening access — allow several weeks. Cyber Essentials Plus adds an audit that must be completed within three months of your base certificate.
Does Cyber Essentials certification expire?
Yes — both levels are valid for 12 months and must be renewed annually. The question set is updated periodically, so requirements can tighten between renewals. Businesses on a managed IT plan generally find renewal straightforward because the controls are maintained year-round rather than fixed up once a year.
Will Cyber Essentials actually make my business more secure?
Yes. The five controls address the most common attack routes — unpatched software, weak access control, missing malware protection. The NCSC estimates these controls prevent the majority of common, untargeted cyber attacks. Certification is the proof; the controls are the protection.




Comments