Cyber & Data Security

The difference between Cyber Essentials and Cyber Essentials PLUS

This article was updated on:
Mar 13th, 2019

The difference between Cyber Essentials and Cyber Essentials PLUS

We are often asked about the differences between the Cyber Essentials and Cyber Essentials PLUS standard, and what level they should choose.

There are some circumstances that will dictate the level you are required to have in tenders, especially with Government contracts, and the level there depends on the risk that they associate with the particular contract. But for everyone else, here’s a brief run down on the two levels of certification.

The Cyber Essentials Scheme

Cyber Essentials is a security standard that is designed to mitigate against the most common cyber attacks, and University of Lancaster research has shown that with Cyber Essentials controls in place 99% of the common attacks they tested against where either fully mitigated (69.2%) or partially mitigated (29.8%). There is a set list of requirements that your organisation is required to meet as published by the National Cyber Security Centre (Part of GCHQ).

The Cyber Essentials (basic) is a self-certification that is assessed by companies such as ours, to validate the answers. This means that you’re asked to supply answers to a questionnaire (with evidence) through our online portal, assessment at this level is simply a pass or fail and feedback given on areas of non compliance.

Cyber Essentials PLUS builds on the self certification questionnaire, as it is an independently audited test of the controls required by the ‘basic’ level, along with an internal and external vulnerability scan. This means that we, as a certification body will visit your offices and perform a test that is in line with the Cyber Essentials requirements. Every certification body will have the same test process, however – the costs may vary.

The vulnerability scan will identify unpatched, or unsupported software, open ports, incorrect firewall configurations – all elements that the basic level will require your own working knowledge of your IT systems to answer.

So what one should I choose?

That can really only be answered by your motivations for gaining the accreditation, are you doing it as we said at the start (as part of a tender requirement) or are you just looking to check your business has the basics in place?

When bidding on a contract/procurement/tender

The tender will specify if PLUS is required, if not, the self certification is the minimum requirement.

Your own internal business reasons

So you want to demonstrate that your organisation is compliant with Cyber Security and takes data protection seriously – then Cyber Essentials PLUS is more likely the route for you. You get the confidence as a business that your own IT department / Outsourced IT Provider are doing the basics to keep you safe and they are not just ‘marking’ their own work, as they might be if helping you complete the self assessment questionnaire.

Insurance

By using a source outside of the organisation to conduct and certify the level of compliance, you can be sure there are no biased opinions and you don’t risk invalidating your insurance. You are more likely to reduce premiums with the PLUS standard as well, where as self certification will not.

Keen to learn more? Explore our other related resources below:
December 13, 2025
Password ‘Sextortion’ and Ransomware
Cyber & Data Security
July 1, 2025
How Might Hackers Exploit My Cyber Security? 7 Tricks Small Business Owners Need-To-Know!
Cyber & Data Security
May 1, 2025
MFA Isn’t Optional Anymore: Here’s Why
Cyber & Data Security
IT Management, Policies & Certifications
April 1, 2025
Why Digital Offboarding Needs to Be on Your Radar!
Cyber & Data Security
February 12, 2025
Upgrading to Windows 11: It’s ESSENTIAL, Let us explain why!
Cyber & Data Security
February 1, 2025
11 Simple Steps to Keep Your Microsoft 365 Data Safe
Cyber & Data Security
Microsoft 365
May 23, 2022
The 5 Benefits of Outsourcing IT Support
IT Management, Policies & Certifications
Cyber & Data Security
May 12, 2021
Cyber Essentials Toolkit
Cyber & Data Security
April 19, 2021
Why your Business needs Microsoft 365 Backup
IT Management, Policies & Certifications
Cyber & Data Security
March 4, 2021
Is Microsoft 365 Secure? Our 5 Essential Tips to Stay Safe
Microsoft 365
Cyber & Data Security
February 1, 2021
Free Cyber Security Awareness Training!
Cyber & Data Security
December 20, 2020
Why Do Businesses Only Care About Cyber Security Once They Get Hacked?
Cyber & Data Security
October 17, 2019
Ransomware – Should You Be Worried? 
Cyber & Data Security
August 12, 2019
Identity Fraud - Easier Than Ever
Cyber & Data Security
March 28, 2019
Invoice Diversion Scenario
Cyber & Data Security
March 26, 2019
Phishing/Ransom Attack Scenario, What Would You Do?
Cyber & Data Security
December 4, 2018
What is the Difference Between Penetration Testing and Vulnerability Scanning?
IT Management, Policies & Certifications
Cyber & Data Security
November 28, 2018
How Secure is My Password?
Cyber & Data Security
November 2, 2018
How much help do I need to get Cyber Essentials Certified?
Cyber & Data Security
October 23, 2018
What is an SSL certificate and why do I need one?
IT Management, Policies & Certifications
Cyber & Data Security
October 3, 2018
Defining the Scope for Cyber Essentials
Cyber & Data Security
October 1, 2018
Is it time to switch your IT partner?
Cyber & Data Security
October 1, 2018
The Facebook Breach: This is What You Need to do NOW...
Cyber & Data Security
September 20, 2018
Email Spoofing Scenario
IT Management, Policies & Certifications
Cyber & Data Security
August 24, 2018
What is OneDrive and why should my business be using it? 
Telecoms & Connectivity
Cyber & Data Security
August 20, 2018
What is GDPR?
Cyber & Data Security
August 15, 2018
Server VS Cloud - Which is best for your business?
Telecoms & Connectivity
Cyber & Data Security
August 14, 2018
Why Should I get my business Cyber Essentials certified?
Cyber & Data Security
August 14, 2018
How Much Does Outsourced IT Support Cost in 2023?
IT Management, Policies & Certifications
Cyber & Data Security
May 1, 2018
The Difference between NCSC Small Business Guide & Cyber Essentials
Cyber & Data Security
December 2, 2017
Cyber Essentials Certification: Everything You Need to Know
Cyber & Data Security
January 22, 2009
Are there any substitutes to ISO 27001 suitable for my business?
Cyber & Data Security
IT Management, Policies & Certifications