Quick Answer
Cyber Essentials is self-assessed. Cyber Essentials Plus is independently verified by a technical assessor. CE Plus proves your controls actually work, not just that you claim they do.
The Key Difference
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment type | Self-assessment questionnaire | Technical verification |
| Who checks | You answer questions | Assessor tests your systems |
| What it proves | You've thought about security | Your controls actually work |
| Cost | £300-400 | £1,200-2,500 |
| Time | 2-3 weeks | 4-6 weeks |
What CE Plus Testing Includes
An assessor will actually probe your systems:
- Vulnerability scan of external-facing systems
- Configuration checks on a sample of devices
- Simulated phishing to test email controls
- Verification that patches are current and MFA is working
Which One Do You Need?
Cyber Essentials (basic) is fine if:
- You want baseline certification for general credibility
- Your customers don't specifically require CE Plus
- You're just getting started with formal security
- You're in the defence supply chain (DEFCON 658 mandates it)
- Your customers specifically ask for CE Plus
- You want to prove your security, not just claim it
- You're bidding on government contracts with data handling
The Real Difference
Basic CE asks: "Do you have MFA enabled?"
CE Plus checks: "Is MFA actually enabled on these accounts, right now?"
That gap between policy and reality is exactly where breaches happen.
