Cyber Essentials is the baseline cyber security certification that the UK Government recommends for organisations of every size. It was developed by the experts at the National Cyber Security Centre (NCSC) and is described in the scheme's own materials as a government-backed, industry-supported scheme that helps organisations protect themselves against common online threats.

Cyber Essentials Plus is the step above it. The protections are the same, but the checking is not. Plus adds more rigorous, independent technical testing of your systems instead of relying on a verified self-assessment alone.

For a UK SME, the real question is rarely "what is it" and far more often "do we need it, which level, and what does it actually change?" This guide answers those three questions using the scheme's published information, and explains where an independent consultant fits into the process.

What Is Cyber Essentials?

Cyber Essentials is a certification scheme that defines a baseline set of cyber security controls every organisation should have in place. The NCSC describes it as the minimum standard of cyber security recommended by the Government for organisations of all sizes.

The scheme is built around five controls. Those controls are designed to reduce the impact of commodity cyber attacks, the everyday, low-effort attacks that make up the bulk of what most businesses actually face. The certification is annually renewable, and it is an independently verified self-assessment: you answer the questions, but someone independent checks the answers.

Because the controls are reviewed over time, it is worth checking the NCSC's official Cyber Essentials pages for the current wording of the five controls before you start preparing. That way you are working from the live specification rather than a version someone shared two years ago.

What Is Cyber Essentials Plus?

Cyber Essentials Plus keeps exactly the same controls and protections, then adds a technical audit of your IT systems to verify that those controls are genuinely in place rather than simply declared. That audit is carried out by trained assessors, and the scheme materials describe it as more rigorous, independent technical testing.

The practical result is a greater level of assurance. With Cyber Essentials, a reviewer is checking that you have understood and answered the questions correctly. With Plus, someone is testing the estate to confirm the controls work as described.

One certification provider describes Cyber Essentials Plus as helping protect against up to 80% of common cyberattacks. Treat figures like that as a useful indication of scope rather than a guarantee, because the scheme defends against common and commodity threats, not against every possible targeted attack.

Pricing works differently too. Cyber Essentials Plus is priced according to the size and complexity of your IT systems, so a fifteen-person firm with one office will not be quoted the same as a multi-site business with remote workers. Always ask for a written, fixed quote before you commit.

information security
Photo by Ann H on Pexels

Cyber Essentials vs Cyber Essentials Plus: the differences that matter

The table below sets out the practical distinctions between the two levels.

Aspect

Cyber Essentials

Cyber Essentials Plus

Controls covered

The five baseline controls

The same five controls, to the same standard

How it is assessed

Independently verified self-assessment

Technical audit of your IT systems by independent assessors

Level of assurance

Confirms the organisation has the important controls in place

Greater assurance, because the controls are tested as well as declared

Typical driver

A baseline security credential and a first step

Buyers, tenders or supply chains that want evidence of testing

Pricing basis

Ask your provider for a quote

Set according to the size and complexity of your IT systems

Why a UK SME would bother with certification

A small business with no certification can still be reasonably secure. What certification adds is structure, evidence and a deadline. These are the benefits that tend to matter most.

  • A defined baseline instead of guesswork. The scheme tells you which controls matter most, which is far more useful than a general instruction to "be more secure".

  • Reduced exposure to common attacks. The controls are designed to reduce the impact of commodity cyber attacks, the ones most likely to hit an SME.

  • Something concrete to show a customer. When a client or procurement team asks how you protect their data, a certification badge is a clearer answer than a paragraph of reassurance.

  • A route into higher-assurance supply chains. Defence suppliers and organisations working under stricter customer requirements often need Cyber Essentials Plus or Defence Cyber Certification rather than the basic level.

  • An annual discipline. Because the certification is annually renewable, it forces a review rather than allowing security to drift for years after one project.

  • Build resilience against cyberattacks. Framed properly, the scheme is about resilience and recovery as much as prevention.

server room
Photo by panumas nikhomkhai on Pexels

Who provides Cyber Essentials certification?

The NCSC sets and publishes the standard. Certification itself is issued through the scheme's network of certification bodies and licensed assessors rather than by the NCSC directly, and the Plus technical audit is carried out by trained assessors working for those bodies.

That structure matters when you are buying. A consultant can prepare you, build the evidence and run you through what the assessor will look for, but the certificate is issued by the certification body. The two roles are separate, and good consultants are clear about the boundary.

The NCSC's official Cyber Essentials overview is the best place to verify which organisations are currently licensed to certify, because the list of bodies does change over time. Anyone quoting you should be able to tell you plainly who will be issuing your certificate.

Smart Quality Services Ltd is an independent UK ISO consultancy headquartered in Dorset and delivering nationwide. Alongside UKAS-accredited ISO certification support, the company delivers Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification with CyberSmart, for a fixed fee, covering gap analysis through to the assessment itself.

Does Cyber Essentials reduce cyber insurance costs?

This is one of the most common reasons businesses start looking at certification, so it deserves a straight answer. The published scheme materials do not set out insurance pricing, and no certification body can promise you a specific discount on your premium.

What certification does give you is documented, independently verified evidence that a recognised baseline of controls is in place. That is exactly the kind of evidence an insurer or broker may ask for when they assess how well your business manages cyber risk. Some organisations find that presenting a current certificate helps the conversation, and others find it makes little difference to price.

The honest position is this: ask your broker directly, before you certify, what they would need to see to review your cover, and whether a current Cyber Essentials or Cyber Essentials Plus certificate is part of that. Shop around if you have to. Certification is a security investment first, and an insurance lever second, which means it stands up on its own merits even if the premium does not move.

Which level should your business choose?

Start with the requirement. If a customer, tender or prime contractor has specified Cyber Essentials, that is the level you need. If the requirement says Plus, or asks for evidence that your controls have been independently tested, only Plus will satisfy it.

If nothing has been specified, Cyber Essentials is a sensible starting point for most SMEs. It is quicker to reach, it exposes the gaps in your setup, and it gives you a foundation to build on. Businesses that go straight to Plus often find they are fixing the same underlying issues, just with an assessor watching.

Worth knowing: Cyber Essentials is a baseline. It is not a replacement for a broader information security management system, and holding it does not mean your security programme is complete. Many organisations hold both a baseline certification and a wider standard, and the work overlaps enough that a consultant can usually map it once rather than twice.

Frequently Asked Questions

Is Cyber Essentials the same as Cyber Essentials Plus?

No. They cover the same baseline controls, but the assessment differs. Cyber Essentials is an independently verified self-assessment, while Cyber Essentials Plus adds a technical audit of your IT systems to verify the controls are genuinely in place. That extra verification is why Plus carries a greater level of assurance, and why it is priced according to the size and complexity of your IT estate.

How long does Cyber Essentials certification last?

Certification is annually renewable. You will need to reassess each year to keep it current, which effectively makes the scheme an annual check that your controls are still doing what they should. That is also part of what makes the certificate valuable to buyers: it reflects a recent assessment rather than a one-off project completed several years ago.

Is Cyber Essentials Plus worth it?

It depends on who you sell to. If a customer, tender or supply chain expects proof that your controls were tested rather than simply declared, Plus is usually the level that satisfies them. If you are starting from scratch, many organisations certify to Cyber Essentials first, fix what the self-assessment exposes, then move up to Plus.

Who can certify my business?

Certification is issued through the scheme's network of certification bodies and licensed assessors, not directly by the NCSC. The official NCSC Cyber Essentials pages publish the current scheme information and the best route to verify who is licensed to certify. Many businesses use a consultancy to prepare for the assessment and a certification body to issue it.

Talk to Smart Quality

Tell us what you need help with. Our team will be in touch to discuss your enquiry.

Loading the enquiry form…

Prefer to speak to us? Call 01202 374272.