Cyber Essentials Vs. Cyber Essentials Plus: What Is The Difference?


Here’s a number worth knowing first. Organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance, according to the NCSC’s review of the scheme’s first decade. That comes from the insurer’s own data, so it counts claims, not every breach. It’s still striking for a scheme built on just five controls: firewalls, secure configuration, user access control, malware protection and patching.

You can prove those five controls in two ways. With basic certification, you fill in a questionnaire. With Plus, an assessor tests your real systems. The difference between Cyber Essentials and Cyber Essentials Plus matters more this year, because the v3.3 “Danzell” question set went live on 27 April 2026. It’s stricter on cloud services, multi-factor authentication, and patching.

Below, we have compared Cyber Essentials vs Cyber Essentials Plus on method, cost, audit depth, and pass bar. Then we will discuss how the Plus process works and which level your contract or insurer really wants.

What Are Cyber Essentials?
So, what is Cyber Essentials in practice? It’s the government-backed baseline scheme the NCSC launched in 2014, and IASME now runs it for them. You answer a questionnaire about the five controls. A certification body marks it, and someone senior signs the declaration.

Here’s the thing: nobody tests anything. The certificate reflects how you describe your setup, not how an outsider would find it. That’s a real limitation. But it’s still useful, because plenty of teams find a forgotten admin account or an unsupported laptop while filling the form in. Fees are fixed by IASME and exclude VAT. The certificate lasts 12 months, so you renew every year.

Same requirements, different checker. Instead of reading your answers, a certification body audits your environment. IASME’s own comparison says the audit can run on site or remotely. It includes vulnerability scans of your scoped systems and tests on a sample of devices, like servers, laptops, tablets, and phones.

That’s where your policy meets reality. You say critical patches go on within 14 days, so the assessor goes and looks at the machines.

You can’t skip straight to Plus, because it sits on top of the basic certificate. But if you sit the audit within three months of your last Cyber Essentials certificate, you don’t repeat the questionnaire. The IASME FAQ covers that rule.

How many people bother? The NCSC’s Annual Review 2025 counts 39,790 basic certificates and 12,850 Cyber Essentials Plus certifications in 2024 to 2025. Roughly one in four certified organisations picked the audited route.

source: https://qualysec.com/cyber- ...

Retour Suivant