Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
Same five controls, different level of proof — and a meaningful difference in cost, effort and what buyers accept. A practical comparison from a provider that holds the Plus certification itself.
Why the Baseline Matters
Quick answer
Cyber Essentials and Cyber Essentials Plus verify the same five controls — the difference is proof. Basic is a verified self-assessment questionnaire (from around £300–£500+VAT by organisation size, insurance included for eligible orgs); Plus adds an independent technical audit of your actual systems (typically from around £1,500+VAT, priced by the certification body). Choose Plus when enterprise customers, regulated supply chains or government contracts demand audited evidence — it's the tier AMVIA holds itself.
Cyber Essentials vs Plus: At a Glance
| Feature | Cyber EssentialsVerified self-assessment | Cyber Essentials PlusIndependent technical auditRecommended |
|---|---|---|
| The five NCSC controls | ||
| How it's verified | Self-assessment questionnaire, assessor-verified | Hands-on audit: device sampling, vulnerability scans, configuration tests |
| Typical cost (2026) | ~£300–£500+VAT IASME fee, by org size | From ~£1,500+VAT, set by the certification body |
| Cyber liability insurance included | Yes — eligible UK orgs under £20m turnover | Via the underlying basic certification |
| Prerequisite | None | A current basic Cyber Essentials pass (audit within 3 months) |
| Weight with enterprise / government buyers | Baseline — accepted for many contracts | Strongest — audited evidence, often specified |
| Typical timeline once prepared | Days | Weeks (audit scheduling + testing) |
| Renewal | Annual | Annual |
When to Choose Each
Choose Cyber Essentials if...
You need the certificate for eligibility — supplier questionnaires, insurance conditions, or government contracts that specify the basic tier — and you want the five controls verified without an audit budget. It's also the mandatory first step to Plus.
Choose Cyber Essentials Plus if...
Enterprise customers, regulated supply chains or contracts specify audited certification, or you want independent proof the controls actually work on your real devices — not just that you said so. If security is part of how you win business, Plus is the credible tier.
The real cost difference
On paper the gap is roughly £300–£500 vs £1,500+. In practice, most of the first-year spend for either tier is remediation — retiring unsupported software, fixing access control, rolling out MFA — and that work is identical for both. If you'll need Plus within a year anyway (a common procurement trajectory), doing the remediation once and auditing immediately is cheaper than certifying basic now and re-mobilising later.
See the full cost breakdownThe AMVIA Recommendation
The AMVIA Recommendation
If certification is purely a checkbox for one contract, basic Cyber Essentials does the job. If security credibility is part of how you sell — or your buyers are enterprises and public sector — go straight to Plus: the audit is the point. AMVIA holds Cyber Essentials Plus ourselves, and our managed security plans run the five controls day to day, which makes certification an outcome of good operations rather than an annual scramble.
Get certification-readyFrequently Asked Questions
Yes — Plus requires a current basic Cyber Essentials pass, with the technical audit completed within three months of it. In practice most businesses run the two together: pass the questionnaire, then schedule the audit immediately while the evidence is fresh.
An assessor tests a sample of your real devices and systems: vulnerability scans, malware protection checks, patch levels, and how workstations handle test payloads delivered by email and browser. It verifies the controls work in practice — not just that the questionnaire said so.
It varies by contract. Cyber Essentials (either tier) is required for certain UK government contracts, and some — particularly those involving more sensitive data — specify Plus. Check the tender requirements; if you sell into the public sector repeatedly, Plus usually pays for itself in eligibility.
Basic certification through IASME includes cyber liability insurance for eligible UK organisations under £20 million turnover — that benefit attaches at the basic tier. Beyond the bundled policy, insurers increasingly ask about certification at renewal, and audited evidence tends to be viewed more favourably than self-assessment.
Yes — it happens when the questionnaire was answered optimistically. Common failure points: unsupported software still in use, missing MFA, and undeclared devices. A gap analysis before the audit day is far cheaper than a failed assessment and re-test.
Get to Certification with AMVIA
Gap analysis, remediation and audit preparation from a provider that holds Cyber Essentials Plus itself — then ongoing compliance so renewal is routine. No obligation.
Related Resources
Cyber Essentials Explained
What the certification is, the five controls, and why UK buyers now expect it.
How Much Does Cyber Essentials Cost?
IASME fees by organisation size, Plus audit pricing, and the real first-year budget.
Managed Cybersecurity
The ongoing service that keeps the five controls running between renewals.
Vulnerability Management
The patching discipline both tiers demand — run continuously.
Protect your business → Get Cybersecurity Assessment