Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?

Same five controls, different level of proof — and a meaningful difference in cost, effort and what buyers accept. A practical comparison from a provider that holds the Plus certification itself.

Why the Baseline Matters

43%of UK businesses experienced a cyber breach or attack in the past 12 months (DSIT 2025)
5technical controls verified by both tiers — firewalls, configuration, access, malware, updates
£20mturnover threshold under which basic certification includes cyber liability insurance for eligible UK orgs
3 monthswindow after a basic pass in which the Plus audit must complete

Quick answer

Cyber Essentials and Cyber Essentials Plus verify the same five controls — the difference is proof. Basic is a verified self-assessment questionnaire (from around £300–£500+VAT by organisation size, insurance included for eligible orgs); Plus adds an independent technical audit of your actual systems (typically from around £1,500+VAT, priced by the certification body). Choose Plus when enterprise customers, regulated supply chains or government contracts demand audited evidence — it's the tier AMVIA holds itself.

Cyber Essentials vs Plus: At a Glance

Feature
Cyber EssentialsVerified self-assessment
Cyber Essentials PlusIndependent technical auditRecommended
The five NCSC controls
How it's verifiedSelf-assessment questionnaire, assessor-verifiedHands-on audit: device sampling, vulnerability scans, configuration tests
Typical cost (2026)~£300–£500+VAT IASME fee, by org sizeFrom ~£1,500+VAT, set by the certification body
Cyber liability insurance includedYes — eligible UK orgs under £20m turnoverVia the underlying basic certification
PrerequisiteNoneA current basic Cyber Essentials pass (audit within 3 months)
Weight with enterprise / government buyersBaseline — accepted for many contractsStrongest — audited evidence, often specified
Typical timeline once preparedDaysWeeks (audit scheduling + testing)
RenewalAnnualAnnual

When to Choose Each

Choose Cyber Essentials if...

You need the certificate for eligibility — supplier questionnaires, insurance conditions, or government contracts that specify the basic tier — and you want the five controls verified without an audit budget. It's also the mandatory first step to Plus.

Choose Cyber Essentials Plus if...

Enterprise customers, regulated supply chains or contracts specify audited certification, or you want independent proof the controls actually work on your real devices — not just that you said so. If security is part of how you win business, Plus is the credible tier.

The real cost difference

On paper the gap is roughly £300–£500 vs £1,500+. In practice, most of the first-year spend for either tier is remediation — retiring unsupported software, fixing access control, rolling out MFA — and that work is identical for both. If you'll need Plus within a year anyway (a common procurement trajectory), doing the remediation once and auditing immediately is cheaper than certifying basic now and re-mobilising later.

See the full cost breakdown

The AMVIA Recommendation

The AMVIA Recommendation

If certification is purely a checkbox for one contract, basic Cyber Essentials does the job. If security credibility is part of how you sell — or your buyers are enterprises and public sector — go straight to Plus: the audit is the point. AMVIA holds Cyber Essentials Plus ourselves, and our managed security plans run the five controls day to day, which makes certification an outcome of good operations rather than an annual scramble.

Get certification-ready

Frequently Asked Questions

Get to Certification with AMVIA

Gap analysis, remediation and audit preparation from a provider that holds Cyber Essentials Plus itself — then ongoing compliance so renewal is routine. No obligation.