Cyber Essentials certification has quietly become one of the most consequential procurement decisions a UK business makes each year — not because the badge itself is glamorous, but because so many doors now stay shut without it. Government contracts, cyber insurance renewals, enterprise supplier onboarding and supply-chain due-diligence questionnaires increasingly treat the scheme as a minimum entry ticket, and the single question owners keep getting wrong is whether the self-assessed Cyber Essentials badge is enough or whether they need the independently audited Cyber Essentials Plus.
This comparison breaks down the two certification levels the way a buyer actually experiences them: what each one costs in 2026, what the five technical controls demand in practice, how the assessment differs, and—crucially—how to read a contract clause or an insurance schedule to work out which level you are genuinely being asked for. By the end you will be able to look at a tender document, an insurer’s proposal form or a client’s vendor questionnaire and say with confidence “we need Plus” or “the basic badge covers this” — and understand exactly what your organisation has to fix before either one will pass.
What Cyber Essentials and Cyber Essentials Plus actually are
Cyber Essentials is a UK government-backed certification scheme owned by the National Cyber Security Centre (NCSC) and delivered on its behalf by IASME as the sole accreditation body, working through a network of licensed certification bodies. It exists to verify that an organisation has five fundamental technical controls in place: firewalls, secure configuration, security update management (patching), user access control and malware protection. Those five controls are deliberately basic. They are the measures that, according to NCSC, would stop the overwhelming majority of the commodity, internet-borne attacks that hit UK businesses every day — the automated scanning, the exploited unpatched services, the password-guessing and the untargeted phishing.
The scheme comes in two tiers that share exactly the same technical requirements but differ entirely in how those requirements are checked. Cyber Essentials (the base level) is a verified self-assessment: you complete a detailed question set, a senior person signs a declaration that the answers are true, and a certification body assessor reviews and marks it. Cyber Essentials Plus keeps the identical self-assessment and then adds a hands-on technical audit by a qualified assessor — internal and external vulnerability scans, tests of malware protection, and a sample of your actual user devices — to prove that what you declared on paper is genuinely true in practice.
Put simply, the base level asks “do you say you have these controls?” and Plus asks “can an independent assessor confirm you actually do?” The gap between those two questions is where most of the cost, the effort and the commercial value lives. Understanding that gap is the entire point of this guide.
Both certifications last twelve months and cover the same five controls. If you plan to reach Plus within the year, scope and configure for Plus from day one — passing the basic self-assessment against a soft scope only to fail the Plus audit later is the single most common and most expensive mistake in the whole scheme.
Cyber Essentials vs Cyber Essentials Plus at a glance
The fastest way to see the difference is side by side. Both tiers demand the identical five controls, the same twelve-month validity and the same scope definition — everything that differs flows from the assessment method. The card on the right is highlighted because, for any organisation whose contracts or insurers care about assurance rather than a tick-box, Cyber Essentials Plus is the level that actually carries weight.
Cyber Essentials
Verified self-assessment
Cyber Essentials Plus
Independently audited
The pattern is consistent: the base badge is cheaper, faster and self-declared; Plus costs more and takes longer because someone independent verifies your estate. Neither is “better” in the abstract — the right choice is the one your buyers, insurers and risk profile actually require, which is what the rest of this guide helps you pin down.
Where UK businesses actually fall short of the five controls
Before you can choose a level, you need an honest view of where your organisation stands against the five controls today, because both tiers fail on the same gaps — Plus just catches them with a scan instead of a signature. The score grid below maps the most common weak points we see across UK SMEs, graded by how often they cause a certification to be delayed or refused.
The high-risk row is where almost every failed assessment concentrates. Since the scheme made multi-factor authentication mandatory for cloud services and tightened the patching window to fourteen days for high and critical vulnerabilities, the two most common reasons an organisation does not pass are an unenforced MFA policy on a SaaS platform and a forgotten machine running an operating system the vendor no longer supports. Fix those two and you have removed the majority of the certification risk for either tier.
Cyber Essentials by the numbers — the UK 2026 reality check
Certification decisions are easier when you can see the market context. The figures below sit behind why so many UK organisations are certifying now, and why insurers and buyers keep raising the bar. They are indicative of the wider UK SME landscape rather than a promise about any single business.
Those four numbers frame the whole decision. The entry fee is modest and banded by organisation size; the control set is small and fixed; the patching expectation is genuinely tight; and the clock resets every year, which means certification is a recurring operating commitment, not a one-off project. Businesses that treat it as an annual rhythm — rather than a scramble the week before a tender deadline — find both tiers dramatically cheaper to sustain.
What drives UK businesses to certify in the first place
Understanding the demand side helps you judge which level you need, because the reason you are certifying usually dictates the assurance your counterparty expects. The bar chart below shows the relative weight of the drivers we see behind UK certification decisions — the taller the bar, the more often it is the deciding factor.
Notice how the top three drivers are exactly the ones most likely to specify Plus. Central government contracts that handle personal or sensitive information, prime contractors flowing requirements down their supply chain, and insurers pricing a policy on demonstrable control maturity all tend to want verified assurance rather than a self-declaration. If your reason for certifying sits near the top of this chart, plan for Plus; if you are certifying mainly to reassure a small client or satisfy your own board’s baseline, the base badge is frequently sufficient.
Control-by-control readiness across the five requirements
Both tiers assess the same five controls, so a realistic self-appraisal against each is the foundation of the decision. The progress bars below reflect the average maturity we encounter among UK SMEs when they first engage — use them as a mirror for where your own estate is likely to need work before either assessment.
Average UK SME maturity against the five controls
The two lowest bars — asset inventory accuracy and MFA coverage — are exactly why Plus catches organisations out. You cannot secure or scan what you have not inventoried, and an audit that samples real devices will surface the machine nobody remembered and the SaaS login that never had a second factor. Firewalls and malware protection sit high because they are usually bought-in and enabled by default; the harder controls are the human, process-driven ones. This is the single most useful lens for deciding readiness: if your patching, MFA and inventory bars are low, the base self-assessment might squeak through on a generous declaration, but a Plus audit will not.
The certification journey — what a real path to the badge looks like
Whether you aim for the base badge or Plus, the sequence of work is broadly the same; Plus simply extends the tail with the audit and any remediation it uncovers. The timeline below is a realistic path for a UK SME going from a standing start to a certificate.
The important detail for the base-versus-Plus decision is the last two active stages. If you certify at the base level, your journey ends at assessor review. If you need Plus, you must budget both the extra weeks and the reality that the audit will test the very controls where the progress bars above were lowest — so front-loading the remediation is what keeps the Plus audit from becoming a second, more expensive remediation round.
Which level do you need? A quick readiness gauge
Combine the drivers, the contract wording and your control maturity into a single readiness score and the decision usually makes itself. The gauge below reflects a typical mid-market UK business that has firewalls and anti-malware sorted but still has MFA and patching gaps — strong enough to attempt the base badge, not yet ready to sail through a Plus audit.
As a rule of thumb: a readiness score below 50 means fix the fundamentals and target the base badge first; 50–75 means you can achieve the base level now and reach Plus with a focused remediation sprint; above 75 means you are genuinely audit-ready and should go straight for Plus to capture its commercial and insurance value. If a contract explicitly names Plus, the gauge does not change the destination — it only tells you how much work stands between you and passing.
Cyber Essentials cost breakdown for 2026
Pricing for the base level is fixed by IASME and banded by organisation size, so it is predictable; Plus is priced on the scope and sample of your estate, so it varies more. The table below gives indicative 2026 figures — always confirm the exact fee with your chosen certification body, as some bundle support, remediation guidance or readiness assessments into their quote.
| Organisation size | Cyber Essentials (base) | Cyber Essentials Plus (indicative total) | What Plus adds |
|---|---|---|---|
| Micro (0–9 staff) | £320 + VAT | £1,700–£2,200 + VAT | Small device sample, single-site scan |
| Small (10–49 staff) | £400 + VAT | £2,000–£2,800 + VAT | Larger sample, more cloud services tested |
| Medium (50–249 staff) | £450 + VAT | £2,800–£4,500 + VAT | Multi-site scans, bigger device sample |
| Large (250+ staff) | £500 + VAT | £4,500+ VAT, scoped per estate | Complex scope, segmented networks |
The headline is that the base badge is a few hundred pounds while Plus runs into low thousands — but the audit fee is rarely the real cost. The genuine investment is the remediation work the Plus audit forces you to complete: enforcing MFA everywhere, replacing unsupported hardware and software, and tightening patch management. Those are improvements you should be making regardless, which is why many boards treat the Plus fee as the trigger that finally funds overdue security housekeeping. Budgeting only for the certificate and not the remediation is how organisations end up paying for two audits.
How much of the UK market has already certified
Certification is no longer a niche signal — it is becoming an expected baseline, and the proportion of UK organisations that hold a current certificate keeps climbing as tenders and insurers make it a condition. The donut below shows an indicative share of the SMEs we work with that hold either level within a given twelve-month period.
Of that certified group, the majority still hold only the base level, but the share choosing Plus rises sharply among organisations that bid for public-sector work or sit in a regulated supply chain. The direction of travel is clear: as more buyers specify Plus and more insurers reward it, the base badge is increasingly a starting point rather than a destination. If your sector is trending toward Plus, certifying at the base level now while planning the Plus audit for your next renewal is a sensible, budget-friendly path.
The Cyber Essentials readiness checklist
Work through this ordered checklist before you engage a certification body for either tier. Every item maps to one of the five controls or to scope accuracy, and clearing them is what turns a nervous submission into a confident one.
- Produce an accurate asset inventory of every in-scope device, server, laptop, mobile and cloud service — nothing hidden, nothing forgotten.
- Confirm no unsupported or end-of-life operating systems or software remain in scope; remove, replace or properly segregate anything past vendor support.
- Enforce multi-factor authentication on every cloud and internet-facing service, for all users, not just administrators.
- Verify that high and critical security updates are applied within fourteen days, and that automatic updates are enabled wherever possible.
- Change every default password and remove or rename default accounts on devices, firewalls and network equipment.
- Separate administrative accounts from everyday user accounts, and confirm admin rights are granted only where genuinely needed.
- Ensure a correctly configured firewall protects every internet connection, including home workers’ routers or a software firewall on remote devices.
- Confirm malware protection is active, updating and set to scan on every in-scope endpoint.
- Review secure configuration — disable unnecessary services, auto-run features and unused accounts.
- Document your account joiner, mover and leaver process so access is promptly revoked when people change roles or leave.
- Gather supporting evidence (screenshots, policy documents, configuration exports) so a Plus assessor can verify claims quickly.
- Nominate a senior signatory who understands the estate and can honestly attest to the declaration.
Clearing this checklist certifies you against the base badge and prepares you for Plus in one pass. The only additional Plus-specific step is booking the technical audit, which must normally take place within three months of your base self-assessment being awarded.
A real-world example — choosing between the two levels
Consider a Leeds-based professional-services firm of forty-two staff that lost a public-sector framework place because the tender required Cyber Essentials Plus and it held only the base badge. When it re-examined its estate, it found MFA missing on two SaaS platforms, three laptops running an unsupported operating system, and a patch process that relied on staff clicking “remind me later”. The base self-assessment had passed the year before on a generous declaration; a Plus audit would have failed immediately on the vulnerability scan.
The firm spent roughly six weeks closing the gaps — enforcing MFA tenant-wide, replacing the three laptops, and moving to a managed patch schedule — then passed Plus at the next attempt and requalified for the framework. The lesson its operations director drew was not about the certificate itself but about the honesty the audit forced.
We treated the base badge as a formality and the Plus audit as a threat. In hindsight the audit was the useful one — it made us prove things we only assumed were true, and every gap it found was a gap a real attacker could have used. We now scope for Plus every year, even for the controls only the base badge strictly requires.
The pattern generalises. Organisations that need Plus almost always discover that the assurance gap between “we declared it” and “an assessor proved it” is exactly where their genuine risk was hiding. Choosing the level your contracts demand is the commercial decision; choosing to actually meet the controls is the security one.
Common Cyber Essentials mistakes to avoid
Most failed or painful certifications trace back to a short list of avoidable errors. Steer around these and either tier becomes far more predictable.
- Under-scoping to make the badge easier. Carving obvious problem devices out of scope may pass the base self-assessment, but it produces a certificate that does not cover the systems your buyers care about — and a Plus audit will expose the gap.
- Treating the base badge as equivalent to Plus. If a contract or insurer specifies Plus, a base certificate does not satisfy it; assuming otherwise loses tenders and voids cover.
- Leaving MFA to administrators only. The scheme expects multi-factor authentication across all users on cloud services, and this is now one of the most common single points of failure.
- Forgetting home and mobile devices. Remote-working laptops and phones that access corporate data are in scope; overlooking them is a frequent audit surprise.
- Ignoring the 14-day patch window. A relaxed “we patch monthly” posture no longer meets the requirement for high and critical updates.
- Certifying reactively the week before a deadline. Rushing remediation invites errors; a standing annual programme is cheaper and calmer.
- Letting the certificate lapse. A twelve-month gap in certification can disqualify you mid-contract; diarise recertification well ahead of expiry.
- Signing a declaration nobody verified. The senior signatory is attesting to accuracy — an over-optimistic declaration that an audit later contradicts is both an assurance and an integrity problem.
The most expensive mistake is passing the base self-assessment against a soft scope and then discovering — at the Plus audit or, worse, during a real incident — that the systems your clients rely on were never actually covered. Scope honestly the first time.
Cyber Essentials vs Plus — the decision at a glance
Use this summary table as the one-page reference when you sit down with a tender document, an insurance schedule or your own risk register and need to decide which level to pursue.
| Question | Base Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| How are controls checked? | Self-declared, assessor-marked | Independently audited & scanned |
| Indicative base cost | £320–£500 + VAT | Base fee plus £1,400–£2,500+ |
| Typical time to certify | Days to two weeks | Two to six weeks |
| Technical controls covered | All five | All five (verified) |
| MFA on cloud services required? | Yes | Yes & tested |
| 14-day patch window? | Yes | Yes & scanned |
| Validity | 12 months | 12 months |
| Meets baseline gov contract clauses | Often | Yes, including higher-assurance |
| Preferred by insurers | Usually accepted | Preferred, may reduce premium |
| Best for | Baseline reassurance, smaller clients | Public sector, regulated supply chains |
| Assurance level | Basic | Strong |
| Recommended when contract is silent | Start here | Upgrade if buyers or insurers value proof |
Read the row that matches your situation and the answer is usually obvious. If nobody is asking for verified assurance and budgets are tight, the base badge is a sound, credible starting point. The moment a contract names Plus, an insurer rewards it, or your own risk appetite demands proof rather than promises, Plus is the level that actually delivers.
Getting certified with Cloudswitched
Cloudswitched helps UK businesses scope, prepare for and achieve both Cyber Essentials and Cyber Essentials Plus — from an honest gap assessment against the five controls, through the remediation work that closes those gaps, to standing beside you at the audit. The aim is a certificate that reflects a genuinely secure estate, not a badge that papers over one.
Not sure which level your contracts require?
We will assess your estate against the five controls, tell you honestly whether the base badge or Plus fits your obligations, and map the shortest credible path to passing.
Get Cyber Essentials CertifiedFrequently Asked Questions
Is Cyber Essentials Plus just a harder version of Cyber Essentials?
No — the technical requirements are identical. Both tiers assess the same five controls: firewalls, secure configuration, security update management, user access control and malware protection. The difference is entirely in verification. The base level is a self-assessment that a director signs and an assessor marks, while Cyber Essentials Plus keeps that same self-assessment and adds an independent hands-on audit with vulnerability scans and device sampling. Plus is not more controls, it is more proof that the controls are genuinely in place.
How much does Cyber Essentials certification cost in 2026?
The base Cyber Essentials fee is set by IASME and banded by organisation size, starting at around £320 + VAT for micro organisations and rising to roughly £500 + VAT for the largest. Cyber Essentials Plus adds a technical audit priced on your scope and device sample, so an indicative total commonly falls between £1,700 and £4,500 + VAT for most SMEs. The bigger cost is usually the remediation the audit demands rather than the fee itself.
Do I need Cyber Essentials Plus to bid for government contracts?
It depends on the contract. Many central government contracts that involve handling personal or sensitive information specify Cyber Essentials Plus, while others accept the base certificate. The tender documentation states which level is required — read the security schedule carefully. If it names Plus, the base badge will not satisfy it. If it simply says “Cyber Essentials” without qualification, the base level is often acceptable, but confirm with the buyer rather than assuming.
How long does Cyber Essentials certification take?
A well-prepared organisation can complete the base self-assessment in a few days to a couple of weeks, depending on how much remediation is needed. Cyber Essentials Plus takes longer — typically two to six weeks — because it adds scheduling the audit, running the scans and fixing anything they uncover. The audit itself must usually happen within three months of the base self-assessment being awarded, so plan the two together rather than as separate projects.
What are the five Cyber Essentials controls?
The five technical controls are firewalls, secure configuration, security update management (patching), user access control, and malware protection. Together they defend against the most common internet-based threats such as automated scanning, exploited unpatched software, password guessing and commodity malware. Both certification tiers assess exactly these five, so any weakness — missing MFA, slow patching, unsupported software — affects both the base badge and Plus equally.
How long is a Cyber Essentials certificate valid?
Both Cyber Essentials and Cyber Essentials Plus certificates are valid for twelve months. You must recertify each year to keep a continuous, in-date certificate, which many contracts and insurers require. Because the controls have to stay live all year rather than only at assessment time, the most cost-effective approach is to treat certification as an annual operating rhythm with continuous patching, MFA and inventory management, not a once-a-year scramble.
Does Cyber Essentials require multi-factor authentication?
Yes. The scheme requires multi-factor authentication on cloud services for all users, not only administrators. This is one of the most common reasons organisations fail or have to remediate, because MFA is often enabled for admins but left optional for general staff. For Cyber Essentials Plus the auditor will actively test that MFA is enforced, so a policy that exists on paper but is not applied in practice will be caught during the audit.
Will Cyber Essentials reduce my cyber insurance premium?
Certification frequently helps with cyber insurance in two ways: many insurers now require at least base Cyber Essentials for cover to be available at all, and holding a certificate — particularly Plus — can improve the terms offered because it demonstrates verified control maturity. It is not a guaranteed discount and varies by insurer, but it is increasingly a condition of eligibility. Check your insurer’s proposal form: it will usually ask which level you hold.
Can I go straight for Cyber Essentials Plus without the base level first?
In practice the base self-assessment is part of the Plus process — you complete and pass the self-assessment, then undertake the audit, normally within three months. So you do not buy two entirely separate things, but you cannot skip the self-assessment stage. If your goal is Plus, scope and remediate to the Plus standard from the outset so the audit confirms what you have already built rather than exposing gaps you then have to fix.
What happens if I fail the Cyber Essentials Plus audit?
A failed audit is not the end — the assessor documents what did not meet the requirement, you remediate the issue, and the relevant tests are repeated. The practical cost is time and, depending on the certification body, possibly a re-test fee. This is exactly why front-loading remediation matters: fixing MFA, patching and unsupported software before the audit turns it into a confirmation rather than a second, more expensive remediation cycle.
Does Cyber Essentials cover home and remote workers?
Yes. Devices used by home and remote workers to access organisational data or services are in scope, including laptops, mobiles and the home network boundary. This catches many organisations out because those devices are easy to forget when defining scope. Both tiers expect home workers to be covered by a firewall (their router or a software firewall), up-to-date patching, malware protection and MFA, and a Plus audit may sample remote devices directly.
Is Cyber Essentials enough, or should I aim for ISO 27001?
Cyber Essentials is a focused technical baseline, whereas ISO 27001 is a comprehensive information security management system covering governance, risk, people and process. They are complementary rather than competing: many organisations achieve Cyber Essentials or Plus first as a fast, affordable foundation and use it as a stepping stone toward ISO 27001 later. For most UK SMEs facing contract and insurance requirements today, Cyber Essentials Plus is the pragmatic priority.
Related reading
Continue building your security and compliance foundations with these related Cloudswitched guides:
- Cloud Backup Compliance, GDPR and Cyber Essentials in the UK for 2026
- Microsoft 365 Email Security: DKIM, SPF and DMARC Explained for UK Businesses
- Network Administration Best Practices for UK SMEs
- Managed IT Support Agreements: What UK Businesses Should Look For
- Azure Cost Management and Optimisation for UK SMEs
Ready to certify with confidence?
Whether you need the base badge to reassure a client or full Cyber Essentials Plus to win a public-sector framework, Cloudswitched will scope the work, close the gaps in your five controls and get you audit-ready without over-engineering or overspending.
Start your Cyber Essentials journey
Talk to Cloudswitched about the right certification level for your contracts, your insurer and your risk profile — and the shortest credible path to passing.
Get Cyber Essentials Certified