New Blog
Understanding Cyber Essentials vs Cyber Essentials Plus and Which One You Need
Cyber Essentials and Cyber Essentials Plus both help organisations strengthen their protection against common cyber threats, but they offer different levels of assurance.
In this blog, we break down the key differences between the two certifications, how each assessment works and what businesses should consider when deciding which level is right for them.


Cyber security is no longer something businesses can afford to treat as an afterthought. One of the best ways to ensure your organisation is protected against common cyber-attacks is by undertaking Cyber Essentials.
This raises the question however, which level should I go for, and what is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials vs Cyber Essentials Plus
Cyber Essentials and Cyber Essentials Plus are two sides of the same coin. They have the same fundamental technical controls and requirements. The difference is how they are assessed and the level of scrutiny involved by the assessor.
For Cyber Essentials, your assessment would typically follow this process;
You fill out and submit your Cyber Essentials questionnaire
An assessor will mark the answers against the Cyber Essentials standard and identify any areas requiring further information or non-compliances
Remediations or clarifications are made and the questionnaire resubmitted
The assessor passes the assessment and Cyber Essentials is achieved
For Cyber Essentials Plus, once Cyber Essentials has been achieved, there is further assessment to ensure that what has been claimed in the Cyber Essentials is accurate using an array of technical and manual checks including;
External vulnerability scans
Internal vulnerability scans
Manual technical checks of workstations
Antivirus tests
Cloud services checks
Network separation checks
These tests give a greater level of assurance that an organisation is adhering to the technical controls and requirements effectively.
Which do you need?
When deciding which level of Cyber Essentials to go for, Cyber Essentials Plus may be the preferred option for organisations that want a higher level of independent assurance and greater confidence for customers and supply-chain partners whereas Cyber Essentials alone may not provide that same confidence.
Some organisations have a requirement to achieve some level of Cyber Essentials as part of contracts or supply chain requirements. In these cases, the contract or supply chain will likely stipulate if Plus is needed or not.
It is also worth considering where your organisation is heading, not just where it is today. If you are planning to bid for larger contracts, work with public sector organisations or enter more security-conscious supply chains, achieving Cyber Essentials Plus can help demonstrate that your controls have been independently tested.
Taking that extra step may also make future procurement and due diligence conversations easier by giving potential customers clearer evidence of your cyber security approach.
Taking the next step
Whether you choose Cyber Essentials or Cyber Essentials Plus, certification can provide a valuable framework for strengthening your organisation's cyber security. The key is to understand your current environment, identify any gaps and make sure your systems and processes meet the relevant requirements.
For businesses unsure which certification to pursue, speaking with the team here at Worknest can help you assess your requirements and prepare for certification.
Cyber security is an ongoing process, not a one-time exercise. Cyber Essentials can provide a strong foundation, while Cyber Essentials Plus offers additional independent assurance. Choosing the right level means balancing your organisation's risks, requirements and security objectives and taking practical steps to protect your business in an increasingly connected world.
Share your challenge with us and we’ll help you find the right level of support for your business.












