Cyber Essentials vs Cyber Essentials Plus: which do you need?
9 September 2026 · 5 min read
Both certifications cover the same five controls. The difference is verification. Basic Cyber Essentials is a self-assessment questionnaire signed off by a director and reviewed by a certification body. Cyber Essentials Plus adds a hands-on technical audit where an assessor tests a sample of your devices and cloud accounts.
That audit is why Plus costs more and takes longer. An assessor checks that updates really are applied, that malware protection really is active, and that multi-factor authentication really is enforced — rather than taking your word for it.
Who needs Plus? Usually organisations bidding for public sector work that specifies it, suppliers handling sensitive data, and firms whose insurers or largest customers require independent verification. If nobody has asked, basic Cyber Essentials is normally the right starting point.
The sensible sequence is basic first, Plus second. You must hold a valid basic certificate before Plus, and the tidy-up work is identical: individual accounts, no unsupported software, updates applied within the expected window, and multi-factor authentication everywhere it is offered.
If Plus is on the horizon, the deciding factor is evidence discipline. Audits go smoothly for organisations that can show a current list of devices and cloud services with dated checks against each control.
Run the free Kept scan to see how your cloud services would look to an assessor today, then decide which route to take.
Kept