Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Cyber Essentials vs Cyber Essentials Plus: Which One Does Your Business Need?

In short

Cyber Essentials is a UK government-backed scheme that proves you have five basic security controls in place. The standard version is a self-assessment; the Plus version adds a hands-on technical audit. This guide explains the real difference, which one you need, what it costs in time and money, and the 2026 change that requires MFA for cloud services.

Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.

What Cyber Essentials is, without the jargon

Cyber Essentials is a UK government-backed certification that shows your business has the basics of security in place. It is run by IASME on behalf of the National Cyber Security Centre (NCSC), and it focuses on five straightforward controls that, between them, stop the majority of common cyber attacks.

Those five controls are:

  • Firewalls — a barrier between your systems and the internet.
  • Secure settings — devices and software set up safely rather than left on default.
  • Access control — people only have access to what they actually need.
  • Malware protection — defences against viruses and malicious software.
  • Security updates — software kept patched and current.

None of that is exotic. It is the security equivalent of locking your doors and windows. The value of the certificate is that it proves, to customers, insurers and larger clients, that you have done it.

The real difference between the two levels

There are two versions of the certification, and the difference is simpler than the names suggest.

Cyber Essentials (the standard version) is a self-assessment. You complete a questionnaire about how your systems are set up, and your answers are reviewed and marked. You are essentially certifying, in good faith, that you meet the five controls.

Cyber Essentials Plus covers exactly the same five controls, but adds an independent technical audit. A qualified assessor examines your systems hands-on to confirm that what you described is genuinely true in practice. They will test a sample of your devices and check things really are configured the way you said.

The simplest way to think about it: Cyber Essentials is you saying you have the basics covered; Cyber Essentials Plus is an independent assessor confirming that you actually do.

That is the whole distinction. Same standard, but Plus is verified rather than self-declared, which is why it carries more weight and costs more.

Which one do you actually need?

For a lot of small businesses, standard Cyber Essentials is the right starting point. It is often the exact requirement for bidding on public-sector work or supplying larger organisations, and it gives you a solid, recognised baseline.

You will need Cyber Essentials Plus when:

  • a client, tender or government framework specifically asks for it;
  • you handle particularly sensitive data and want the stronger assurance;
  • you want the added confidence that your controls have been independently tested.

The golden rule is to read the exact wording of any contract you are chasing. “Cyber Essentials” and “Cyber Essentials Plus” are not interchangeable, and turning up with the wrong one can cost you the work. If you are unsure, it is worth a quick conversation before you spend anything.

The audit: what to expect

For standard Cyber Essentials, there is no site visit. You work through the questionnaire, submit it, and it is assessed. The effort is in the honesty and accuracy of your answers, and in fixing anything that does not yet meet the mark.

For Cyber Essentials Plus, the assessor will typically:

  • test a sample of your computers and devices;
  • check that security updates are being applied;
  • confirm malware protection is working;
  • verify that access controls and secure settings are genuinely in place;
  • often run a scan to look for obvious vulnerabilities.

It is not meant to be an ordeal, but it is a real check. The businesses that sail through are the ones that treated the questionnaire as a genuine description of a well-run setup, not an aspiration.

Cost and effort, honestly

Certification fees for standard Cyber Essentials are tiered by the size of your organisation and start at a modest level for the smallest firms. Cyber Essentials Plus costs more because it includes the assessor’s time for the audit. Fees are reviewed periodically, so always check the current figures with IASME rather than relying on an old number.

Here is the part people underestimate: the certificate fee is rarely the main cost. The real work is the preparation, getting everything into a state that meets the standard before you apply. If your basics are already in good order, a self-assessment can be a matter of days. A first-time Plus, starting from scratch, can take a few weeks once you factor in the fixes.

This is where having your IT and security managed properly pays off. When updates, access control and secure settings are looked after continuously, certification stops being a scramble and becomes a formality.

The 2026 MFA-for-cloud change

The scheme is deliberately kept in step with how attacks actually happen, and it is updated over time. The change small businesses most need to know about is that multi-factor authentication (MFA) for cloud services is now a firm requirement rather than an optional extra.

In plain terms, that means every cloud account your business uses, including administrator accounts, needs that second login check on top of the password. Given how many businesses run on cloud email and file storage, this affects nearly everyone.

If you are certifying in 2026, the practical advice is:

  • turn on MFA across all your cloud services before you apply, not during;
  • pay special attention to admin accounts, which are often overlooked;
  • confirm the exact current requirements with IASME, as the scheme is refreshed periodically.

MFA is one of the single most effective things you can do to protect your business, certification aside. If you have not rolled it out yet, do it regardless of whether you are chasing a certificate. A password manager makes MFA far easier for staff to adopt without a fight.

Where to start

If Cyber Essentials is on your to-do list, the best first step is an honest look at where you stand today against the five controls. That tells you whether you are days away from certifying or whether there is groundwork to do first.

We help Leeds and Yorkshire businesses get certified without the stress, and keep them there year after year. You can learn more about our cyber-security work, or simply book a free IT and security review and we will tell you plainly which level you need and what it will take to get there.

Frequently asked questions

What is Cyber Essentials in simple terms?

It is a UK government-backed certification, run by IASME on behalf of the National Cyber Security Centre (NCSC), that shows your business has five basic security controls in place. Those controls cover firewalls, secure settings, access control, protection against malware, and keeping software updated. Achieving it tells customers and insurers you have covered the fundamentals that stop the most common attacks.

What's the actual difference between the two levels?

Cyber Essentials is a self-assessment: you answer a questionnaire about your setup and it is reviewed. Cyber Essentials Plus covers the same five controls but adds an independent technical audit, where an assessor tests your systems to confirm the answers are true in practice. Plus is more rigorous and more expensive, because someone actually checks rather than taking your word for it.

Which one do I need?

For many small firms, standard Cyber Essentials is enough and is often the entry requirement for public-sector or larger contracts. If a client, framework or tender specifically asks for Plus, or you handle particularly sensitive data, you will need the Plus audit. When in doubt, check the exact wording of any contract you are chasing.

How much does it cost and how long does it take?

Standard Cyber Essentials certification fees are tiered by organisation size and start at a modest level for the smallest firms; Plus costs more because it includes the hands-on audit. The bigger cost is usually the preparation, fixing anything that does not yet meet the standard. With basics already in place, self-assessment can take days; a first-time Plus can take a few weeks. Check current fees with IASME as they are reviewed periodically.

What is the 2026 MFA change?

The scheme is being kept in step with modern threats, and multi-factor authentication for cloud services has become a firm requirement rather than a nice-to-have. In practice that means every cloud account, including admin accounts, needs a second login check. If you are certifying in 2026, make sure MFA is switched on everywhere before you apply, and confirm the exact current requirements with IASME.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.