Cyber Essentials

Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?

> series: cyber_essentials_demystified —— part: 09/10 —— comparison: CE_vs_CE_Plus —— verdict: it_depends<span class="cursor-blink">_</span>_

Hedgehog Security 2 April 2026 12 min read

Same five controls. Very different assurance.

Both Cyber Essentials (CE) and Cyber Essentials Plus (CE+) certify against the same five technical controls. The difference is how compliance is verified. CE is a verified self-assessment — you declare your controls are in place and an assessor reviews your answers. CE+ adds a hands-on technical audit where the assessor independently tests your systems to verify that the controls work in practice. The distinction matters because self-declarations and technical reality do not always match.


Recommended

Getting certified doesn't have to be painful.

We handle the Cyber Essentials process end to end — from gap analysis to certification.

Start Your Certification

A direct comparison.

Aspect Cyber Essentials (CE) Cyber Essentials Plus (CE+)
Assessment method Verified self-assessment questionnaire (Danzell question set). The assessor reviews your answers for accuracy and completeness. Everything in CE, plus an independent technical audit. The assessor directly tests your devices, networks, and cloud services.
What the assessor tests Your answers — checked against the requirements for consistency, completeness, and plausibility. No hands-on technical verification. Vulnerability scanning of in-scope devices. Verification of patch levels. MFA enforcement testing. Configuration checks. Browser and email malware protection testing.
Level of assurance Baseline — confirms you have declared the right controls. Based on trust in the accuracy of your self-assessment. Higher — confirms the controls are genuinely in place and working. Independent verification provides evidence that goes beyond self-declaration.
Typical cost £300 – £500 for the assessment fee. May be higher with consultancy or concierge support. £1,500 – £3,500 depending on scope (number of devices, cloud services, and locations). Includes the CE self-assessment plus the technical audit.
Duration Typically 1–2 weeks from submitting the questionnaire to certification, depending on the certification body's workload. Typically 2–4 weeks, including the self-assessment phase and the technical audit window.
Who accepts it Satisfies the minimum Cyber Essentials requirement for government contracts and many supply chain requirements. Required by many enterprise clients, defence supply chain organisations, NHS trusts, and financial services firms. Provides stronger evidence for insurance and regulatory purposes.

What actually happens during the technical assessment.

The CE Plus technical audit is conducted by a qualified assessor — typically remotely, using a combination of vulnerability scanning and manual verification. The assessor tests a representative sample of your in-scope devices and verifies compliance with each of the five controls.

Device Sampling and Scanning
The assessor selects a random sample of in-scope devices and runs vulnerability scans to check for missing patches, outdated software, and configuration weaknesses. Under Danzell, if the initial sample fails and remediation is applied, a second random sample is tested to verify that fixes were applied estate-wide — not just to the tested devices.
MFA Verification
The assessor tests that MFA is genuinely enforced on all cloud services in scope. This typically involves logging into each service from a new session and confirming that a second factor is required. If you declared MFA is enabled but it is not actually enforced, the assessment fails.
Email and Web Malware Testing
The assessor sends test emails with simulated malicious attachments and tests whether malicious websites are blocked by your web filtering. This verifies that your malware protection is active and correctly configured, not just installed.
Configuration Verification
The assessor checks device configurations against the Cyber Essentials requirements — auto-lock settings, firewall state, administrative account controls, and unnecessary services. Discrepancies between your self-assessment answers and the actual configuration are flagged.

Making the right choice.

Scenario Recommended Level
You need Cyber Essentials for a specific tender or contract Check the requirement. If it specifies 'Cyber Essentials Plus', CE alone will not satisfy it. If it says 'Cyber Essentials' without specifying Plus, CE is sufficient — but CE+ provides stronger differentiation.
You are in the defence supply chain CE Plus is the expected standard for MoD supply chain organisations. CE alone is unlikely to satisfy defence prime contractors' requirements.
You want genuine assurance that your controls work CE Plus. The independent technical audit verifies that your controls are not just declared but genuinely effective. CE alone confirms your intentions; CE+ confirms your reality.
You are an SME on a tight budget and want baseline certification Start with CE. It provides a recognised baseline and opens doors to many contracts. Plan for CE+ as your next step when budget allows.
Your insurer or regulator requires evidence of security testing CE Plus. The technical audit provides evidence of independent verification — a self-assessment alone may not satisfy insurers or regulators seeking proof that controls have been tested.

How to prepare for the CE Plus audit.

The most effective preparation for CE Plus is to know your own position before the assessor arrives. Run your own vulnerability scans, verify your MFA enforcement, check your patching state, and audit your configurations. Every issue you find and fix before the assessment is one fewer potential failure during it.

Our vulnerability scanning service provides the same type of scanning the CE Plus assessor will run — giving you a preview of your results before the assessment begins. Our Concierge service goes further, handling the entire preparation and certification process end-to-end so you can focus on running your business.


Part 10 — the finale.

In the final article of this series, we bring everything together into a practical Cyber Essentials action plan — a step-by-step timeline from initial preparation through to certification, with specific guidance for the Danzell requirements and checklists for both CE and CE Plus.


Hedgehog Security is your certification body.

As an IASME-approved certification body, we certify organisations at both levels. Our <a href="/cyber-essentials/concierge">Concierge service</a> handles everything — gap analysis, remediation guidance, self-assessment support, and CE Plus technical audit — in a single engagement. For organisations that want continuous security beyond certification, <a href="https://www.socinabox.co.uk">SOC in a Box</a> provides 24/7 monitoring with <a href="https://www.socinabox.co.uk/blog/cyber-essentials-certification-uk-small-business-guide">Cyber Essentials support</a> built in.

Next Step

Getting certified doesn't have to be painful.

We handle the Cyber Essentials process end to end — from gap analysis to certification.

Start Your Certification

Related Articles