What’s the Difference and Why Does It Matter?
Cyber Essentials has become one of the most recognised cyber security certifications in the UK.
For some organisations, it is a contractual requirement. For others, it is a way to demonstrate a commitment to cyber security, improve resilience, and provide reassurance to customers, suppliers, and stakeholders.
Yet one question comes up time and time again:
“Do we need Cyber Essentials or Cyber Essentials Plus?”
The answer depends on your requirements, but before making that decision it is worth understanding what each certification involves, the benefits they provide, and what the assessment process actually looks like.
Why Cyber Essentials Matters
At its core, Cyber Essentials focuses on reducing the risk from common cyber attacks.
The scheme is built around a number of fundamental security controls including:
- Secure configuration
- User access control
- Security update management
- Malware protection
- Firewalls and boundary controls
While these controls may sound basic, many successful cyber attacks still exploit weaknesses in these areas.
In fact, some of the most common issues we encounter during penetration tests involve missing updates, weak access controls, unsupported software, excessive permissions, or poorly managed devices.
Cyber Essentials helps organisations establish a strong baseline and provides confidence that key security controls are in place.
For customers and suppliers, certification demonstrates that cyber security is being taken seriously.
For organisations themselves, it often highlights weaknesses that may otherwise go unnoticed.
Cyber Essentials vs Cyber Essentials Plus
The easiest way to think about the difference is this:
Cyber Essentials is a self-assessment certification.
Cyber Essentials Plus independently verifies that the controls are actually working.
Both certifications assess the same technical controls, however the assessment approach differs significantly.
Cyber Essentials
Cyber Essentials is completed through an online questionnaire covering the technical controls required by the scheme.
Organisations provide information about how their environment is secured and how the controls are implemented.
An assessor then reviews the responses, requests clarification where required, and determines whether the organisation meets the requirements of the scheme.
Cyber Essentials Plus
Cyber Essentials Plus builds on the Cyber Essentials certification by introducing independent technical verification.
Rather than simply reviewing responses, the assessor actively validates that controls are operating as expected.
This includes testing a sample of devices and reviewing security controls to confirm they meet the scheme requirements.
The result is a much higher level of assurance.
The Securebytes Approach
Before certification begins, many organisations choose to undertake a readiness or gap assessment.
This is particularly useful for businesses that have never completed Cyber Essentials before, have undergone significant infrastructure changes, or simply want confidence before submitting their certification.
A readiness assessment helps identify any areas that may require attention before the formal certification process begins.
In many cases, this avoids delays, unnecessary stress, and repeated submissions.
Think of it as checking everything is in order before the assessment starts.
The Cyber Essentials Process
The Cyber Essentials process is relatively straightforward.
Once engaged, Securebytes provides access to the Cyber Essentials questionnaire through the IASME portal.
The organisation completes the questions based on their environment and current security controls.
Throughout this process, we remain available to provide guidance and help interpret the requirements where necessary.
This is often where organisations benefit most from working with an experienced certification body.
Many questions seem straightforward at first glance but can become more nuanced once cloud services, remote working, mobile devices, and modern IT environments are involved.
Once the questionnaire is complete, we review the submission, assess the responses, and work through any clarification points before final certification is issued.
The Cyber Essentials Plus Process
Cyber Essentials Plus introduces a practical verification stage.
The process typically begins with a preparation call where we discuss the environment, gather the necessary information, explain the assessment process, and agree a suitable assessment date.
Three days before the assessment, we provide a sample list of devices that will need to be available during the assessment.
This allows organisations time to prepare users and ensure the required devices are available.
On the day of the assessment, we create a Microsoft Teams meeting and invite the relevant users.
The assessment itself is generally straightforward and usually takes around fifteen minutes per user.
During this time we review the selected devices, verify security controls, and perform the technical checks required by the scheme.
Following the assessment, we complete the required reporting and provide the certification outcome.
For most organisations, the process is considerably less intrusive than they expect.
Important Changes Introduced in April 2026
The April 2026 Cyber Essentials updates introduced several important changes, particularly around device sampling for Cyber Essentials Plus assessments.
One of the most notable changes was the introduction of second samples where issues are identified within the initial device sample. The purpose of this change is to provide greater confidence that security controls are consistently applied across the organisation rather than being limited to a small number of devices.
In practical terms, organisations need to ensure controls are applied consistently across their entire environment rather than assuming a small sample will be sufficient. While this does increase the importance of preparation, it ultimately improves the value and assurance provided by the certification.
The Biggest Challenge We See: Vulnerability Management
If there is one area that causes more issues than any other during Cyber Essentials assessments, it is vulnerability management and patching.
Many organisations believe they are fully patched because Windows Update reports that there are no outstanding updates.
Unfortunately, it is rarely that simple.
Modern environments contain far more than Windows itself.
Microsoft Office, browsers, VPN clients, remote support tools, PDF readers, conferencing applications, security software, and countless other applications all require maintenance and patching.
One commonly overlooked setting is:
“Receive updates for other Microsoft products”
When disabled, organisations may miss updates for Office, .NET components, SQL components, Edge, and other Microsoft software installed on devices.
Then there are third-party applications which often receive even less attention.
This is where visibility becomes important. Many organisations simply do not know which vulnerabilities exist across their estate because they have no way of identifying them.
A vulnerability management programme helps provide that visibility by identifying missing patches, outdated software, and known vulnerabilities before they become a compliance issue or, more importantly, a security incident.
While Cyber Essentials does not require a full vulnerability management programme, organisations that have visibility into vulnerabilities generally find compliance significantly easier to maintain over time.
More Than a Certification
One of the biggest misconceptions about Cyber Essentials is that it is simply a badge.
In reality, the certification process often uncovers security weaknesses that organisations were completely unaware of.
For many businesses, Cyber Essentials becomes the starting point for improving cyber security maturity, rather than the finish line. The organisations that gain the most value are usually those that treat it as an opportunity to strengthen security rather than simply a compliance exercise.
Final Thoughts
Whether you choose Cyber Essentials or Cyber Essentials Plus, both certifications provide valuable assurance that fundamental security controls are in place and operating effectively.
Cyber Essentials demonstrates that your organisation has implemented the required controls.
Cyber Essentials Plus independently verifies those controls through technical testing.
Both play an important role in improving security, reducing risk, and demonstrating commitment to protecting your organisation and its data.
If you are considering Cyber Essentials, Cyber Essentials Plus, or would like assistance with a readiness assessment before certification, speak to the team at Securebytes. As an IASME Certification Body, we help organisations navigate the process with practical advice, clear guidance, and a focus on making certification as straightforward as possible.

