Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?
Cyber Essentials offers two certification levels: Cyber Essentials and Plus. Both cover the same five core security controls, but they differ significantly in how those controls are verified. Choosing the right level depends on your organisation's requirements, risk profile, and the expectations of your customers and partners.
The Core Difference: Self-Assessment vs Third-Party Verification
Cyber Essentials is the self-assessed certification level. Your organisation completes a questionnaire covering five control categories – firewalls, secure configuration, security update management, user access control, and malware protection. An IASME-accredited certification body reviews your answers and issues the certificate if you meet the requirements.
Cyber Essentials Plus adds independent, third-party verification. An external auditor reviews your self-assessment, then conducts a technical audit of your systems. This includes vulnerability scanning of your external-facing infrastructure and verification that the controls you described are actually implemented and working.
Side-by-Side Comparison
When Cyber Essentials Is Sufficient
Cyber Essentials is appropriate when:
When You Need Plus
Cyber Essentials Plus is the right choice when:
The Assessment Process for Each Level
Cyber Essentials process with Fig:
1. Purchase your Cyber Essentials certification (select organisation size)
2. Complete the self-assessment questionnaire
3. Submit for review – orders before midday – certified in under 6 hours
4. Receive structured feedback if any gaps are identified (up to 3x)
5. Certificate issued on successful completion
Plus process with Fig:
1. Achieve Cyber Essentials certification first (this is a prerequisite)
2. Purchase your Cyber Essentials Plus certification
3. Schedule the third-party technical audit
4. Auditor conducts vulnerability scanning and control verification (1–3 days)
5. Certificate issued on successful completion
Can I Start with Cyber Essentials and Upgrade Later?
Yes. Many organisations start with Cyber Essentials to meet an immediate requirement, then upgrade to Plus when the business case demands it. Since Cyber Essentials is a prerequisite for Plus, achieving it first is always the right starting point.
Fig's Recommendation
For most organisations, start with Cyber Essentials. It meets the majority of contractual and regulatory requirements, can be achieved same-day, and costs a fraction of Plus. Upgrade to Plus when a specific contract, client, or risk assessment requires it.
If you are unsure which level you need, speak to our team or use our readiness checker to assess your current position.
Want to see how Fig handles this?
Explore how Fig automates compliance mapping, evidence collection, and framework alignment across 65+ compliance standards.
Request a demoRelated solutions
More in Compliance
The Fastest Cyber Essentials Certification Body in the UK: Why Fig Stands Alone
Most Cyber Essentials certification bodies take 24 to 72 hours to issue a certificate. Fig does it in under 6 hours. No other certification body in the UK can match this. Here is why.
Why Does Cyber Essentials Certification Take So Long? It Does Not Have To.
Waiting 24 to 72 hours for Cyber Essentials certification is the norm at most certification bodies. But it is not a requirement – it is a limitation. Fig is the only certification body that has eliminated the wait entirely.
Cyber Essentials Certification Bodies Compared: Speed, Service, and Why Fig Leads
With dozens of Cyber Essentials certification bodies in the UK, how do you choose? We compare the key differences in speed, service, and process – and explain why Fig is the only body that certifies in under 6 hours.