Skip to contentAbout Fig Group
Guides

Who needs Cyber Essentials Plus?

Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Who needs Cyber Essentials Plus?

You need Cyber Essentials Plus when a tender, contract, framework, customer, or internal risk decision explicitly requires independently tested assurance. Contract value alone does not decide the level. If the requirement only names Cyber Essentials, do not assume Plus is mandatory.

Section 02

Cyber Essentials Plus is typically required for:

MOD and defence sub-contracting

Defence contracts can combine Cyber Essentials requirements with Defence Cyber Certification. The applicable level comes from the contract, its Cyber Risk Profile, and any flow-down terms from the prime contractor. Check those documents rather than assuming every defence subcontract requires Plus.

Higher-risk public contracts

PPN 014 describes Plus as the more rigorous assessment to use when cyber risk is higher. It does not prescribe a £5 million or other contract-value threshold for Plus. The contracting organisation should state the proportionate requirement in the tender.

NHS and healthcare supplier frameworks

PPN 014 applies to NHS bodies as in-scope organisations, but the requirement remains contract-specific and proportionate. An NHS tender or supplier framework may specify Plus; the buyer's published documents are the source of truth.

Financial services regulated supply chain

Regulated firms can require Plus through their supplier-onboarding standards or contract. That is a buyer requirement, not a universal FCA or PRA rule applying to every supplier.

SJP partner practices

St. James's Place Partner practices require CE Plus for ongoing partnership.

Enterprise B2B SaaS supplier onboarding

An enterprise buyer may specify Plus in its vendor questionnaire or contract, particularly for suppliers with privileged access or sensitive data. Treat the buyer's actual wording as decisive.

Section 03

Where standard Cyber Essentials is sufficient

  • Most B2B SME work without specific procurement mandates
  • Most UK legal practice PI-insurance baselines
  • General client-onboarding signals for most professional services
  • Cyber-insurance baseline for SMEs with standard cyber-liability needs
  • Most charity / nonprofit funder requirements

Section 04

Cost and timeline

Because Plus requires a valid standard CE certificate as a prerequisite, both are typically completed in a single engagement. See Can I get Cyber Essentials Plus without Cyber Essentials?.

Section 05

Bottom line

You need Cyber Essentials Plus if your tender documents, supplier-onboarding form, regulatory counterparty, or insurance broker says so. For most UK SMEs without that specific pressure, standard CE is the right bar. Review the Cyber Essentials Plus certification service for the audit scope and preparation requirements, or use the full pricing page to compare both levels side by side.

Start Cyber Essentials from £299.99 + VAT | Explore Cyber Essentials Plus | Cyber Essentials vs Cyber Essentials Plus

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig