Who needs Cyber Essentials Plus?
Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.
Section 01
Who needs Cyber Essentials Plus?
You need Cyber Essentials Plus when a tender, contract, framework, customer, or internal risk decision explicitly requires independently tested assurance. Contract value alone does not decide the level. If the requirement only names Cyber Essentials, do not assume Plus is mandatory.
Section 02
Cyber Essentials Plus is typically required for:
MOD and defence sub-contracting
Defence contracts can combine Cyber Essentials requirements with Defence Cyber Certification. The applicable level comes from the contract, its Cyber Risk Profile, and any flow-down terms from the prime contractor. Check those documents rather than assuming every defence subcontract requires Plus.
Higher-risk public contracts
PPN 014 describes Plus as the more rigorous assessment to use when cyber risk is higher. It does not prescribe a £5 million or other contract-value threshold for Plus. The contracting organisation should state the proportionate requirement in the tender.
NHS and healthcare supplier frameworks
PPN 014 applies to NHS bodies as in-scope organisations, but the requirement remains contract-specific and proportionate. An NHS tender or supplier framework may specify Plus; the buyer's published documents are the source of truth.
Financial services regulated supply chain
Regulated firms can require Plus through their supplier-onboarding standards or contract. That is a buyer requirement, not a universal FCA or PRA rule applying to every supplier.
SJP partner practices
St. James's Place Partner practices require CE Plus for ongoing partnership.
Enterprise B2B SaaS supplier onboarding
An enterprise buyer may specify Plus in its vendor questionnaire or contract, particularly for suppliers with privileged access or sensitive data. Treat the buyer's actual wording as decisive.
Section 03
Where standard Cyber Essentials is sufficient
- Most B2B SME work without specific procurement mandates
- Most UK legal practice PI-insurance baselines
- General client-onboarding signals for most professional services
- Cyber-insurance baseline for SMEs with standard cyber-liability needs
- Most charity / nonprofit funder requirements
Section 04
Cost and timeline
- Standard Cyber Essentials: from £299.99 + VAT (Micro), 6-hour turnaround
- Cyber Essentials Plus: from £1,499 + VAT (Micro), with Fig's published service timeline shown on the Plus certification page
Because Plus requires a valid standard CE certificate as a prerequisite, both are typically completed in a single engagement. See Can I get Cyber Essentials Plus without Cyber Essentials?.
Section 05
Bottom line
You need Cyber Essentials Plus if your tender documents, supplier-onboarding form, regulatory counterparty, or insurance broker says so. For most UK SMEs without that specific pressure, standard CE is the right bar. Review the Cyber Essentials Plus certification service for the audit scope and preparation requirements, or use the full pricing page to compare both levels side by side.
Start Cyber Essentials from £299.99 + VAT | Explore Cyber Essentials Plus | Cyber Essentials vs Cyber Essentials Plus
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoMore from Guides