UK Cybersecurity SpecialistsTransport·Logistics·Haulage·Warehousing SMEs
← All resourcesCompliance · 9 min read

Cyber Essentials vs Cyber Essentials Plus: Which Do You Need?

By , Founder, DefendVistaLast reviewed:

A plain English breakdown of the two UK Cyber Essentials certifications, who actually needs each, common reasons firms fail, and how to budget realistically.

Cyber Essentials and Cyber Essentials Plus are routinely treated as interchangeable. They are not. The difference shapes cost, effort, tender eligibility and the credibility of the certificate you hang on the wall. This guide explains both, who needs each, and the specific reasons UK hauliers and SMEs fail their first assessment.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials and Cyber Essentials Plus cover the same five technical controls: firewalls, secure configuration, user access control, malware protection and patch management. Cyber Essentials is a self assessed questionnaire signed by a company director, typically £300 to £500. Cyber Essentials Plus adds a hands on external technical audit, typically £1,800 to £5,000.

Cyber Essentials vs Cyber Essentials Plus at a glance, based on typical UK SME certifications.
Cyber EssentialsCyber Essentials Plus
Control standardFive technical control familiesIdentical five control families
How it is verifiedOnline self assessment questionnaire, signed by a board director and reviewed by a certification bodyEverything in Cyber Essentials plus a hands on audit by an external assessor
Testing carried outNone. Controls are declared in writingDevice sampling, authenticated vulnerability scans, a test phishing email through the gateway and MFA validation on cloud admin accounts
Typical external cost£300 to £500 in fees£1,800 to £5,000 plus internal preparation
Typical timescale2 to 4 weeks of work for a prepared SME6 to 10 weeks for a 50 to 250 staff operator
Who usually asks for itSmaller contracts and some sectors that only ask for the basic certificationDfT, MOD, NHS Supply Chain and Cabinet Office contracts, major UK retailers and the top 10 3PLs above a spend threshold
RenewalAnnualAnnual

What both schemes cover

Both Cyber Essentials and Cyber Essentials Plus are built on five technical control families: boundary firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. Get all five right and you have closed the door on a sizeable share of common opportunistic attacks. The control standard itself is identical between the two schemes. What changes is how the controls are verified.

Cyber Essentials: the self assessment

You complete an online questionnaire (NCSC and IASME publish the question set in advance), declare your controls in writing, and a board director signs the declaration. A certification body reviews it and either issues the certificate or comes back with clarification questions. For a prepared SME with reasonable IT hygiene, the assessment itself is 2 to 4 weeks of work and roughly £300 to £500 in fees. The biggest risk is getting through the questionnaire and then failing to actually do what you declared, which becomes a real problem at insurance claim time.

Cyber Essentials Plus: the audited version

Everything in Cyber Essentials, plus a hands on technical audit by an external assessor. They sample your devices (usually 10 percent of the estate or a representative set), run authenticated vulnerability scans, test a phishing email through the gateway, validate MFA on cloud admin accounts, and check that the controls are genuinely deployed rather than just declared. Cost is typically £1,800 to £5,000 plus internal preparation effort, usually 6 to 10 weeks for a 50 to 250 staff operator.

Which one do you actually need?

Public sector contracts under DfT, MOD, NHS Supply Chain and the Cabinet Office often mandate Plus. Most major UK retailers and the top 10 3PLs now require it for haulage suppliers above a certain spend threshold. Some sectors only ask for the basic certification. The honest answer comes from your top three or four target customers: ask their procurement team directly. If even one will require Plus inside the next 12 months, go straight to Plus, you will save the duplicated effort.

Common reasons firms fail first time

Inconsistent patching of laptops that have been off the network for weeks (drivers and field staff are the usual culprits). MFA missing from Microsoft 365 global admin or Azure AD breakglass accounts. BYOD phones with company email but no MDM or conditional access. Missing inventory of devices and software (CE Plus requires you to know what you have). Default admin passwords still in place on small office routers or NAS units. Almost every one of these is fixable inside two to four weeks of focused work with a competent IT partner.

Budget realistically

For a 100 staff transport SME with reasonable IT hygiene, a realistic budget to reach Cyber Essentials Plus first time is £2,500 to £8,000 in external costs (assessor, certification body, any tooling top up), plus 60 to 120 hours of internal effort. Add £5,000 to £20,000 if you discover larger gaps such as unsupported operating systems or missing endpoint protection. The investment is usually recovered inside the first contract win that requires the certification.

Keeping certification current

Both schemes are annual. The biggest mistake is treating recertification as a fresh project each year. Build the control evidence into the monthly IT rhythm: patch reporting, account reviews, joiner mover leaver process, MFA exception reviews. By the time recertification comes around, the evidence is already collected.

Frequently asked questions

How long does Cyber Essentials Plus take to achieve?+

Typically 6 to 10 weeks for a well run 50 to 250 staff operator, longer if there are significant gaps such as unsupported Windows 10 estates or missing MFA on cloud admin. Allow 90 days end to end to be safe.

Does it expire?+

Yes. Both certifications are annual and recertification requires a fresh assessment. The control standard is also updated periodically (the most recent major refresh was the Montpellier set), so previous answers cannot simply be carried over.

Will it reduce my insurance premium?+

Often yes. Many UK cyber insurers offer 5 to 20 percent better terms for certified firms, and several have moved to refusing cover entirely for firms without it. The premium saving alone usually pays for the certification.

Can I do it without external help?+

Cyber Essentials self assessment, yes, with a competent IT lead. Cyber Essentials Plus is harder to pass first time without help because the technical sampling exposes gaps you did not know you had.

How much does Cyber Essentials Plus cost in the UK?+

Typically £1,800 to £5,000 in external assessor and certification fees, plus 60 to 120 hours of internal preparation. Budget another £5,000 to £20,000 if the assessment uncovers larger gaps such as unsupported operating systems or missing endpoint protection.

Do I need Cyber Essentials before Cyber Essentials Plus?+

Both schemes are built on the same five control families, and Plus is the audited version of the same standard. If any of your top target customers will require Plus within the next 12 months, go straight to Plus and avoid duplicating the effort.

Why do firms fail Cyber Essentials first time?+

The usual causes are inconsistent patching of laptops that have been off the network for weeks, MFA missing from Microsoft 365 global admin accounts, BYOD phones with company email but no MDM, no device and software inventory, and default admin passwords still set on routers or NAS units.

Next step

Want to talk this through?

Book a free 30 minute consultation. No sales pitch, just clear answers.

Book free consultation

Talk to a specialist who actually understands logistics.

Book a free 30-minute consultation. No sales pitch, no obligation. Just clear answers about where your business is exposed and what to do first.

Readiness ScoreBook Consultation