Cyber Essentials vs Cyber Essentials Plus — The Actual Difference
Most UK businesses know there are two levels of Cyber Essentials certification. Fewer understand exactly what separates them. The self-assessed Cyber Essentials involves completing a questionnaire and having an assessor verify your answers. Cyber Essentials Plus involves an external technical assessment — someone actually tests your systems.
If you are pursuing Cyber Essentials Plus, you need to understand what that assessment covers before you book it. Failing the assessment costs time and money and delays the certification your customer or contract is waiting for.
The Five Technical Controls Under Assessment
Cyber Essentials Plus checks the same five controls as the standard certification, but verifies them through technical testing rather than self-declaration.
1. Firewalls
The assessor verifies that your network boundary is protected. For most businesses, this means your router or firewall is configured to block inbound connections that have not been explicitly allowed. They will check from the internet that no unnecessary services are exposed.
Common failure points: management interfaces (router admin pages) accessible from the internet; services like RDP, SSH, or SMB exposed publicly; cloud security groups or firewall rules that are overly permissive.
In cloud environments (AWS, Azure, GCP), security groups and network ACLs are the firewall. The assessment covers these too.
2. Secure Configuration
Systems should be configured securely, which means unnecessary software removed, default passwords changed, and software not required for the device’s function disabled.
The assessor checks for default or weak credentials on devices. They also look for services that should not be running — an HTTP server exposed from a workstation, for example, or a database port accessible on a network interface it should not be on.
For user devices, the assessment typically involves checking a sample of laptops or workstations. Screen locks, auto-lock timeouts, and local administrator accounts are all in scope.
3. Security Update Management (Patching)
The assessor checks that your operating systems and applications are up to date. The Cyber Essentials standard requires that critical and high-severity patches are applied within 14 days of release.
They will look at: - Operating system patch level on assessed devices - Browser version (browsers are explicitly in scope and are a common failure) - Software with known vulnerabilities — out-of-date Office, Adobe Acrobat, Java, etc.
This is one of the most common failure causes. A single device running an out-of-date browser or operating system can cause a fail on this control. Check every device in scope before the assessment, not just servers.
4. User Access Control
User accounts should have the minimum permissions necessary for their role. Shared accounts are a red flag. Administrator privileges should not be used for day-to-day tasks.
The assessor checks: - Whether standard users have local administrator rights on their devices (they should not) - Whether administrator accounts are used for non-administrative tasks - Password policies — minimum length, complexity, and in some cases multi-factor authentication
Under the 2022 updates to the Cyber Essentials framework, thin-client and cloud-based services (Microsoft 365, Google Workspace) are explicitly in scope. MFA is now required for cloud services where accounts have access to sensitive data.
5. Malware Protection
Devices in scope need malware protection — either traditional antivirus or, increasingly, application whitelisting or execution control.
The assessor checks: - That malware protection software is installed and active on all in-scope devices - That it is up to date with current definitions - That real-time protection is enabled
Windows Defender, properly configured and updated, satisfies this requirement. The key is that it is running and current on every device in scope.
What Is “In Scope” for Cyber Essentials Plus
The scope definition is critical. In theory, Cyber Essentials Plus covers your entire organisation. In practice, you can define a boundary — for example, a specific office location, a specific department, or a specific set of systems.
The assessor will verify: - All internet-facing systems within scope (web servers, email, VPN endpoints) - A sample of end-user devices (typically up to 5 devices) - Any cloud services used by people within scope
If you have 200 staff but want to scope the certification to a single team of 10 for a specific contract, you can — but the scoping must be legitimate and documented.
Common Reasons Organisations Fail Cyber Essentials Plus
Based on common assessment patterns:
**Out-of-date browsers on user devices.** This is the single most common failure. Staff using Chrome, Firefox, or Edge on a device that has not been updated recently will fail the patching control.
**MFA not enabled on cloud services.** Microsoft 365 and Google Workspace accounts with access to sensitive data must have MFA enabled under the current framework.
**Local administrator rights on standard accounts.** Many small businesses give all staff local admin rights on their laptops for convenience. This fails the user access control check.
**Exposed management interfaces.** Router admin pages, NAS devices, printers with web interfaces — anything with a management interface that is accessible from the internet.
**Shared accounts.** A generic “reception@company.com” account used by multiple people with no individual accountability.
How to Prepare
Four weeks before your assessment:
1. Audit every device in scope. Check OS patch level, browser version, and installed software. 2. Enable MFA on all cloud services for all users in scope. 3. Remove local administrator rights from standard user accounts. Test that they can still do their jobs. 4. Check your firewall rules. Use a tool like Shodan or your assessor’s pre-check to verify what is exposed. 5. Ensure malware protection is installed, active, and updated on every device.
Two weeks before: run the Cyber Essentials self-assessment questionnaire yourself. If you cannot answer “yes” to all five controls in good conscience, you are not ready.
One week before: ask your assessor if they offer a pre-assessment check. Many IASME-accredited bodies provide a readiness review.
The Certification and What It Unlocks
Cyber Essentials Plus is valid for 12 months and must be renewed annually. The IASME certificate lists your organisation name, scope, and certification date. It is publicly searchable on the NCSC and IASME websites.
Key business benefits: required for some UK government contracts (any contract involving handling of personal data or certain sensitive information); recognised in NHS supplier requirements; increasingly asked for in enterprise procurement questionnaires; required for some cyber insurance policies.
Yrzo AI’s automated scanning covers many of the web application vulnerabilities that appear in Cyber Essentials Plus assessments. Running a scan before your certification gives you early sight of issues to fix.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →