Back to blog
EU & UK

Cyber Essentials and Cyber Essentials Plus: the fastest credential to earn

The UK government-backed baseline covering five technical controls. What it requires, how Plus differs, why it is often a contract prerequisite, and where it stops short of ISO 27001.
GRC Copilot Team
Cyber Essentials and Cyber Essentials Plus: the fastest credential to earn

Cyber Essentials is a UK government-backed scheme covering five technical controls that block the large majority of common internet-based attacks. It is deliberately narrow, and that is its strength: it is achievable in weeks rather than months, and it is frequently a mandatory qualification for UK public-sector contracts.

The five controls

  1. Firewalls - boundary and host firewalls configured to block unapproved inbound connections, with documented approval for any open service.
  2. Secure configuration - remove or disable unnecessary accounts, software and services; change default passwords; disable auto-run.
  3. Security update management - supported software only, with high-risk and critical updates applied within a short defined window. Unsupported software in scope is a straightforward fail.
  4. User access control - unique accounts, least privilege, a documented approval process, prompt removal of leavers, and separate administrative accounts not used for day-to-day work.
  5. Malware protection - anti-malware, application allow-listing, or sandboxing.

Multi-factor authentication expectations for cloud services also feature prominently in current requirements.

Cyber Essentials versus Plus

  • Cyber Essentials - a verified self-assessment questionnaire, signed off by a board-level representative and reviewed by a certification body.
  • Cyber Essentials Plus - the same five controls, but technically verified by an assessor through hands-on testing: vulnerability scans, sampled devices, and simulated malware and phishing tests.
The gap between the two catches people out. Organisations that pass the self-assessment comfortably sometimes fail Plus, because the assessor tests what is actually configured rather than what was reported.

Check yourself against the five controls

GRC Copilot assesses you against Cyber Essentials, connects to your systems to evidence patching and access control, and maps the same evidence into ISO 27001 for when you go further.

Scope decisions that matter

You can certify the whole organisation or a defined subset, but sub-setting must be genuine - a properly segregated network or business unit, not a convenient selection of well-configured laptops. Points to settle early:

  • All end-user devices in scope, including home and mobile working.
  • Cloud services - infrastructure, platform and software - are in scope in current requirements.
  • Bring-your-own devices accessing organisational data.
  • Unsupported operating systems, which must be removed from scope or replaced.

Why organisations fail

  • Unsupported software still in scope - an end-of-life operating system is an immediate fail.
  • Patching outside the window, particularly on infrequently used devices.
  • Administrator accounts used for browsing and email.
  • Default credentials on network equipment.
  • Leavers still active, found during the Plus sample.
  • Scope drawn too cleverly, which assessors challenge.

Where it stops

Cyber Essentials covers technical hygiene. It does not require a risk assessment, an information security policy set, supplier management, incident response, business continuity or an internal audit. It is a strong first credential and a genuine risk reduction, but it is not a substitute for ISO 27001 when a customer asks for a management system.

The practical sequence for many UK organisations: Cyber Essentials to unblock contracts quickly, then Plus if a customer requires verification, then ISO 27001 when you need a management system for larger or international buyers.

Frequently asked questions

How long does certification take?

Cyber Essentials can often be completed in weeks if your technical hygiene is sound, since it is a verified self-assessment. Plus requires scheduling hands-on assessment, so allow longer.

How long is certification valid?

Annually - it is designed to be renewed each year, which keeps the technical controls current.

Do we need Plus, or is the base enough?

Follow the contract. Some UK public-sector and defence-adjacent work specifies Plus by name; otherwise the base certification satisfies many buyers.

Does it help with ISO 27001?

Yes. The five controls map into ISO 27001 Annex A, so the evidence carries over. ISO then adds the management system, risk assessment and audit layer that Cyber Essentials does not cover.

Key takeaways

  • Five technical controls, achievable quickly, often a UK contract prerequisite.
  • Plus is the same controls, verified hands-on - and harder to pass.
  • Unsupported software in scope is an automatic fail.
  • It covers hygiene, not a management system - ISO 27001 is the next step.
#cyber-essentials #uk #ncsc #certification #baseline