Cyber Essentials is a self-assessment. Cyber Essentials Plus is the same control set with someone checking whether your answers were true. That difference is the entire value, and it is why some buyers - particularly in the UK public sector supply chain - specifically require Plus.
The five control areas
Both levels cover the same ground: firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. Nothing exotic - the scheme deliberately targets commodity attacks rather than sophisticated adversaries.
What the hands-on assessment adds
- Vulnerability scanning of internet-facing systems and a sample of end-user devices.
- Device sampling across your estate - checking patch levels, configuration and malware protection on real machines rather than on a form.
- Email and web testing - whether malicious file types actually reach a user and execute.
- Account separation checks - confirming administrative accounts are separate from day-to-day ones and that MFA is enforced where required.
The sampling is what catches people. A self-assessment describes the fleet you intended; sampling finds the four laptops running an old OS, the contractor machine nobody enrolled, and the one server excluded from patching because it broke last time.
Where organisations fail
- Patch timeliness. The scheme expects high-severity updates applied within a short window. A device a few weeks behind fails.
- Unsupported software anywhere in scope - an old operating system, an end-of-life browser, an unsupported database.
- Scope gaps - BYOD, home working devices and cloud services omitted from the declared scope but genuinely in it.
- Administrative accounts used for routine work, or without MFA.
- Default configurations left in place on network equipment.
Note how many of these are inventory problems rather than security capability problems. Organisations usually know what good looks like; they do not know what is actually on the network.
Know your estate before an assessor samples it
GRC Copilot ties your asset inventory to the controls and evidence each framework requires, so scope gaps surface before an assessor finds them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Scope carefully and honestly
Scope can be the whole organisation or a defined subset, but a scope that conveniently excludes the messy part invites questions and may not satisfy the customer asking for the certificate. Whole-organisation scope is the strongest claim and the one most buyers assume.
Remember that cloud services and home-working devices are generally in scope. The scheme has moved to reflect how organisations actually work, and treating cloud as out of scope is a common and outdated assumption.
Preparing
- Inventory first - you cannot pass on devices you do not know exist.
- Verify patch status across the fleet, not on a sample you chose.
- Find and remove unsupported software, or remove it from scope legitimately.
- Separate administrative accounts and enforce MFA.
- Run your own vulnerability scan and fix findings before the assessor does.
Is it worth the step up?
If a customer or framework requires it, the question is settled. Otherwise, the value is credibility - a verified certificate says something a self-assessment does not, particularly to buyers who know the difference. It is also considerably cheaper and faster than ISO 27001, which makes it a reasonable first step for smaller organisations rather than a competitor to it.
Frequently asked questions
How long is certification valid?
Annually, so it is a recurring commitment rather than a one-off.
Is cloud in scope?
Generally yes, along with home-working devices. Excluding them is a common and outdated assumption.
Does it replace ISO 27001?
No. It covers technical baseline controls; ISO certifies a management system. They serve different buyer questions.
What is the most common failure?
Patch timeliness on a minority of devices, usually ones missing from the inventory.
Key takeaways
- Plus verifies technically what the self-assessment asserts.
- Sampling finds inventory gaps more often than capability gaps.
- Cloud and home-working devices are in scope.
- Scan yourself before the assessor does.