Cyber Essentials vs Cyber Essentials Plus: what they are and what’s the difference?
Most cyber attacks on small businesses are fairly basic. Someone tries the digital front door to see if it’s unlocked: a reused password, a laptop that skipped its updates, an admin account everyone shares. Cyber Essentials is the UK government-backed scheme that helps you lock those doors.
If a customer, an insurer or a tender form has asked whether you’re certified, this guide covers what Cyber Essentials is, what Cyber Essentials Plus adds, what changed in April 2026 and which one makes sense for your business.
What is Cyber Essentials?
Cyber Essentials is a certification scheme backed by the UK government and the National Cyber Security Centre (NCSC). It sets out five basic security controls that every organisation should have in place.
To get certified, you complete an online questionnaire about how your IT is set up. An independent assessor from a certification body reviews your answers. If everything meets the standard, you get a certificate that lasts 12 months, and your business appears on the public register of certified organisations.
The five controls
- Firewalls. A barrier between your devices and the internet that blocks traffic you haven’t asked for. Every device used for work needs one, including laptops used at home.
- Secure configuration. Changing default passwords, removing software and accounts nobody uses, and making sure devices lock when left alone.
- Security update management. Keeping software supported and applying critical or high-risk updates within 14 days of release. That covers operating systems, apps, and router and firewall firmware.
- User access control. People only get the access they need for their job. Admin accounts are used for admin tasks only, and multi-factor authentication (MFA) is switched on for cloud services.
- Malware protection. Anti-malware software on your devices, or controls that stop unapproved programs from running.
Think of it as everyday good housekeeping, written down and checked.
What is Cyber Essentials Plus?
Cyber Essentials Plus covers exactly the same five controls. The difference is who does the checking. With Plus, an independent assessor tests your systems to confirm that what you said in the questionnaire is true in practice.
The audit typically includes:
- An external scan of your public internet addresses, looking for weaknesses anyone online could find.
- Internal vulnerability scans on a sample of your devices (laptops, desktops, servers, phones and tablets) to confirm updates have been applied within 14 days.
- Malware tests. Safe test files are sent by email and through a web browser to see whether your protection stops them.
- Admin rights checks to confirm everyday users can’t carry out administrator tasks from their normal accounts.
- MFA checks on a sample of user accounts to confirm cloud services such as Microsoft 365 ask for a second step at login.
You need your standard Cyber Essentials certificate first, and the Plus audit must be completed within three months of it. If the assessor finds problems, you get a window of 30 days to fix them before the certificate can be issued.
Cyber Essentials vs Cyber Essentials Plus at a glance
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| How it works | Online self-assessment questionnaire | The same questionnaire, plus a hands-on technical audit |
| Who checks it | An independent assessor reviews your answers | An independent assessor tests your actual devices and accounts |
| Technical testing | None | External scan, internal vulnerability scans, malware tests, admin rights and MFA checks on a sample of devices and users |
| The five controls | Firewalls, secure configuration, security updates, user access control, malware protection | Exactly the same five |
| Order | Comes first | Must be completed within 3 months of your Cyber Essentials certificate |
| Valid for | 12 months | 12 months |
| Good fit for | A first step, smaller teams, customers asking for a baseline | Tenders that require it, sensitive data, regulated sectors, anyone wanting independent proof |
What changed in April 2026?
The scheme was updated on 27 April 2026 with a new set of questions, known as Danzell. The rules got stricter in a few areas that catch a lot of businesses out:
- MFA on every cloud account. MFA must be switched on for all users of in-scope cloud services wherever it’s available, admins and everyday staff alike. Missing MFA is now an automatic fail.
- The 14-day update rule is firmer. Critical and high-risk updates left unapplied for more than 14 days now lead to an automatic fail.
- A clear definition of cloud services. Microsoft 365, Google Workspace, Dropbox, webmail, Salesforce and your line-of-business cloud apps all count, and all need to meet the controls.
- Home workers. Home broadband routers are out of scope. Instead, the software firewall on each work device acts as its boundary, so it needs to be switched on and set up properly.
- Tighter scope. Old systems can only be left out if they’re properly separated from the rest of your network, and you need to explain why.
If you were certified before April, your next renewal will be assessed against these newer rules. It’s worth checking MFA and update settings well before the renewal date.
Why get certified?
- Win more work. UK central government contracts that involve handling personal information or certain IT services require Cyber Essentials, and many large companies and public bodies ask their suppliers for it too. Some contracts, including many in defence, ask for Plus.
- Free cyber insurance. UK-based organisations with turnover under £20 million that certify their whole organisation can opt in to £25,000 of cyber liability cover, which includes access to a 24-hour incident response helpline.
- Fewer successful attacks. The five controls are designed to stop the most common internet-based attacks, the kind that rely on weak passwords and missed updates.
- Reassurance for customers. A certificate on your website and a listing on the public register show customers you take their data seriously.
- A clearer picture of your own IT. Going through the questions often turns up forgotten accounts, unsupported software and devices nobody realised were still connected.
Which one do you need?
Cyber Essentials is a good fit if it’s your first time, you’re a smaller team, or a customer has asked you to show a basic security standard.
Cyber Essentials Plus makes sense if a tender or contract asks for it, you handle sensitive or regulated data, or you want independent proof that your controls work day to day.
Plenty of businesses start with Cyber Essentials and move to Plus within the same year, once they know their systems are in good shape.
How Absolute Technology can help
Our in-house Cyber Essentials team works with you to get certified.
We can help with:
- A readiness check against the five controls, so you know where you stand before you apply.
- Fixing the gaps, including MFA, update settings, firewall configuration and admin accounts.
- Completing the questionnaire with you, so the answers are accurate and nothing is missed.
- Preparing for the Plus audit, so there are no surprises.
- Staying compliant all year through our managed IT support, so renewal is a formality.
Where to start
Start with a short, no-obligation chat. We’ll ask a few questions about your setup, tell you roughly how far you are from passing, and whether Plus is worth it for you. If you’ve been certified before, check your renewal date and give yourself at least a month to review the April 2026 changes.
Frequently asked questions
Is Cyber Essentials a legal requirement?
No. It’s voluntary, but it’s required for some government contracts, and more and more customers and insurers ask for it.
How long does a certificate last?
12 months. You renew each year to stay certified, and each renewal is assessed against the current rules.
Can we go straight to Cyber Essentials Plus?
You need the standard Cyber Essentials certificate first, and the Plus audit must be completed within three months of it. Many businesses do the two back to back.
What happens if we don’t pass?
The assessor will tell you what needs fixing. With Plus, you have 30 days to sort any issues before the certificate is issued. A readiness check beforehand makes a fail much less likely.
Do staff working from home count?
Yes. Any device used for work is in scope, wherever it’s used. Home routers aren’t, so the firewall on each laptop needs to be switched on and configured.
Are Microsoft 365 and other cloud services included?
Yes. Cloud services that store or process your business data are in scope, and since April 2026 MFA must be switched on for every user wherever it’s available.
What about staff using their own phones for work email?
If a personal device accesses business data or email, it’s in scope and needs to meet the same controls, such as supported software, a screen lock and up-to-date apps.
Talk to us about Cyber Essentials
Call Absolute Technology on 0345 225 1047 or use our contact page to book a readiness chat. We’re a local IT company based in Chandler’s Ford, helping businesses across Hampshire get certified and stay secure.