Cyber Essentials Plus is not a harder standard than Cyber Essentials. It is the same five controls — firewalls, secure configuration, access control, malware protection, and patching. The difference is that somebody comes and checks whether your answers were true.
That is the whole thing. Which means Plus is only difficult if the self-assessment was optimistic.
What actually happens on the day
This is the part most guides skip. A trained assessor, working for an IASME-licensed certification body, does four things:
1. An external vulnerability scan of everything you expose to the internet. Firewalls, web servers, mail, VPN endpoints — anything with a public IP is in scope. This finds the forgotten box far more often than it finds a sophisticated flaw.
2. Authenticated scans on a sample of your devices. Not a look from the outside — they log in and inspect. Missing patches, unsupported operating systems, and configuration drift all surface here.
3. Simulated malware delivery. The assessor attempts to get test malware onto sampled machines, typically the harmless EICAR test file, usually by email and by web download. They are checking your protection actually intervenes rather than merely being installed.
4. Direct inspection of configuration evidence. Account separation, admin rights, MFA on cloud services, device lock settings — verified on the machine rather than asserted on a form.
The scoping trap
The sample is drawn from every device that touches organisational data. That includes laptops and desktops, but also:
- Mobile phones used for work email
- Personally owned devices under any BYOD arrangement, if they access company data
- Home workers' machines
Firms routinely scope Plus around "the office computers" and then discover half the estate is in scope. If five people read work email on personal phones with no MFA and no screen lock, that is five devices heading into the sample.
Get scoping right before you book. It is the single biggest cause of a failed first attempt.
The 2026 change worth knowing
Assessors can now randomly re-sample during remediation. Historically, if a device failed you fixed that device and were re-checked on it. Now the assessor can pull a fresh set of machines to confirm the fix was applied across the organisation, not just to the ones that got caught.
That closes the obvious loophole, and it changes how you should prepare: fix the class of problem, not the machine. If one laptop is three months behind on patches, patching that laptop is not the remediation — working out why nothing noticed is.
The sequencing rule
You need a valid Cyber Essentials certificate before you can sit Plus, and Plus has to follow within three months of it. Firms sometimes book both months apart and find the self-assessment has gone stale.
The fees stack too: the Cyber Essentials assessment fee, then Plus on top. We covered the full numbers in what Cyber Essentials actually costs in 2026, but as a rule Plus starts around £1,399 + VAT for a micro organisation and rises with the size and messiness of the estate.
Does your firm actually need Plus?
Often not. Plus gets bought for the wrong reasons — usually because it sounds more serious, or because nobody read the requirement closely.
You probably need Plus if:
- A contract, tender, or framework names it specifically. MOD supply chain and many public-sector contracts do.
- A client's procurement team has asked for independently verified controls.
- You handle client data at a level where "we assessed ourselves" would not survive a difficult conversation after an incident.
Base Cyber Essentials is very likely enough if:
- Your PI insurer asked for "Cyber Essentials" without qualification.
- A principal firm or network asked for it as a condition.
- You want the baseline because it is sensible — which it is.
Read the actual wording of whatever prompted this. If it says "Cyber Essentials", it means the base certificate. Buying Plus to be safe is an expensive way to answer a question nobody asked.
How to pass first time
Firms that pass cleanly tend to have done four unglamorous things beforehand:
- Inventoried every device that touches company data, including the phones, and scoped honestly.
- Removed unsupported software and hardware. Anything past end-of-life fails you outright, and no amount of goodwill on the day changes that.
- Made patching something that reports, rather than something everyone assumes is happening.
- Turned MFA on everywhere it can be turned on, not just on email.
None of that is exotic. It is simply harder to arrange in a fortnight than over a year.
Making it survivable
The reason Plus feels painful is usually that the controls were assembled for the audit rather than running continuously. Do it that way and you rebuild the scramble every twelve months.
Telebyte Shield exists for that: managed security for small and regulated firms, running the same stack we use across our own estate — patching, device encryption, MFA, threat protection, and a compliance dashboard from £25 per user per month. When the assessor turns up, the evidence is already there.
If you have been asked for something and are not certain whether it means Plus, send us the wording and we will tell you straight — including when the answer is that the base certificate covers it.
Assessment methods described reflect the scheme as delivered by IASME-licensed certification bodies at the time of writing. Certification bodies vary in scheduling and resubmission policy, so confirm both before booking.