Cyber Essentials and Cyber Essentials Plus look similar on paper — both certify the same five technical controls. In practice, they're very different exercises. Cyber Essentials is a self-assessed questionnaire. Cyber Essentials Plus is an independent, hands-on technical audit of your actual environment. Many organisations pass the first comfortably and are then caught out by the second.
Why the gap exists
Self-assessment relies on someone answering honestly and accurately about how systems are configured. That's often done from memory, or from how systems were configured when they were first set up — not necessarily how they're configured today. Plus testing doesn't take your word for it. An assessor scans your external and internal environment, checks patch levels, tests authentication, and verifies that controls actually work as described, not just as documented.
The result: organisations that pass Cyber Essentials on paper frequently fail their first Plus attempt on details like unpatched third-party software, weak MFA enforcement, or devices that were never brought into scope.
The five controls, under real scrutiny
Firewalls. Plus testing verifies rules are actually restrictive, not just present — default-allow configurations and open management ports are common findings.
Secure configuration. Assessors check for unnecessary accounts, default credentials, and unused services still running on production systems.
User access control. This is tested, not just documented. Admin rights sprawl — accounts with more privilege than their role requires — is one of the most frequent gaps found at audit.
Malware protection. Coverage needs to be verified across every device in scope, including remote and BYOD endpoints that are easy to miss in a self-assessment.
Patch management. This is usually where organisations fail. Cyber Essentials Plus has strict timelines for applying critical and high-severity patches, and assessors check actual patch levels against known CVEs — not just whether a patching policy exists.
Closing the gap before the audit
The organisations that pass first time treat the self-assessment questionnaire as a starting point, not the finish line. A few practical steps make the biggest difference:
- Scope it properly first. Know exactly which devices, cloud services and networks are in scope before testing begins — ambiguity here causes avoidable failures.
- Run a technical readiness check, not just a policy review, ideally against the same 96-question depth an assessor will apply.
- Fix patch management first. It's the single most common reason organisations fail Plus, and usually the easiest to remediate once identified.
- Re-verify access control. Audit who actually has admin rights today, not who was granted them when the account was created.
The value beyond the certificate
Cyber Essentials Plus is increasingly a contractual requirement, particularly for government and supply chain work. But treated properly, the preparation itself is valuable independent of the certificate — it's a forced, structured look at whether your controls work in practice, not just in policy.
Want to know where you stand before the assessor does? Start the Cyber Essentials Plus readiness assessment for a full report against all 96 technical checks.
See where your organisation stands in minutes.
Start a framework-aligned assessment and get an instant, section-by-section maturity score.
Browse assessments