Cyber Essentials and Cyber Essentials Plus share the same five technical control families, but the assessment process is completely different. CE is self-attested; CE+ has an assessor running real tools on your real systems. Here's what changes.
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment method | Self-assessment questionnaire | Independent assessor + technical audit |
| External vulnerability scan | Not required | Required — Nessus/equivalent against external IPs |
| Internal credentialed scan | Not required | Required — assessor scans an authenticated workstation |
| Malware test (EICAR via email) | Not required | Required — assessor sends test files to verify AV |
| Patch verification | Self-attested | Sampled — assessor checks specific systems |
| Configuration verification | Self-attested | Sampled — assessor checks specific systems |
| Cost (typical SMB) | £300–£500 | £1,500–£3,500 |
| Time on assessor's site | 0 | Half day to 2 days |
| Validity | 12 months | 12 months |
| Required for UK gov contracts | Yes (most) | Yes (handling sensitive data) |
Both certifications cover the same technical control set: firewalls, secure configuration, user access control, malware protection, and patch management. The difference is who's checking, and how.
CE+ assessors typically find at least one issue on the first pass — most commonly an out-of-date dep, a missing security header on an internal tool, or a default-allow firewall rule. You either fix it on the spot or the assessor returns for a re-audit (which is billable, often £500+).
The cheapest CE+ outcome is one where the assessor finds nothing actionable in your codebase. RepoWarden's monthly readiness scan exists to make that the default — by surfacing the same kinds of issues an assessor's tools would find, with file/line evidence, before they bill you for finding them.
If you're handling personal data, payment data, or selling into UK public sector contracts that mention CE+ explicitly, you need CE+. Otherwise CE is usually sufficient — and you can upgrade to CE+ later once your security posture is stable.
Many RepoWarden customers start on CE, run our scan for 3–6 months to clean up findings, then go for CE+ in year two with a much higher first-pass rate.
Whether you're going for CE or CE+, RepoWarden's monthly readiness scan finds the same classes of issue an assessor's tools would — with file and line evidence, before you pay for the assessor's time.