UK · CE vs CE+

CE is a questionnaire.
CE+ is an audit.

Cyber Essentials and Cyber Essentials Plus share the same five technical control families, but the assessment process is completely different. CE is self-attested; CE+ has an assessor running real tools on your real systems. Here's what changes.

AspectCyber EssentialsCyber Essentials Plus
Assessment methodSelf-assessment questionnaireIndependent assessor + technical audit
External vulnerability scanNot requiredRequired — Nessus/equivalent against external IPs
Internal credentialed scanNot requiredRequired — assessor scans an authenticated workstation
Malware test (EICAR via email)Not requiredRequired — assessor sends test files to verify AV
Patch verificationSelf-attestedSampled — assessor checks specific systems
Configuration verificationSelf-attestedSampled — assessor checks specific systems
Cost (typical SMB)£300–£500£1,500–£3,500
Time on assessor's site0Half day to 2 days
Validity12 months12 months
Required for UK gov contractsYes (most)Yes (handling sensitive data)

Same five control families

Both certifications cover the same technical control set: firewalls, secure configuration, user access control, malware protection, and patch management. The difference is who's checking, and how.

When the assessor finds something

CE+ assessors typically find at least one issue on the first pass — most commonly an out-of-date dep, a missing security header on an internal tool, or a default-allow firewall rule. You either fix it on the spot or the assessor returns for a re-audit (which is billable, often £500+).

The cheapest CE+ outcome is one where the assessor finds nothing actionable in your codebase. RepoWarden's monthly readiness scan exists to make that the default — by surfacing the same kinds of issues an assessor's tools would find, with file/line evidence, before they bill you for finding them.

Should we go for CE or CE+?

If you're handling personal data, payment data, or selling into UK public sector contracts that mention CE+ explicitly, you need CE+. Otherwise CE is usually sufficient — and you can upgrade to CE+ later once your security posture is stable.

Many RepoWarden customers start on CE, run our scan for 3–6 months to clean up findings, then go for CE+ in year two with a much higher first-pass rate.

Get scan-ready

Pre-flight your assessment

Whether you're going for CE or CE+, RepoWarden's monthly readiness scan finds the same classes of issue an assessor's tools would — with file and line evidence, before you pay for the assessor's time.