The Tender Says “Cyber Essentials Plus.” A Basic Certificate Is Not the Same Assessment
Compare verified self-assessment and independent audit with the more rigorous independent technical testing required for Cyber Essentials Plus before scoping a certification request.

Signals to watch
- A UK tender explicitly requires Cyber Essentials Plus while the supplier only names a current basic certificate
- A buyer asks for external testing, endpoint sampling or remediation without confirming the Cyber Essentials assessment scope
- A certification date is fixed but device inventory, cloud services, remote users or boundary exceptions remain unknown
Cyber Essentials and Cyber Essentials Plus protect against the same five common technical-control areas, but they are not the same assessment route. The National Cyber Security Centre (NCSC) describes Cyber Essentials as verified self-assessment with independent assessor review, while Plus adds more rigorous, independent technical testing. If a tender explicitly asks for Plus, a basic certificate should not be presented as equivalent.
A UK managed security or certification provider’s sales director needs that distinction in authorised procurement, managed service provider (MSP) and security Telegram groups. “We have CE but procurement wants testing before Friday” could describe a Plus gap, an expired or wrongly scoped certificate, or ordinary customer assurance. A one-day delay can lose the testing slot; a rushed promise can put the wrong legal entity or network inside the quote.
Quick decision: choose the level named by the buyer, then verify scope
Use Cyber Essentials when the actual requirement is the verified foundational certification. Use Cyber Essentials Plus when the buyer, tender or policy requires the Plus level and its independent technical testing. Do not upgrade or downgrade the wording based on what the supplier already owns.
Both routes start with the same practical question: which organisation and which IT estate are meant to be certified? A certificate for a parent company, one office or a narrow network boundary may not answer a tender for a subsidiary or whole service.
The shared baseline is five technical controls
The NCSC overview identifies five controls:
- firewalls, which filter traffic between the organisation and the internet;
- secure configuration, which removes or reduces unnecessary exposure;
- security update management, which addresses known software vulnerabilities;
- user access control, which limits who can access systems and at what privilege; and
- malware protection, which detects or prevents malicious software.
Plus does not replace those controls with a different security framework. It tests the implementation more rigorously. That makes a control gap relevant to both levels, while the evidence collection and assessment activity differ.
Cyber Essentials is verified, not merely self-declared
NCSC’s current route says an organisation completing the self-led option registers through IASME, pays, and completes a verified self-assessment. Answers are signed off by a board member or equivalent and marked by an assessor. NCSC summarises the basic level as a combination of self-assessment and independent audit.
That is different from an internal spreadsheet in which a team marks itself compliant. The applicant needs to understand the assessment questions, define scope and provide answers that withstand assessor review.
The NCSC page accessed for this article listed pricing from £320 plus VAT for Cyber Essentials, depending on organisation size. That figure is a dated starting point, not a universal project quote: advisory work, remediation and estate complexity can add separate costs.
Plus adds independent technical testing
NCSC describes Cyber Essentials Plus as the same protections with more rigorous, independent technical testing. Its price depends on the size and complexity of the network.
For a provider, “ready for Plus” therefore needs operational facts. Which endpoint types, internet-facing services, cloud services, users and remote-working paths sit inside scope? Are sample devices reachable for the assessor? Who can change configurations if a test exposes a failure? How long is available for remediation and retest?
A current basic certificate can be useful evidence that the organisation has already completed the foundational assessment. It is not proof that the Plus technical assessment will pass, and it does not erase a scope mismatch.
Compare the request with one assessment-route card
Use the same seven fields for either level:
| Field | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Required outcome | Verified foundational certificate | Plus certificate named by buyer or policy |
| Control themes | Five NCSC technical controls | The same five technical controls |
| Assessment evidence | Signed verified self-assessment and assessor review | Foundational assessment plus rigorous independent technical testing |
| Scope question | Entity and IT boundary covered by answers | Entity, IT boundary and estate available for technical test |
| Readiness risk | Incomplete or inaccurate inventory and answers | Test access, sampling, configuration failure and retest timing |
| Pricing fact | NCSC listed a £320 + VAT starting point on the access date | Depends on network size and complexity |
| Decision owner | Applicant, certification body and buyer’s acceptance criteria | Applicant, certification body and buyer’s Plus requirement |
This assessment-route card is the article’s original contribution. It keeps the comparison on one evidence scale instead of treating Plus as a decorative suffix.
Example: the certificate exists, but covers the wrong boundary
Consider this illustrative composite thread, not a real customer conversation:
“Framework bid closes on the 28th. They wrote CE Plus.”
“We have CE for the London office. Product runs in cloud, half the team remote. No idea if that’s in scope.”
The messages identify a bid date, the Plus level, an existing basic certificate, a London office, cloud service and remote workers. They do not establish the bidding legal entity, certificate status, existing scope, device inventory, cloud administration path, technical-test plan or remediation time.
The correct first proposal is not “replace the certificate.” It is a bounded scope review followed by the certification route that the tender actually requires. If the bid entity or service falls outside the existing certificate, that gap should be explicit before a testing date is promised.
Product discovery is earlier than certification
TOP Prospect can filter and combine fragments from Telegram groups the user deliberately connects and is authorised to access. It can preserve the original message, source and time, join a tender level, certificate status, estate detail and deadline, remove obvious duplicates and rank the discussion for review.
It cannot test devices, access an applicant’s network, act as a certification body, guarantee a pass, determine the tender’s legal meaning or contact group members. Pricing and access options cover early discovery only.
For a different US federal supplier-assurance route, see the CMMC implementation evidence map. A service onboarding request for another assurance standard is covered in the SOC 2 evidence article.
Key facts
- Cyber Essentials is the UK government-recommended minimum cyber-security standard described by NCSC.
- Both levels address firewalls, secure configuration, security update management, user access control and malware protection.
- Cyber Essentials is a verified self-assessment signed off by a board member or equivalent and marked by an assessor; NCSC also describes independent audit.
- Cyber Essentials Plus adds more rigorous independent technical testing.
- NCSC listed Cyber Essentials pricing from £320 plus VAT on the page accessed for this article.
- Plus pricing varies with network size and complexity.
- Certificate level, legal entity, technical scope and buyer acceptance must all be joined before a provider promises a route.
FAQ
Is Cyber Essentials only an unverified questionnaire?
No. NCSC describes a verified self-assessment signed off by a board member or equivalent and marked by an assessor; it also describes the level as a combination of self-assessment and independent audit.
What does Cyber Essentials Plus add?
It uses the same five technical-control themes but adds more rigorous independent technical testing. The network size and complexity affect the assessment scope and price.
Can a basic Cyber Essentials certificate satisfy a tender asking for Plus?
Only the buyer can interpret its tender, but the two levels are not interchangeable. If the requirement expressly names Plus, the supplier should not represent the basic level as equivalent.
Which facts should a provider confirm before quoting?
Confirm the required level, legal entity and scope, certificate status, device and cloud estate, remote-working boundary, test readiness, remediation window and tender deadline.
The shortest useful answer to “CE or CE Plus?” is the buyer’s exact wording joined to the estate that must be assessed.
Frequently asked questions
Is Cyber Essentials only an unverified questionnaire?
No. NCSC describes a verified self-assessment signed off by a board member or equivalent and marked by an assessor; it also describes the level as a combination of self-assessment and independent audit.
What does Cyber Essentials Plus add?
It uses the same five technical-control themes but adds more rigorous independent technical testing. The network size and complexity affect the assessment scope and price.
Can a basic Cyber Essentials certificate satisfy a tender asking for Plus?
Only the buyer can interpret its tender, but the two levels are not interchangeable. If the requirement expressly names Plus, the supplier should not represent the basic level as equivalent.
Which facts should a provider confirm before quoting?
Confirm the required level, legal entity and scope, certificate status, device and cloud estate, remote-working boundary, test readiness, remediation window and tender deadline.
Sources and further reading
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.
