← Back to insights

The Tender Says “Cyber Essentials Plus.” A Basic Certificate Is Not the Same Assessment

Compare verified self-assessment and independent audit with the more rigorous independent technical testing required for Cyber Essentials Plus before scoping a certification request.

A UK certification request compares verified Cyber Essentials assessment with Cyber Essentials Plus independent technical testing
#Cyber Essentials#Cyber Essentials Plus#NCSC#IASME#UK Procurement

Signals to watch

  • A UK tender explicitly requires Cyber Essentials Plus while the supplier only names a current basic certificate
  • A buyer asks for external testing, endpoint sampling or remediation without confirming the Cyber Essentials assessment scope
  • A certification date is fixed but device inventory, cloud services, remote users or boundary exceptions remain unknown

Cyber Essentials and Cyber Essentials Plus protect against the same five common technical-control areas, but they are not the same assessment route. The National Cyber Security Centre (NCSC) describes Cyber Essentials as verified self-assessment with independent assessor review, while Plus adds more rigorous, independent technical testing. If a tender explicitly asks for Plus, a basic certificate should not be presented as equivalent.

A UK managed security or certification provider’s sales director needs that distinction in authorised procurement, managed service provider (MSP) and security Telegram groups. “We have CE but procurement wants testing before Friday” could describe a Plus gap, an expired or wrongly scoped certificate, or ordinary customer assurance. A one-day delay can lose the testing slot; a rushed promise can put the wrong legal entity or network inside the quote.

Quick decision: choose the level named by the buyer, then verify scope

Use Cyber Essentials when the actual requirement is the verified foundational certification. Use Cyber Essentials Plus when the buyer, tender or policy requires the Plus level and its independent technical testing. Do not upgrade or downgrade the wording based on what the supplier already owns.

Both routes start with the same practical question: which organisation and which IT estate are meant to be certified? A certificate for a parent company, one office or a narrow network boundary may not answer a tender for a subsidiary or whole service.

The shared baseline is five technical controls

The NCSC overview identifies five controls:

  • firewalls, which filter traffic between the organisation and the internet;
  • secure configuration, which removes or reduces unnecessary exposure;
  • security update management, which addresses known software vulnerabilities;
  • user access control, which limits who can access systems and at what privilege; and
  • malware protection, which detects or prevents malicious software.

Plus does not replace those controls with a different security framework. It tests the implementation more rigorously. That makes a control gap relevant to both levels, while the evidence collection and assessment activity differ.

Cyber Essentials is verified, not merely self-declared

NCSC’s current route says an organisation completing the self-led option registers through IASME, pays, and completes a verified self-assessment. Answers are signed off by a board member or equivalent and marked by an assessor. NCSC summarises the basic level as a combination of self-assessment and independent audit.

That is different from an internal spreadsheet in which a team marks itself compliant. The applicant needs to understand the assessment questions, define scope and provide answers that withstand assessor review.

The NCSC page accessed for this article listed pricing from £320 plus VAT for Cyber Essentials, depending on organisation size. That figure is a dated starting point, not a universal project quote: advisory work, remediation and estate complexity can add separate costs.

Plus adds independent technical testing

NCSC describes Cyber Essentials Plus as the same protections with more rigorous, independent technical testing. Its price depends on the size and complexity of the network.

For a provider, “ready for Plus” therefore needs operational facts. Which endpoint types, internet-facing services, cloud services, users and remote-working paths sit inside scope? Are sample devices reachable for the assessor? Who can change configurations if a test exposes a failure? How long is available for remediation and retest?

A current basic certificate can be useful evidence that the organisation has already completed the foundational assessment. It is not proof that the Plus technical assessment will pass, and it does not erase a scope mismatch.

Compare the request with one assessment-route card

Use the same seven fields for either level:

FieldCyber EssentialsCyber Essentials Plus
Required outcomeVerified foundational certificatePlus certificate named by buyer or policy
Control themesFive NCSC technical controlsThe same five technical controls
Assessment evidenceSigned verified self-assessment and assessor reviewFoundational assessment plus rigorous independent technical testing
Scope questionEntity and IT boundary covered by answersEntity, IT boundary and estate available for technical test
Readiness riskIncomplete or inaccurate inventory and answersTest access, sampling, configuration failure and retest timing
Pricing factNCSC listed a £320 + VAT starting point on the access dateDepends on network size and complexity
Decision ownerApplicant, certification body and buyer’s acceptance criteriaApplicant, certification body and buyer’s Plus requirement

This assessment-route card is the article’s original contribution. It keeps the comparison on one evidence scale instead of treating Plus as a decorative suffix.

Example: the certificate exists, but covers the wrong boundary

Consider this illustrative composite thread, not a real customer conversation:

“Framework bid closes on the 28th. They wrote CE Plus.”

“We have CE for the London office. Product runs in cloud, half the team remote. No idea if that’s in scope.”

The messages identify a bid date, the Plus level, an existing basic certificate, a London office, cloud service and remote workers. They do not establish the bidding legal entity, certificate status, existing scope, device inventory, cloud administration path, technical-test plan or remediation time.

The correct first proposal is not “replace the certificate.” It is a bounded scope review followed by the certification route that the tender actually requires. If the bid entity or service falls outside the existing certificate, that gap should be explicit before a testing date is promised.

Product discovery is earlier than certification

TOP Prospect can filter and combine fragments from Telegram groups the user deliberately connects and is authorised to access. It can preserve the original message, source and time, join a tender level, certificate status, estate detail and deadline, remove obvious duplicates and rank the discussion for review.

It cannot test devices, access an applicant’s network, act as a certification body, guarantee a pass, determine the tender’s legal meaning or contact group members. Pricing and access options cover early discovery only.

For a different US federal supplier-assurance route, see the CMMC implementation evidence map. A service onboarding request for another assurance standard is covered in the SOC 2 evidence article.

Key facts

  • Cyber Essentials is the UK government-recommended minimum cyber-security standard described by NCSC.
  • Both levels address firewalls, secure configuration, security update management, user access control and malware protection.
  • Cyber Essentials is a verified self-assessment signed off by a board member or equivalent and marked by an assessor; NCSC also describes independent audit.
  • Cyber Essentials Plus adds more rigorous independent technical testing.
  • NCSC listed Cyber Essentials pricing from £320 plus VAT on the page accessed for this article.
  • Plus pricing varies with network size and complexity.
  • Certificate level, legal entity, technical scope and buyer acceptance must all be joined before a provider promises a route.

FAQ

Is Cyber Essentials only an unverified questionnaire?

No. NCSC describes a verified self-assessment signed off by a board member or equivalent and marked by an assessor; it also describes the level as a combination of self-assessment and independent audit.

What does Cyber Essentials Plus add?

It uses the same five technical-control themes but adds more rigorous independent technical testing. The network size and complexity affect the assessment scope and price.

Can a basic Cyber Essentials certificate satisfy a tender asking for Plus?

Only the buyer can interpret its tender, but the two levels are not interchangeable. If the requirement expressly names Plus, the supplier should not represent the basic level as equivalent.

Which facts should a provider confirm before quoting?

Confirm the required level, legal entity and scope, certificate status, device and cloud estate, remote-working boundary, test readiness, remediation window and tender deadline.

The shortest useful answer to “CE or CE Plus?” is the buyer’s exact wording joined to the estate that must be assessed.

Frequently asked questions

Is Cyber Essentials only an unverified questionnaire?

No. NCSC describes a verified self-assessment signed off by a board member or equivalent and marked by an assessor; it also describes the level as a combination of self-assessment and independent audit.

What does Cyber Essentials Plus add?

It uses the same five technical-control themes but adds more rigorous independent technical testing. The network size and complexity affect the assessment scope and price.

Can a basic Cyber Essentials certificate satisfy a tender asking for Plus?

Only the buyer can interpret its tender, but the two levels are not interchangeable. If the requirement expressly names Plus, the supplier should not represent the basic level as equivalent.

Which facts should a provider confirm before quoting?

Confirm the required level, legal entity and scope, certificate status, device and cloud estate, remote-working boundary, test readiness, remediation window and tender deadline.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage