There are two Cyber Essentials certification levels. The standard option is based on a verified questionnaire, while Cyber Essentials Plus uses independent technical testing to confirm that the same five controls are working correctly.
The audit examines a representative sample of user devices, servers and network equipment. It includes an internal vulnerability scan and checks covering updates, account security, system configurations and protection against malware.
Assessors also examine internet gateways, relevant IP addresses and servers with services accessible from the internet. The process combines a remote audit with on-site testing completed by an authorised assessor.
Cyber Essentials Plus does not introduce different controls or stricter marking criteria. It provides a higher level of assurance because the assessor tests the measures described in the original assessment.
Organisations operating in high-risk sectors, handling sensitive information, or responding to stricter procurement requirements often choose this certification level. Standard certification must be achieved before the Plus audit is completed.
No. Cyber Essentials concentrates on five practical safeguards against common attacks. ISO 27001 is a broader international standard covering the policies, processes, and risk management systems used to manage information security.
The relationship between Cyber Essentials and cyber standards such as ISO 27001 is complementary. They serve different purposes, and holding one does not automatically confirm compliance with the other.