Cyber Essentials and Cyber Essentials Plus certify the same five technical controls — the difference is entirely in how much proof stands behind the certificate. That makes the choice simpler than it looks: it turns on who will read your certificate, and what they need it to demonstrate.
The differences that actually matter
What it is
Cyber Essentials: A verified self-assessment: your school answers the question set, a senior person signs it, an assessor reviews the answers.
Cyber Essentials Plus: The same requirements, independently tested: an auditor technically verifies on your systems that the claims are true.
The controls
Cyber Essentials: The five control areas — firewalls, secure configuration, user access control, malware protection, security update management.
Cyber Essentials Plus: Identical. Plus adds no new controls; it adds proof.
External validation
Cyber Essentials: Trust in your declaration, reviewed. It proves the school has attested, competently, to the basics.
Cyber Essentials Plus: Hands-on testing. It proves the basics are actually in force — a materially stronger claim to show a third party.
Effort and disruption
Cyber Essentials: Mostly preparation and honest form-filling with your IT provider.
Cyber Essentials Plus: The same preparation plus an audit window — device sampling, testing time, and remediation of anything found.
Cost
Cyber Essentials: From £320 +VAT (the NCSC's published starting price; fees are tiered — current figures on the IASME site).
Cyber Essentials Plus: Priced by the size and complexity of your network, on top of the standard assessment. Get a quote before budgeting.
Timing
Cyber Essentials: Whenever you're ready — and readiness first is cheaper than failing.
Cyber Essentials Plus: Follows the standard assessment within a fixed window on the same scope (three months at the time of writing — confirm the current rule with your certification body when booking, because missing it means re-taking the standard assessment).
When a school should choose each
Standard Cyber Essentials fits when the asker — a framework, an insurer, a trust — names it without the Plus, when budget is tight, or when this is the school’s first certification cycle and the discipline of the question set is itself the value. Plus earns its cost when a contract or framework explicitly requires it, when a trust wants independently verified assurance across academies rather than seven self-declarations, or when leadership wants the audit precisely because it cannot be self-graded. Many schools sensibly do standard first, live with it for a cycle, and step up when an external reason arrives — and because Plus must follow within the window on the same scope, the step up is a planned pair, not an afterthought.
The wider context — whether your school needs certification at all, and how these controls relate to the DfE’s expectations — is in the Cyber Essentials hub and the DfE standards guide; the hands-on preparation list is the school cyber security checklist.


