Skip to content
Standards & certification

Cyber Essentials vs Cyber Essentials Plus: which does your school need?

Published 13 August 2026 · Last reviewed 13 August 2026

Cyber Essentials and Cyber Essentials Plus certify the same five technical controls — the difference is entirely in how much proof stands behind the certificate. That makes the choice simpler than it looks: it turns on who will read your certificate, and what they need it to demonstrate.

The differences that actually matter

What it is

Cyber Essentials: A verified self-assessment: your school answers the question set, a senior person signs it, an assessor reviews the answers.

Cyber Essentials Plus: The same requirements, independently tested: an auditor technically verifies on your systems that the claims are true.

The controls

Cyber Essentials: The five control areas — firewalls, secure configuration, user access control, malware protection, security update management.

Cyber Essentials Plus: Identical. Plus adds no new controls; it adds proof.

External validation

Cyber Essentials: Trust in your declaration, reviewed. It proves the school has attested, competently, to the basics.

Cyber Essentials Plus: Hands-on testing. It proves the basics are actually in force — a materially stronger claim to show a third party.

Effort and disruption

Cyber Essentials: Mostly preparation and honest form-filling with your IT provider.

Cyber Essentials Plus: The same preparation plus an audit window — device sampling, testing time, and remediation of anything found.

Cost

Cyber Essentials: From £320 +VAT (the NCSC's published starting price; fees are tiered — current figures on the IASME site).

Cyber Essentials Plus: Priced by the size and complexity of your network, on top of the standard assessment. Get a quote before budgeting.

Timing

Cyber Essentials: Whenever you're ready — and readiness first is cheaper than failing.

Cyber Essentials Plus: Follows the standard assessment within a fixed window on the same scope (three months at the time of writing — confirm the current rule with your certification body when booking, because missing it means re-taking the standard assessment).

When a school should choose each

Standard Cyber Essentials fits when the asker — a framework, an insurer, a trust — names it without the Plus, when budget is tight, or when this is the school’s first certification cycle and the discipline of the question set is itself the value. Plus earns its cost when a contract or framework explicitly requires it, when a trust wants independently verified assurance across academies rather than seven self-declarations, or when leadership wants the audit precisely because it cannot be self-graded. Many schools sensibly do standard first, live with it for a cycle, and step up when an external reason arrives — and because Plus must follow within the window on the same scope, the step up is a planned pair, not an afterthought.

What Ceidwad can and cannot do here
We are not a certification body: certificates come through IASME, the NCSC’s delivery partner, and its licensed assessors — for either version. What we can honestly do is the readiness half: our platform tracks a school’s distance from these controls and keeps the evidence, which makes preparation cheaper and failure less likely. A readiness view is not a certificate, whichever version you pursue.

The wider context — whether your school needs certification at all, and how these controls relate to the DfE’s expectations — is in the Cyber Essentials hub and the DfE standards guide; the hands-on preparation list is the school cyber security checklist.

Want to know where your school stands?

Assess your school’s cyber readiness in about two minutes — no account, and nothing connects to your systems. You’ll get an indicative score and a plain-English list of what to fix first.

Start the free assessment

Sources

Related