• About Us
  • Contact

Cyber Essentials vs Cyber Essentials Plus for Building Security Strategy

Published: 30th July 2026

In the latest episode of the Red Helix Cyber in Focus podcast, Red Helix’s Head of Cyber Security Tom Exelby sits down with Risk Crew’s Lead Compliance Consultant, Antony Hyson Seltran to unpack the changing landscape of Cyber Essentials.  

Drawing on extensive experience across hundreds of certifications, the discussion highlights a crucial operational truth: baseline cyber security is no longer a secondary compliance task, but a fundamental commercial requirement for SMEs across the UK. 

Make sure to listen to the full episode of the Red Helix Cyber in Focus podcast on Spotify or YouTube for more insights on managing cyber risk, governance, and technical compliance: https://open.spotify.com/episode/7H8JXP43fo4Pj6n0Gc6N7S?si=IamJiShJSYq_45-mX9ilSg  

Why SMEs Are Prime Supply Chain Targets

The threat environment facing smaller UK businesses has escalated dramatically over the past two years. Threat actors increasingly view small and medium enterprises as accessible entry points into broader corporate and public sector supply chains. Human factors remain a primary vulnerability, with phishing, credential theft, and misconfigured systems providing easy initial access.  

At the same time, technological risks are accelerating rapidly. Attackers now leverage artificial intelligence tools to analyse released vendor patches and reverse engineer functional exploits within hours. This leaves organisations with a significantly narrower window to apply critical security updates before automated scanning tools detect vulnerable systems on their networks. 

The Five Core Controls of Cyber Essentials

Cyber Essentials mitigates commodity attacks by focusing on five foundational technical controls. These encompass firewalls and internet gateways to secure network perimeters, secure system configuration to remove unnecessary default functions, user access management to restrict administrative privileges, malware protection to defend endpoints against malicious software, and security update management to enforce rapid patching routines.  

Adhering to these five controls transforms an organisation into a significantly harder target for automated attacks. Statistical data shows certified businesses are 92% less likely to make a cyber insurance claim. Furthermore, eligible UK businesses with annual turnovers under twenty million pounds receive inclusive cyber liability insurance through IASME upon achieving certification. 

Cyber Essentials vs. Cyber Essentials Plus

While standard Cyber Essentials relies on a verified self-assessment questionnaire, Cyber Essentials Plus introduces rigorous independent technical testing. During a Cyber Essentials Plus audit, qualified assessors perform hands-on technical checks across the environment. These checks include internal and external vulnerability scans, malware execution tests, email application checks, and network segregation verification.  

Organisations typically pursue Cyber Essentials Plus to satisfy strict enterprise supply chain requirements, qualify for government and Ministry of Defence contracts, or provide verified proof that their documented policies match technical realities. 

Navigating Key Changes Under the Danzell Update

The scheme update, designated as the Danzell standard, introduces significantly stricter compliance enforcement compared to the outgoing Willow scheme. Under Danzell, historical leniencies have been removed, turning former minor gaps into automatic assessment failures. 

A strict 14-day patching rule is now enforced for all critical and high-risk vulnerabilities across operating systems, third-party software, and network appliances, meaning missing this window results in an immediate assessment fail. Multi-factor authentication has also been made non-negotiable. If a cloud software vendor offers multi-factor authentication, even as an extra paid licence tier, the organisation must purchase and configure it across all accounts. Relying on single-factor authentication or IP allowlisting is no longer permitted. 

Organisations must also hold a completely clean basic Cyber Essentials certificate to even be eligible for Cyber Essentials Plus. The mechanics of technical rescans have also been tightened. If an unpatched vulnerability causes an initial failure during a Cyber Essentials Plus audit, the business receives a 30-day remediation window. However, when the assessor returns, they will retest the original failing device alongside a secondary, freshly chosen sample. If that new sample exhibits the same unpatched vulnerability, the organisation fails Cyber Essentials Plus completely and their baseline Cyber Essentials certificate is revoked. 

Common Assessment Pitfalls and Failures 

Audit failures frequently stem from predictable operational oversight. Untracked assets and unsupported end-of-life hardware are common culprits, particularly legacy firewalls and routers that no longer receive vendor security patches. Another frequent pitfall is poor account separation, where directors and IT staff conduct day-to-day work like email and web browsing while logged into accounts with permanent administrative rights. Smaller firms also commonly fail the basic questionnaire due to missing written policy documentation, such as formal joiners and leavers procedures or written password standards. Any discrepancies between questionnaire answers and technical realities become immediately obvious during hands-on Cyber Essentials Plus testing. 

Practical Steps to Prepare for Renewal

Organisations planning an initial assessment or upcoming renewal should start preparing two months in advance of their deadline. The process must begin with a comprehensive audit of all endpoints, mobile devices, network appliances, and cloud software to eliminate any unsupported assets. Automated patching routines must be verified to ensure fixes land well within the 14-day window, and multi-factor authentication must be enabled across every user account.  

Partnering with an accredited Certification Body like Risk Crew early in the process ensures network scope boundaries are properly defined before formal submission, preventing costly audit surprises. 

Walking Before You Run

Attempting to adopt complex frameworks such as NIST or the NCSC Cyber Assessment Framework without first mastering foundational technical controls often leads to unnecessary operational friction.  

Cyber Essentials and Cyber Essentials Plus provide the practical building blocks needed to establish real defensive resilience. By embedding these baseline controls into everyday operations rather than treating certification as an annual tick-box exercise, UK businesses protect their positions in critical supply chains and build a lasting security posture.