Skip to content
Guides

Who needs Cyber Essentials Plus?

Cyber Essentials Plus is needed when a tender, contract, framework, customer, or risk decision explicitly requires independently tested assurance. Contract value alone does not determine the level.

silver padlock

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Who needs Cyber Essentials Plus?

You need Cyber Essentials Plus when a tender, contract, framework, customer, or internal risk decision explicitly requires independently tested assurance. Contract value alone does not decide the level. If the requirement only names Cyber Essentials, do not assume Plus is mandatory.

Section 02

Cyber Essentials Plus is typically required for:

MOD and defence sub-contracting

Defence contracts can combine Cyber Essentials requirements with Defence Cyber Certification. The applicable level comes from the contract, its Cyber Risk Profile, and any flow-down terms from the prime contractor. Check those documents rather than assuming every defence subcontract requires Plus.

Higher-risk public contracts

PPN 014 describes Plus as the more rigorous assessment to use when cyber risk is higher. It does not prescribe a £5 million or other contract-value threshold for Plus. The contracting organisation should state the proportionate requirement in the tender.

NHS and healthcare supplier frameworks

PPN 014 applies to NHS bodies as in-scope organisations, but the requirement remains contract-specific and proportionate. An NHS tender or supplier framework may specify Plus; the buyer's published documents are the source of truth.

Financial services regulated supply chain

Regulated firms can require Plus through their supplier-onboarding standards or contract. That is a buyer requirement, not a universal FCA or PRA rule applying to every supplier.

SJP partner practices

St. James's Place Partner practices should follow their current practice instructions. The published route allows Cyber Essentials Plus or the approved Device-as-a-Service alternative; the individual practice's applicable notice and scope decide what to arrange.

Enterprise B2B SaaS supplier onboarding

An enterprise buyer may specify Plus in its vendor questionnaire or contract, particularly for suppliers with privileged access or sensitive data. Treat the buyer's actual wording as decisive.

Section 03

Where standard Cyber Essentials is sufficient

  • Most B2B SME work without specific procurement mandates
  • A legal practice whose actual PI insurer or client contract requests Plus
  • General client-onboarding signals for most professional services
  • A business whose own insurer specifically asks for Plus; cover and pricing remain the insurer's decision
  • A charity whose specific funder agreement names Plus

Section 04

Cost and timeline

Because Plus requires a valid standard CE certificate as a prerequisite, a combined package may include Basic and Plus in one engagement. Check the quote before purchasing; a separate duplicate Basic purchase is not inherently required. See Can I get Cyber Essentials Plus without Cyber Essentials?.

Section 05

Bottom line

You need Cyber Essentials Plus if your tender documents, supplier-onboarding form, regulatory counterparty, or insurance broker says so. For most UK SMEs without that specific pressure, standard CE is the right bar. Review the Cyber Essentials Plus certification service for the audit scope and preparation requirements, or use the full pricing page to compare both levels side by side.

Start Cyber Essentials from £299.99 + VAT | Explore Cyber Essentials Plus | Cyber Essentials vs Cyber Essentials Plus

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Choose the right Plus assessment for your organisation

Review your scope, baseline certificate date and device availability before arranging the technical audit. Certification follows a successful assessment; the Basic six-working-hour guarantee does not apply to Plus.