Cyber Essentials used to be enough to tick the compliance box in most tenders. Increasingly, procurement teams and cyber insurers are asking for the technically verified version — CE+ — instead. Here's why, and what actually changes in the assessment.
Cyber Essentials and Cyber Essentials Plus certify the same five control areas, but they're verified very differently — and that difference is becoming more important to the people asking for proof of either one.
Cyber Essentials is a self-assessment: your organisation answers a structured questionnaire about its controls, and a certifying body reviews the answers. CE+ adds an external technical audit — a vulnerability scan of your internet-facing systems and an internal assessment of a sample of your devices, carried out independently.
Why it matters to buyers
An external scan and device sample means a CE+ certificate is evidence a third party actually verified your controls — not just that you asserted them on a form.
If you already hold Cyber Essentials, the step up to CE+ is mostly about proving what you've already claimed — the technical controls themselves rarely need to change, but your evidence does.
Read the full guide
How to prepare for Cyber Essentials certification
Fortify's free readiness check walks through all five control areas and produces a scored gap report in 10 minutes — no account required.