Blog/Certification
CertificationSeptember 2026

Why more contracts and insurers are asking for Cyber Essentials Plus

Cyber Essentials used to be enough to tick the compliance box in most tenders. Increasingly, procurement teams and cyber insurers are asking for the technically verified version — CE+ — instead. Here's why, and what actually changes in the assessment.

Cyber Essentials and Cyber Essentials Plus certify the same five control areas, but they're verified very differently — and that difference is becoming more important to the people asking for proof of either one.

The gap CE+ closes

Cyber Essentials is a self-assessment: your organisation answers a structured questionnaire about its controls, and a certifying body reviews the answers. CE+ adds an external technical audit — a vulnerability scan of your internet-facing systems and an internal assessment of a sample of your devices, carried out independently.

Why it matters to buyers

An external scan and device sample means a CE+ certificate is evidence a third party actually verified your controls — not just that you asserted them on a form.

Where this shows up in practice

  • Government and NHS-adjacent procurement increasingly specifying CE+ over CE for higher-value or higher-risk contracts
  • Cyber insurers factoring CE+ status into premium and coverage decisions, alongside their own proposal questions
  • Enterprise customers treating an existing CE+ certificate as a faster trust signal than waiting on a full security questionnaire response

If you already hold Cyber Essentials, the step up to CE+ is mostly about proving what you've already claimed — the technical controls themselves rarely need to change, but your evidence does.

Read the full guide

How to prepare for Cyber Essentials certification

Start with your free CE+ readiness check

Fortify's free readiness check walks through all five control areas and produces a scored gap report in 10 minutes — no account required.