Two questions arrive at our door most months, and both come from the same misunderstanding.
“We had a penetration test last year, so we should pass Cyber Essentials Plus easily, right?”
“We’ve got Cyber Essentials Plus. Does that mean we don’t need a penetration test?”
The answer to both is no, and the reason matters. These are not two grades of the same thing. They are different exercises, with different scopes, different rules and different purposes, and each one leaves exactly the gap the other fills.
What Cyber Essentials Plus actually is
Cyber Essentials Plus is an independent technical audit that verifies the five Cyber Essentials controls are genuinely in place. It follows a defined test specification, and it must be carried out by an assessor working for a licensed certification body.
That word “prescribed” is the important one. The assessor is not free to improvise. The tests are specified: a sample of devices is examined, patch levels are checked against the requirement, malware protection is verified, email and web browser handling of malicious files is tested, account separation and authentication are confirmed. The same tests, applied consistently, so that a certificate issued in Salisbury means the same thing as one issued in Sunderland.
It also depends on a passing Cyber Essentials certificate first. The self-assessment describes the controls; Plus verifies the description was true.
What it deliberately does not do: attempt to break in, chain findings into an attack path, test your web application’s business logic, or go looking for anything outside its specification. It is not trying to. Consistency is the entire point of a certification scheme.
What a penetration test is
A penetration test is a skilled person attempting to achieve something an attacker would want to achieve, within an agreed scope and rules of engagement. There is no fixed test list, because the value lies in the tester following what they find.
They chain weaknesses together, exploit misconfigurations, look for logic flaws nobody documented, and demonstrate impact with evidence. Two tests of the same environment by different testers will not produce identical reports, and that variation is a feature rather than a fault.
What it deliberately does not do: certify anything. There is no pass mark, no standard being measured against, and no badge at the end. A test report is evidence of what was found, not proof that a control framework is in place.
The difference, drawn
Side by side
| Cyber Essentials Plus | Penetration test | |
|---|---|---|
| Purpose | Verify the five controls are implemented | Find what an attacker could achieve |
| Method | Prescribed tests, applied consistently | Open ended, guided by what the tester finds |
| Who can deliver it | An assessor at a licensed certification body | Any competent tester, ideally certified |
| Scope | Defined by the scheme, sampled across the estate | Defined by you, usually narrower and deeper |
| Prerequisite | A passing Cyber Essentials certificate | None |
| Output | Pass or fail, and a certificate | A report of findings, attack paths and evidence |
| Recognised by | Government contracts, insurers, supply chains | Customers, auditors, boards, regulators |
| Repeatable | Yes, deliberately identical each year | No, and it should not be |
What actually happens on the day
Cyber Essentials Plus. The assessor agrees a testing window and a device sample with you in advance, then works through the specification: confirming the sampled devices are patched within the required timescales, that malware protection is present and functioning, that the browser and email client handle known malicious files the way the requirement expects, and that accounts and authentication match what you declared. You know beforehand what will be tested, because it is published. There are no surprises by design.
A penetration test. You agree scope, rules of engagement and a testing window, then the tester works. Reconnaissance first, then probing, then following whatever looks promising. You do not know in advance what they will try, because neither do they until they see what is there. The interesting findings usually arrive late in the engagement, once enough small things have been assembled into something that matters.
The mindset is the difference. One asks “is the control present and working?” and records the answer. The other asks “given everything I can see, what could I do here?” and keeps pulling.
Why the confusion is expensive
Assuming a penetration test satisfies Cyber Essentials Plus. It does not, and it cannot. Plus requires its own prescribed audit by a licensed certification body; there is no route by which an unrelated test substitutes for it. Businesses that discover this a fortnight before a tender deadline lose the tender, not the argument.
Assuming Cyber Essentials Plus means you are tested. It means five specific control areas were verified on a sample of your estate. It says nothing about your web application, your business logic, your internal network segregation, or what someone with a stolen password could reach. A customer asking “have you been penetration tested?” is not asking whether you hold Plus.
Assuming they compete for the same budget. They answer to different audiences. Plus is procurement evidence; a test is engineering evidence. Organisations with both are not gold plating, they are answering two different questions that both get asked.
Cyber Essentials Plus proves your basics are genuinely in place, consistently, to a national standard. A penetration test proves what a determined person can do to you specifically. One is a certificate; the other is an education. Most businesses that need one eventually need both.
Cost, frequency and what you get to show for it
| Cyber Essentials Plus | Penetration test | |
|---|---|---|
| Priced by | Organisation size, published in advance | Complexity and tester days, scoped first |
| Frequency | Annually, to keep certification current | Periodically, and after significant change |
| Duration | Typically a day or less of testing for a smaller estate | Days to weeks, depending on scope |
| You receive | A certificate and a verifiable badge | A report, evidence, and a remediation plan |
| Shows a customer | That a national standard was independently verified | That you have tested your defences seriously |
Our Cyber Essentials Plus pricing is published by organisation size on the Cyber Essentials page. Penetration testing is scoped before it is quoted, because there is no honest way to price an open ended exercise without knowing what it covers.
Which do you need first?
If a contract or tender asks for Cyber Essentials Plus, that is the answer, and no amount of testing evidence replaces it. Start there. Our Cyber Essentials certification page covers both levels and publishes the pricing.
If you hold Cyber Essentials Plus and want to know what remains, that is exactly the moment a penetration test earns its fee: the fundamentals are verified, so the tester spends their time on genuinely interesting problems rather than reporting missing patches.
If you have neither and no deadline, start with Cyber Essentials, then a vulnerability assessment to see the estate as it really is, then testing where it matters. We wrote about choosing between assessment and testing separately.
One point of independence
We are a licensed certification body for Cyber Essentials and Cyber Essentials Plus, and we deliver penetration testing through Cyber Scheme certified testers. That means we can tell you honestly which you need, including when the answer is only one of them.
It also means we keep the two properly separate. A penetration test we deliver does not become evidence in a Cyber Essentials Plus audit, because the scheme does not work that way and a certificate is only worth what its independence is worth.
Get in touch or call 01722 445972 if you want a straight answer about which of these your situation actually calls for.