Two questions arrive at our door most months, and both come from the same misunderstanding.

“We had a penetration test last year, so we should pass Cyber Essentials Plus easily, right?”

“We’ve got Cyber Essentials Plus. Does that mean we don’t need a penetration test?”

The answer to both is no, and the reason matters. These are not two grades of the same thing. They are different exercises, with different scopes, different rules and different purposes, and each one leaves exactly the gap the other fills.

PrescribedCyber Essentials Plus follows a defined test specification
Open endedA test follows what it finds, within the agreed scope
NeitherSubstitutes for the other. Ever

What Cyber Essentials Plus actually is

Cyber Essentials Plus is an independent technical audit that verifies the five Cyber Essentials controls are genuinely in place. It follows a defined test specification, and it must be carried out by an assessor working for a licensed certification body.

That word “prescribed” is the important one. The assessor is not free to improvise. The tests are specified: a sample of devices is examined, patch levels are checked against the requirement, malware protection is verified, email and web browser handling of malicious files is tested, account separation and authentication are confirmed. The same tests, applied consistently, so that a certificate issued in Salisbury means the same thing as one issued in Sunderland.

It also depends on a passing Cyber Essentials certificate first. The self-assessment describes the controls; Plus verifies the description was true.

What it deliberately does not do: attempt to break in, chain findings into an attack path, test your web application’s business logic, or go looking for anything outside its specification. It is not trying to. Consistency is the entire point of a certification scheme.

What a penetration test is

A penetration test is a skilled person attempting to achieve something an attacker would want to achieve, within an agreed scope and rules of engagement. There is no fixed test list, because the value lies in the tester following what they find.

They chain weaknesses together, exploit misconfigurations, look for logic flaws nobody documented, and demonstrate impact with evidence. Two tests of the same environment by different testers will not produce identical reports, and that variation is a feature rather than a fault.

What it deliberately does not do: certify anything. There is no pass mark, no standard being measured against, and no badge at the end. A test report is evidence of what was found, not proof that a control framework is in place.

The difference, drawn

Cyber Essentials Plus runs a fixed sequence of prescribed tests: sample of devices, patch levels, malware protection, email and browser tests, accounts and authentication. A penetration test starts from an agreed scope and branches, chaining findings such as weak configuration, an exposed service and a username format into a compromised account and a proven business impact.
One follows a specified route so that every certificate means the same thing. The other follows whatever the tester finds, inside the boundary you agreed.

Side by side

Cyber Essentials PlusPenetration test
PurposeVerify the five controls are implementedFind what an attacker could achieve
MethodPrescribed tests, applied consistentlyOpen ended, guided by what the tester finds
Who can deliver itAn assessor at a licensed certification bodyAny competent tester, ideally certified
ScopeDefined by the scheme, sampled across the estateDefined by you, usually narrower and deeper
PrerequisiteA passing Cyber Essentials certificateNone
OutputPass or fail, and a certificateA report of findings, attack paths and evidence
Recognised byGovernment contracts, insurers, supply chainsCustomers, auditors, boards, regulators
RepeatableYes, deliberately identical each yearNo, and it should not be

What actually happens on the day

Cyber Essentials Plus. The assessor agrees a testing window and a device sample with you in advance, then works through the specification: confirming the sampled devices are patched within the required timescales, that malware protection is present and functioning, that the browser and email client handle known malicious files the way the requirement expects, and that accounts and authentication match what you declared. You know beforehand what will be tested, because it is published. There are no surprises by design.

A penetration test. You agree scope, rules of engagement and a testing window, then the tester works. Reconnaissance first, then probing, then following whatever looks promising. You do not know in advance what they will try, because neither do they until they see what is there. The interesting findings usually arrive late in the engagement, once enough small things have been assembled into something that matters.

The mindset is the difference. One asks “is the control present and working?” and records the answer. The other asks “given everything I can see, what could I do here?” and keeps pulling.

Why the confusion is expensive

Assuming a penetration test satisfies Cyber Essentials Plus. It does not, and it cannot. Plus requires its own prescribed audit by a licensed certification body; there is no route by which an unrelated test substitutes for it. Businesses that discover this a fortnight before a tender deadline lose the tender, not the argument.

Assuming Cyber Essentials Plus means you are tested. It means five specific control areas were verified on a sample of your estate. It says nothing about your web application, your business logic, your internal network segregation, or what someone with a stolen password could reach. A customer asking “have you been penetration tested?” is not asking whether you hold Plus.

Assuming they compete for the same budget. They answer to different audiences. Plus is procurement evidence; a test is engineering evidence. Organisations with both are not gold plating, they are answering two different questions that both get asked.

The short version

Cyber Essentials Plus proves your basics are genuinely in place, consistently, to a national standard. A penetration test proves what a determined person can do to you specifically. One is a certificate; the other is an education. Most businesses that need one eventually need both.

Cost, frequency and what you get to show for it

Cyber Essentials PlusPenetration test
Priced byOrganisation size, published in advanceComplexity and tester days, scoped first
FrequencyAnnually, to keep certification currentPeriodically, and after significant change
DurationTypically a day or less of testing for a smaller estateDays to weeks, depending on scope
You receiveA certificate and a verifiable badgeA report, evidence, and a remediation plan
Shows a customerThat a national standard was independently verifiedThat you have tested your defences seriously

Our Cyber Essentials Plus pricing is published by organisation size on the Cyber Essentials page. Penetration testing is scoped before it is quoted, because there is no honest way to price an open ended exercise without knowing what it covers.

Which do you need first?

If a contract or tender asks for Cyber Essentials Plus, that is the answer, and no amount of testing evidence replaces it. Start there. Our Cyber Essentials certification page covers both levels and publishes the pricing.

If you hold Cyber Essentials Plus and want to know what remains, that is exactly the moment a penetration test earns its fee: the fundamentals are verified, so the tester spends their time on genuinely interesting problems rather than reporting missing patches.

If you have neither and no deadline, start with Cyber Essentials, then a vulnerability assessment to see the estate as it really is, then testing where it matters. We wrote about choosing between assessment and testing separately.

One point of independence

We are a licensed certification body for Cyber Essentials and Cyber Essentials Plus, and we deliver penetration testing through Cyber Scheme certified testers. That means we can tell you honestly which you need, including when the answer is only one of them.

It also means we keep the two properly separate. A penetration test we deliver does not become evidence in a Cyber Essentials Plus audit, because the scheme does not work that way and a certificate is only worth what its independence is worth.

Get in touch or call 01722 445972 if you want a straight answer about which of these your situation actually calls for.