If you're a UK business preparing for a tender, an NHS contract, or an MOD supply chain relationship, you've probably run into two terms that get used almost interchangeably — and shouldn't be: Cyber Essentials Plus and penetration testing. They're related, but they are not the same thing, and understanding the difference will save you from either under-preparing for an audit or overpaying for testing you don't yet need.
What Cyber Essentials Actually Is
Cyber Essentials is a UK Government-backed scheme, overseen by the National Cyber Security Centre (NCSC), built around five technical controls: firewalls, secure configuration, user access control, malware protection, and security update (patch) management. It comes in two tiers:
- Cyber Essentials — a self-assessment questionnaire, independently verified by an external Certification Body.
- Cyber Essentials Plus (CE+) — the same five controls, plus an independent technical audit. A qualified assessor connects to a sample of your devices, runs vulnerability scans, attempts to deliver simulated malware to test your endpoint defences, and inspects configuration evidence directly rather than taking your word for it.
CE+ has become the assurance level UK Government departments, the Ministry of Defence, and NHS suppliers increasingly require from their supply chain — and it's becoming standard in enterprise procurement for any vendor handling sensitive data.
What Changed in April 2026
The scheme's requirements tightened significantly under the v3.3 update, which applies to assessments started after 26 April 2026. The changes that matter most:
- No major non-compliances allowed into the CE+ audit stage. Previously you could carry up to two major non-compliances into the self-assessment and still pass; now those have to be resolved before the technical audit even begins.
- Password minimum length increased to 12 characters (up from 8), unless offset by technical controls like MFA, throttling, or account lockout.
- MFA is now mandatory wherever it's available on a system.
- Patch verification got stricter. High and critical vulnerabilities must be patched within 14 days, and the auditor runs an authenticated scan against a device sample to confirm it. If a second sampled batch still fails the same vulnerability, there's no remediation window — it's an immediate fail, and IASME will revoke the underlying Cyber Essentials certificate along with it.
- Only IASME-approved scanning tools can be used as audit evidence going forward.
In short: CE+ has moved from "prove you did the paperwork" to "prove your controls are actually working right now." That's a meaningfully higher bar than it was a year ago.
Does Cyber Essentials Plus Require a Penetration Test?
This is the part that trips people up. Not exactly. The CE+ technical audit is a vulnerability scan plus a simulated malware delivery test performed by an accredited assessor — it is not a full, manual, adversarial penetration test in the sense a security firm normally uses that term. A penetration tester actively tries to chain vulnerabilities together, escalate privileges, and demonstrate real business impact. A CE+ assessor is checking whether your patching, configuration, and malware defences meet a defined technical baseline.
That distinction matters for budgeting: CE+ certification itself doesn't obligate you to commission a separate penetration test. But in practice, many UK businesses end up needing both — for reasons that have nothing to do with the certificate itself.
When You Need Penetration Testing on Top of Cyber Essentials Plus
- Tender requirements. Some public sector and enterprise tenders explicitly require a CREST-accredited (or equivalent) penetration test in addition to CE+, especially for suppliers handling personal or clinical data.
- NHS Data Security and Protection Toolkit (DSPT). NHS suppliers are frequently expected to demonstrate testing beyond the CE+ baseline as part of DSPT compliance.
- Custom web applications and APIs. CE+ scans your infrastructure and endpoints — it does not test the business logic of a custom-built application. If you've built your own product, application-layer penetration testing is a separate, necessary exercise.
- Pursuing ISO 27001 alongside Cyber Essentials. ISO 27001 is broader and typically expects evidence of regular penetration testing as part of its ongoing control set, assessed over a three-year certification cycle with annual surveillance audits.
- You simply want deeper assurance than a fixed technical baseline can offer — particularly if you handle sensitive customer data or are a frequent target due to your industry.
Where Nexoryn Security Fits
To be clear on scope: formal Cyber Essentials and Cyber Essentials Plus certification has to be issued through an NCSC/IASME-accredited Certification Body — that's not something a penetration testing firm does. What Nexoryn Security does is the technical work that sits alongside it: application and infrastructure penetration testing to satisfy tender requirements that go beyond CE+, remediation support to help you pass patch and configuration checks cleanly the first time, and — for businesses that want to move past a once-a-year snapshot — Shield, our continuous protection subscription with ongoing automated and manual assessments and a live vulnerability dashboard, starting at £309/month.
If you're a UK business trying to work out whether you need CE+, a full penetration test, or both, that scoping conversation is worth having before you commit to either.

Comments
Post a Comment