Guide
Cyber Essentials Plus penetration testing: related, but not the same
Cyber Essentials Plus penetration testing questions usually come from UK firms asked for both. However, the CE Plus technical audit and a penetration test answer different questions.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
What Cyber Essentials Plus checks
Cyber Essentials is a UK government-backed scheme covering five basic technical controls. Also, the Plus level adds hands-on verification by an assessor from a certification body.
The checks confirm the basics are in place. For example, devices are patched and malware protection works.
How a pentest differs from Cyber Essentials Plus penetration testing assumptions
Many buyers assume CE Plus includes a full pentest. However, it is a defined technical audit of baseline controls, not an open-ended attempt to break in.
| Topic | CE Plus audit | Penetration test |
|---|---|---|
| Goal | Verify baseline controls | Find exploitable weaknesses |
| Scope | Set by the scheme | Agreed with you |
| Depth | Defined checks | Manual, creative testing |
| Who performs | Certification body assessor | Independent tester |
Cyber Essentials Plus penetration testing planning check
Tick what you know about the request.
Your result appears here as you tick, so you can see what is still open.
When to commission Cyber Essentials Plus penetration testing alongside
Some contracts ask for both. Therefore plan them together, so findings from one feed the other.
- Public sector contracts often require CE or CE Plus
- Enterprise customers may also ask for a pentest report
- SOC 2 or ISO 27001 auditors may expect testing
- Your own risk appetite may demand more depth
A sensible order
Fix the basics first, then certify, then test deeper. As a result, the pentest spends time on real weaknesses rather than missing patches.
In addition, we are not a certification body, so we do not issue Cyber Essentials. Scheme details are in the NCSC Cyber Essentials overview.
Fees and timing
Packages start at $5,900 for one asset and $14,500 for up to three, each as a fixed fee. One retest inside 30 days is included, and the report is delivered in 10 working days. Testing is delivered by vetted third-party practitioners under our project management.
Cyber Essentials Plus penetration testing questions
Does Cyber Essentials Plus include a penetration test?
No. It includes a defined technical audit of baseline controls.
Can one supplier do Cyber Essentials Plus penetration testing and certification?
Only certification bodies certify. A separate tester can run the pentest.
Which should come first, CE Plus or Cyber Essentials Plus penetration testing work?
Usually the basics and CE Plus first, then a deeper pentest.
Do you issue Cyber Essentials?
No. We are not a certification body.
Related guides
Plan Cyber Essentials Plus penetration testing sensibly
Tell us what your contract requires. We reply with a fixed fee for any pentest, usually within four working hours.
Get my fixed-fee quote