Skip to content

Home » Insights » Cyber Essentials Plus vs penetration testing: what each covers and which to do first

Cyber Essentials Plus vs penetration testing: what each covers and which to do first

By Lewis Lockwood · Published · Updated

Book a call

A scrabble type block spelling the word cyber

In short. Cyber Essentials Plus is a pass/fail audit of five baseline controls on a sample of your devices; a penetration test is a qualified tester trying to get into your systems the way an attacker would. One does not replace the other, and this guide explains what each covers, which to do first and how to scope both in one conversation.

Cyber Essentials Plus and a penetration test answer different questions. Cyber Essentials Plus is a pass/fail audit of five baseline controls on a sample of your devices, run by a licensed certification body against a fixed standard; it tells a customer your basics are in place. A penetration test is an attempt by a qualified tester to get into your systems the way an attacker would; it tells you whether they could. One does not replace the other, and passing Plus comfortably says nothing about your web application, your cloud tenant or your internal network. This guide explains what each covers, where they overlap, which to do first, and how to run both without paying for the same work twice.

What Cyber Essentials Plus does and does not test

Cyber Essentials Plus verifies five controls: firewalls, secure configuration, security update management, user access control and malware protection. The assessor runs an external vulnerability scan of your internet gateways, an authenticated internal scan of a random sample of devices, malware protection tests by email and browser download, and configuration checks such as patching within 14 days, separate administrator accounts and multi-factor authentication on cloud services. It is assessed against the IASME standard and results in a certificate valid for twelve months.

It does not test your web applications, your APIs, your cloud configuration beyond the MFA check, your Active Directory, your wireless network or your building, and it does not attempt to exploit anything it finds. A vulnerability scan that reports a missing patch is the end of the Plus process; for a penetration tester it is the beginning.

What a penetration test covers that Plus does not

AreaCyber Essentials PlusPenetration test
External perimeterVulnerability scan of gateways and exposed serversA tester exploits what the scan finds and looks for what it missed: weak credentials, exposed services, logic flaws
Web applications and APIsNot assessedAuthenticated testing of every role, access control, injection, business logic
Internal networkAuthenticated scan of sampled devicesWhat an attacker or compromised device can reach: privilege escalation, lateral movement, domain compromise
Cloud (Microsoft 365, Azure, AWS, Google Cloud)MFA check onlyConfiguration and identity review: over-privileged roles, exposed storage, conditional access gaps
Wireless, physical, buildsNot assessedAssessed where in scope
OutputPass/fail certificateReport with rated findings, impact, remediation and a retest

Which should you do first?

If a customer, contract or framework requires Cyber Essentials Plus, do that first. It has a deadline, a fixed standard and a 90-day window after the basic certificate, so it needs to be scheduled. If nothing requires it, an external penetration test usually finds more that matters per pound spent, because it tests what is actually exposed rather than what a sample of devices is configured to do.

If you are going to do both within a few months, say so at the start. The same weaknesses fail Plus and appear in a penetration test report (unpatched systems, missing MFA, shared administrator accounts), and sequencing the two means you fix them once and the fix counts towards both.

How we run them together

Incursion Cyber Security is an IASME-licensed certification body for Cyber Essentials Plus and a penetration testing consultancy, and our Plus assessors are penetration testers. That lets us do the following:

  1. One scoping conversation. An active penetration tester scopes the test; the same short question set scopes the Plus assessment and is reviewed by an assessor.
  2. Cyber Essentials basic self-assessment if you do not already hold it, followed by the Plus assessment inside the 90-day window.
  3. Penetration testing scoped to what matters most, usually the external estate and the main application first.
  4. Overlap flagged. Findings from the penetration test that would also fail Plus are identified so you fix them once.
  5. Separate outputs. The Plus certificate for your customers; the penetration test report, with retest, for your team.

The Cyber Essentials Plus page sets out the assessment and prices; the penetration testing page describes each type of test; the sample report shows what you receive from a test.

Frequently asked questions

Does a penetration test count as Cyber Essentials Plus?

No. Cyber Essentials Plus is a specific assessment run by a licensed certification body against the IASME standard. A penetration test, however thorough, does not produce a Cyber Essentials Plus certificate. We can do both.

Does passing Cyber Essentials Plus mean we do not need a penetration test?

No. Plus checks five baseline controls on sampled devices. It does not test applications, cloud, internal networks or people. Many organisations that pass Plus comfortably have serious findings in their main application.

Can the same consultant do both?

Yes. Our Cyber Essentials Plus assessors are penetration testers, which is why we can scope both in one call.

Which is cheaper?

Cyber Essentials Plus is priced by organisation size and starts at £1,000 plus VAT on top of the basic certificate. A penetration test is priced by scope. For a small organisation Plus is usually the smaller number; it is also the narrower assessment.

How do we get started?

Contact us with what you need certified and what you want tested. An active tester and an assessor will scope both in one conversation.

Ready to scope a test?

Book a call. Our sales team will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.

Book a callRead the FAQ