Skip to main content
    NixInfinity-AI
    Comparison

    Cyber Essentials Plus vs Penetration Testing: Do You Need Both?

    Published 17 July 2026

    What CE Plus actually tests

    • Authenticated and unauthenticated vulnerability scanning of a sample of devices
    • Verification of MFA, anti-malware, account separation and patching
    • Email and browser handling of common malicious content
    • Sample-size scaling with organisation size (see our CE Plus cost guide)

    What a pen test actually tests

    • External attack-surface enumeration and exploitation
    • Web app vulnerabilities (OWASP Top 10, business-logic flaws)
    • API authorisation and authentication weaknesses
    • Internal network lateral movement and privilege escalation
    • Wireless, social engineering and physical (if in scope)

    Cost and time

    CE Plus typically costs £1,400–£2,000 + VAT for a small UK firm and runs over 1–2 weeks. A focused external pen test starts around £3,500 + VAT; a serious web/API engagement is £8k–£20k. Pen tests take 5–15 working days plus reporting.

    Which one tenders ask for

    • Most UK public sector tenders ask for CE or CE+ only
    • NHS DSPT often references CE or CE+ depending on the data type
    • Financial services counterparties commonly ask for both CE+ and an annual pen test
    • SaaS due diligence questionnaires (Vanta, Drata, SecurityScorecard-driven) almost always ask "when was your last pen test?"

    The order to do them

    1. CE first – cheap, fast, fixes the obvious technical gaps
    2. CE Plus next – validates CE with hands-on scanning
    3. Pen test last – with the basics fixed, your money buys real findings, not a list of missing patches

    Pen-testing before CE is a common waste of budget. Half the report ends up being "patch your stuff" which CE/CE+ would have caught for a fraction of the cost.

    What CE Plus does not catch

    • Business-logic flaws in your own application
    • API authorisation bugs (BOLA, BFLA, mass assignment)
    • Insider threat scenarios
    • Social engineering / phishing-resistant culture
    • Misconfigurations specific to your cloud architecture (IAM trust paths, S3 ACLs)

    How they sit together in a security programme

    For most SMEs: CE annually, CE Plus annually, pen test on each major release of any customer-facing application, and a lighter external attack-surface scan continuously. For buyer-facing assurance, pair the CE/CE+ certificate with the executive summary from your most recent pen test.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides