Cyber Essentials Plus vs Penetration Testing: Do You Need Both?
Published 17 July 2026
What CE Plus actually tests
- Authenticated and unauthenticated vulnerability scanning of a sample of devices
- Verification of MFA, anti-malware, account separation and patching
- Email and browser handling of common malicious content
- Sample-size scaling with organisation size (see our CE Plus cost guide)
What a pen test actually tests
- External attack-surface enumeration and exploitation
- Web app vulnerabilities (OWASP Top 10, business-logic flaws)
- API authorisation and authentication weaknesses
- Internal network lateral movement and privilege escalation
- Wireless, social engineering and physical (if in scope)
Cost and time
CE Plus typically costs £1,400–£2,000 + VAT for a small UK firm and runs over 1–2 weeks. A focused external pen test starts around £3,500 + VAT; a serious web/API engagement is £8k–£20k. Pen tests take 5–15 working days plus reporting.
Which one tenders ask for
- Most UK public sector tenders ask for CE or CE+ only
- NHS DSPT often references CE or CE+ depending on the data type
- Financial services counterparties commonly ask for both CE+ and an annual pen test
- SaaS due diligence questionnaires (Vanta, Drata, SecurityScorecard-driven) almost always ask "when was your last pen test?"
The order to do them
- CE first – cheap, fast, fixes the obvious technical gaps
- CE Plus next – validates CE with hands-on scanning
- Pen test last – with the basics fixed, your money buys real findings, not a list of missing patches
Pen-testing before CE is a common waste of budget. Half the report ends up being "patch your stuff" which CE/CE+ would have caught for a fraction of the cost.
What CE Plus does not catch
- Business-logic flaws in your own application
- API authorisation bugs (BOLA, BFLA, mass assignment)
- Insider threat scenarios
- Social engineering / phishing-resistant culture
- Misconfigurations specific to your cloud architecture (IAM trust paths, S3 ACLs)
How they sit together in a security programme
For most SMEs: CE annually, CE Plus annually, pen test on each major release of any customer-facing application, and a lighter external attack-surface scan continuously. For buyer-facing assurance, pair the CE/CE+ certificate with the executive summary from your most recent pen test.
