Do You Need a Penetration Test for Cyber Essentials?

  • September 10, 2026

Short answer: no. Cyber Essentials does not require a penetration test, and neither does Cyber Essentials Plus.

This gets confused often enough to be worth setting out properly, because organisations regularly buy the wrong thing — either paying for a penetration test they did not need for certification, or assuming certification means they have been tested when nobody has actually tried to break in.

What Cyber Essentials actually is

Cyber Essentials is a UK government-backed scheme, overseen by the NCSC and administered through IASME. It certifies that you have five basic technical controls in place:

  1. Firewalls — boundary protection between your systems and the internet
  2. Secure configuration — devices and software set up to reduce unnecessary exposure
  3. User access control — people have the access they need and no more, with administrator accounts controlled
  4. Malware protection — in place and functioning
  5. Security update management — patches applied, unsupported software removed

Basic Cyber Essentials is a self-assessment questionnaire. You answer it, someone at a certification body reviews it, and you are certified or you are not.

What Cyber Essentials Plus adds

Cyber Essentials Plus covers exactly the same five controls. The difference is verification: rather than taking your answers on trust, an assessor checks technically that the controls are working. That typically involves a vulnerability scan of your internet-facing systems and hands-on checks against a sample of user devices.

That vulnerability scan is why people assume Plus involves a penetration test. It does not. A scan checks whether known issues are present against a defined list. A penetration test is a human attempting to exploit and chain what they find to establish what an attacker could actually achieve. Different activity, different depth, different output.

So when is a penetration test the right purchase?

Cyber Essentials tells you a floor exists. It says nothing about what someone determined would find above it.

Testing is the right purchase when:

  • A customer's security questionnaire asks for it directly. Enterprise procurement frequently asks for a recent penetration test report specifically, and a Cyber Essentials certificate will not satisfy that question.
  • You handle data whose compromise would be serious — payment details, health records, anything where a breach means a regulator and not just an awkward week.
  • You build or operate your own application. Cyber Essentials does not assess your code. If you have written a customer-facing web application, none of the five controls covers whether a user can reach another user's data.
  • You want to know what a phishing success would cost. Cyber Essentials does not model an attacker already inside your network.

Where they work well together

The sensible sequence for most small and mid-sized organisations is Cyber Essentials first, then testing.

Certification forces you to fix the unglamorous things — unsupported operating systems, accounts that should have been disabled, patches that stopped applying eighteen months ago. Those are the same findings that would otherwise fill the first half of a penetration test report. Fix them first and your test spends its days on questions you cannot answer any other way, rather than re-reporting what a questionnaire would have caught.

Put differently: Cyber Essentials clears the cheap findings so testing can look for the expensive ones.

Where organisations usually fail

The controls are not difficult, but the failures are consistent:

  • Unsupported software still running. An old Windows Server, an unpatched appliance, a business system nobody wants to touch because it still works.
  • Everyday accounts with administrator rights. Very common, and one of the fastest routes from a single phished user to a serious incident.
  • Patching that covers Windows and nothing else. Browsers, PDF readers, third-party agents and firmware all count.
  • Cloud treated as out of scope. Microsoft 365 and Azure fall within scope, and conditional access, multi-factor coverage and administrative roles all get looked at.
  • Devices nobody thought about. Personal laptops used for work, contractor machines, that one Mac in the design team.

The last two are where a cloud configuration review earns its cost even if certification is your only immediate goal — misconfigured identity and access in Microsoft 365 is the single most common thing we find in cloud environments, and it is squarely in scope.

Getting ready

To be clear about what we do and do not do: we are not a certification body, so we cannot certify you. What we can do is find and help you fix the things that would otherwise fail you, before you sit the assessment.

In practice that means managed vulnerability scanning to surface unsupported software and missing patches across your estate, and a cloud review if a meaningful share of what you run is Microsoft 365 or Azure. Both map closely to what Plus assessors verify.

If you are working toward certification and want to know where you currently stand, tell us what you are running. And if what you actually need is a penetration test rather than certification support, we will say so.

Blog Post

Related Articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.

Cyber Security Basics: Simple Ways to Stay Safe Online

March 4, 2026
In today’s digital world, cyber security is more important than ever. We use the internet for almost...

Cheap Penetration Testing: What You Actually Get for the Money

September 10, 2026
Searching for cheap penetration testing is not a red flag. Most organisations looking for affordable testing are not...

Internal vs External Penetration Testing: What's the Difference?

September 10, 2026
When you start looking at penetration testing, one of the first choices you face is internal or external. The terms...
Blog Post CTA

H2 Heading Module

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.