Short answer: no. Cyber Essentials does not require a penetration test, and neither does Cyber Essentials Plus.
This gets confused often enough to be worth setting out properly, because organisations regularly buy the wrong thing — either paying for a penetration test they did not need for certification, or assuming certification means they have been tested when nobody has actually tried to break in.
Cyber Essentials is a UK government-backed scheme, overseen by the NCSC and administered through IASME. It certifies that you have five basic technical controls in place:
Basic Cyber Essentials is a self-assessment questionnaire. You answer it, someone at a certification body reviews it, and you are certified or you are not.
Cyber Essentials Plus covers exactly the same five controls. The difference is verification: rather than taking your answers on trust, an assessor checks technically that the controls are working. That typically involves a vulnerability scan of your internet-facing systems and hands-on checks against a sample of user devices.
That vulnerability scan is why people assume Plus involves a penetration test. It does not. A scan checks whether known issues are present against a defined list. A penetration test is a human attempting to exploit and chain what they find to establish what an attacker could actually achieve. Different activity, different depth, different output.
Cyber Essentials tells you a floor exists. It says nothing about what someone determined would find above it.
Testing is the right purchase when:
The sensible sequence for most small and mid-sized organisations is Cyber Essentials first, then testing.
Certification forces you to fix the unglamorous things — unsupported operating systems, accounts that should have been disabled, patches that stopped applying eighteen months ago. Those are the same findings that would otherwise fill the first half of a penetration test report. Fix them first and your test spends its days on questions you cannot answer any other way, rather than re-reporting what a questionnaire would have caught.
Put differently: Cyber Essentials clears the cheap findings so testing can look for the expensive ones.
The controls are not difficult, but the failures are consistent:
The last two are where a cloud configuration review earns its cost even if certification is your only immediate goal — misconfigured identity and access in Microsoft 365 is the single most common thing we find in cloud environments, and it is squarely in scope.
To be clear about what we do and do not do: we are not a certification body, so we cannot certify you. What we can do is find and help you fix the things that would otherwise fail you, before you sit the assessment.
In practice that means managed vulnerability scanning to surface unsupported software and missing patches across your estate, and a cloud review if a meaningful share of what you run is Microsoft 365 or Azure. Both map closely to what Plus assessors verify.
If you are working toward certification and want to know where you currently stand, tell us what you are running. And if what you actually need is a penetration test rather than certification support, we will say so.