Every few weeks a UK founder forwards an enterprise security questionnaire that says “please attach your Cyber Essentials certificate and your latest pentest.” Those are two different artefacts. Treating them as synonyms is how you fail the questionnaire twice.
What Cyber Essentials actually is
Cyber Essentials is a UK government-backed baseline. You assert five control themes (firewalls, secure configuration, access control, malware protection, patching) and, for CE+, someone technically verifies a sample. It is valuable. It is also a known questionnaire. It does not try to log in as another tenant and download their invoices.
What a penetration test is
A pentest is an authorised attempt to break the thing your customers use. The output is a list of proven, replayable failures — plus a re-test when you fix them. NCSC is explicit that CE is not a substitute for a risk-based test of your applications.
When CE+ is enough
If a buyer only asked for CE+, send CE+. Do not invent a pentest PDF to look busy. If they asked for both, they mean both.
When the pentest is the gap
Multi-tenant SaaS, payment flows, APIs, mobile apps, and anything an enterprise customer will put on their own pentester’s desk. CE will not find IDOR. That is the finding that delays a UK deal.
How we write the report so both sit in the same pack
We do not pretend the pentest “covers Cyber Essentials.” We map application findings to the control language the questionnaire used, and we leave CE to your CE body. Honesty reads as competence. Logo soup does not.
Need this as an engagement, not an article?
UK hours. GBP quote. Written CMA 1990 authorisation.
Request a pentest