Cyber Essentials is unusual in security for having a published price. It is also unusual in how little that published price tells you about what certification will actually cost your business.
In short: the certification fee runs from £320 + VAT for an organisation of nine people or fewer to £600 + VAT for one of 250 or more, and it is fixed and published by IASME. Cyber Essentials Plus has no list price because it is quoted against the size and complexity of your network. For most businesses the fee is the smallest line in the budget: remediation, licences and internal time cost more, and the certificate expires after twelve months, so all of it recurs.
What the certification fee covers
Cyber Essentials is a UK government backed scheme, run by the IASME Consortium on behalf of the NCSC. The base level is a self-assessment questionnaire, verified by an accredited certification body, covering five control themes: firewalls, secure configuration, security update management, user access control and malware protection.
The fee you pay buys that assessment. An assessor marks your answers, gives you feedback on anything non-compliant, and issues the certificate if you pass. Nobody logs into your systems at this level, and no vulnerability scan is run. What you are buying is independent marking of answers a director has signed a declaration to say are true.
The 2026 fee bands
Pricing is tiered using the UK government's definition of organisation size, which is based on employee numbers rather than turnover or how complicated your estate is.
| Organisation size | Employees | Certification fee |
|---|---|---|
| Micro | 0 to 9 | £320 + VAT |
| Small | 10 to 49 | £440 + VAT |
| Medium | 50 to 249 | £500 + VAT |
| Large | 250 or more | £600 + VAT |
Figures published in IASME's Cyber Essentials FAQ. Two things follow from that table. A ten-person business pays more than a nine-person one, and certificates expire after twelve months, so this is an annual cost rather than a one-off.
What does Cyber Essentials Plus cost?
There is no published figure, and the reason is worth understanding rather than treating as evasiveness. Cyber Essentials Plus begins with the same verified self-assessment and then adds a technical audit of the systems in scope.
IASME describes that audit as an internal and external vulnerability scan focused on a representative set of user devices, all internet gateways, and all servers with services accessible to unauthenticated internet users. The assessor tests a random sample, typically around 10 per cent, then decides whether further testing is needed.
That work is priced against your network, not your headcount. The variables that move the quote are:
- How many devices are in scope, and how many distinct operating systems they run, since each needs representation in the sample
- How many sites and internet gateways there are
- Whether the audit runs remotely or in person
- How much server estate is reachable from the internet
- Whether a retest is likely, which depends on how confident you are in your patching
IASME's route to a price is to submit your details and receive quotes from three certification bodies. Expect a multiple of the base fee rather than a small uplift, and expect device count to matter more than staff count. Our guide to Cyber Essentials versus Cyber Essentials Plus covers which one your contracts actually require.
"The certificate fee is the only part of Cyber Essentials with a price list. Everything that determines whether you pass is quoted, borrowed from another budget, or absorbed by your own team."
One timing rule that saves money
If you achieve the verified self-assessment less than three months before certifying to Cyber Essentials Plus, you do not have to repeat the self-assessment stage. Leave a longer gap and you are redoing work you have already paid for. Plan the two as one sequence.
The costs that are not on the invoice
This is where budgets go wrong. The assessment fee is knowable in advance. The work needed to answer the questions honestly is not, until somebody looks.
Remediation
Every question you cannot answer yes to is a piece of work. Common examples are default credentials still in place on a router, local administrator rights handed out years ago, a firewall rule nobody can explain, or a laptop that has never been enrolled in anything. None of these are expensive individually. Collectively, on an estate that has never been audited, they are a project.
Licences you assumed you had
Multi-factor authentication is now a mandatory requirement for all cloud services where it is available, and IASME confirms that failing to implement it is an automatic fail, whether MFA is free, included or a paid option. Two further security update questions became auto-fail questions at the same time: high-risk or critical updates for operating systems and firewalls, and for applications, must be installed within 14 days of release.
In practice that often means buying or upgrading something: a licence tier that includes conditional access, a device management platform that can prove patch status across every machine, or endpoint protection that covers the whole scope rather than most of it. Those are real costs and they are annual.
Kit that cannot be brought back into support
Unsupported software is the classic automatic fail. If a machine cannot run a supported operating system, the options are replacement, a licensed extended support route where one exists, or properly segmenting it out of scope, which is itself work. From April 2026 the scheme is explicit that the assessment is a point in time and that point is the date the certificate is issued, so everything in scope has to be supported on that date.
Your own people's time
Somebody has to produce an accurate device inventory, chase answers out of whoever holds them, and get a board member to sign the declaration. On a first certification, that is usually the single largest cost and the one nobody records. Our Cyber Essentials checklist exists to shorten it.
What does a provider charge to get you through it?
Two commercial models are common, and they answer different problems.
- Certification only. A certification body takes the fee, marks your answers and issues the certificate. You do the remediation. Cheapest, and appropriate if your controls are already in good shape.
- Guided certification. A provider assesses you against the five themes first, closes the gaps, prepares the answers with you and stands beside you through the assessment. Priced against the gap, not the certificate, so it is quoted after a look at the estate.
Systech is an accredited Cyber Essentials provider and holds the certification itself. We guide clients through both levels as part of our security services, and compliance support of this kind sits inside a scoped engagement rather than a rate card. What we do publish is the managed IT price it usually sits alongside, which starts at £40 per user per month and is set out in full on our pricing page.
How long does certification take?
Faster than most people expect, once the underlying work is done.
| Stage | Typical duration |
|---|---|
| Completing a prepared self-assessment | About an hour |
| Assessor marking and result | Around 3 days |
| Correcting simple issues after a fail | 2 working days, no extra charge |
| Window to submit after applying | 6 months before the account closes |
| Certificate validity | 12 months |
Timings from IASME's FAQ. Note the failure rule: you get one short window to fix simple issues and resubmit free, and a second failure means reapplying and paying the fee again. That is the strongest argument for doing the remediation before you apply rather than discovering it in the marking.
When is it worth paying for?
When a contract requires it
Cyber Essentials is required in a large number of central government contracts and an increasing number of local government ones, and IASME notes it is required for Ministry of Defence suppliers across the supply chain handling defence information. If a tender names it, the cost question is settled.
When an insurer is asking
UK-domiciled organisations with a turnover under £20m that certify their whole organisation and opt in are entitled to cyber liability insurance with a £25,000 total limit of indemnity, underwritten by AIG, including a 24-hour incident helpline. Read the exclusions before treating it as cover, but for a small business it is a genuine benefit attached to a fee you were paying anyway.
When you sell to schools or the public sector
The DfE's cyber security standard for schools and colleges asks for the same fundamentals: MFA for staff accounts with cloud or remote access, vulnerability fixes inside 14 days, and a backup plan reviewed every year. Our guide to the DfE standards sets that alongside the other eleven, and suppliers into that market are increasingly asked to evidence the equivalent themselves.
When your customers' questionnaires ask
Supply chain security questionnaires cover the same ground as the five control themes. Certifying gives you one answer to a question you will otherwise write a paragraph about several times a year.
The honest summary
For a business of 20 people with a tidy Microsoft 365 estate, the certificate is a few hundred pounds and a fortnight of light work. For a business of the same size with two unsupported servers, patchy MFA and no device inventory, the certificate is still a few hundred pounds and the rest is a project.
Both are worth doing. Only one of them is worth budgeting as if the fee were the cost. If you want to know which one you are, our security team will tell you before you apply rather than after an assessor does.
Frequently asked
How much does Cyber Essentials cost in 2026?
The IASME certification fee is published and tiered by headcount: £320 + VAT for a micro organisation of 0 to 9 employees, £440 + VAT for a small organisation of 10 to 49, £500 + VAT for a medium organisation of 50 to 249, and £600 + VAT for a large organisation of 250 or more. That fee buys the assessment itself. It does not buy the remediation work, the licences or the internal time needed to get to a passing set of answers, which is usually the larger number. Certificates expire after twelve months, so the fee recurs annually.
Why is there no published price for Cyber Essentials Plus?
Because the audit is priced against your network rather than your headcount. Cyber Essentials Plus adds an internal and external vulnerability scan and hands-on testing of a random sample of user devices, all internet gateways and all servers reachable by unauthenticated internet users. IASME says the assessor typically tests around 10 per cent of those systems and then decides whether further testing is needed. A business with one office and one operating system is a much smaller job than the same headcount spread across four sites, three platforms and a hybrid server estate, so certification bodies quote individually. IASME will send you quotes from three of them if you submit your details.
What are the hidden costs of Cyber Essentials?
Four things catch businesses out. Remediation, because anything you cannot honestly answer yes to has to be fixed before you submit. Licensing, where multi-factor authentication, mobile device management or endpoint protection has to be bought or upgraded to cover the whole scope. Hardware, because unsupported software and operating systems fail the assessment outright and old kit often cannot be brought back into support. And internal time, since somebody has to gather the device inventory, chase the answers and sign the board declaration. None of those appear on the certification invoice.
How long does Cyber Essentials take?
The assessment itself is quick. IASME says a prepared organisation might complete the self-assessment in about an hour, and that most assessors aim to return results within three days. If you fail, you get two working days to correct simple issues and resubmit at no extra cost, after which a further failure means reapplying and paying again. You have six months from application to submit before the account closes. The variable is not the paperwork, it is the remediation: a business that already runs MFA everywhere and patches inside fourteen days can be certified in weeks, while one that does not should plan for a month or two of work first.
Is Cyber Essentials worth the money?
It is worth it when something depends on it, and increasingly something does. Cyber Essentials is required in a large number of central government contracts, in a growing number of local government ones, and for Ministry of Defence suppliers handling defence information. UK-domiciled organisations with turnover under £20m that certify their whole organisation and opt in are entitled to cyber liability insurance with a £25,000 limit of indemnity. Beyond the badge, the five control themes are the controls an insurer, an auditor or a customer questionnaire will ask about anyway, so the work has value even where the certificate is not demanded.



