Cyber Essentials cost is one of the few things about the scheme that is genuinely transparent: the assessment fee is published by IASME, fixed by organisation size, and identical whichever certification body you go through. What is not published — and what catches out most budgets — is the cost of Cyber Essentials Plus, the cost of renewal, and the remediation work you have to do before anyone will certify you.
This is the complete picture, with the figures IASME actually publishes rather than the ranges that circulate in blog posts.
Cyber Essentials certification cost: the published fees
The Cyber Essentials assessment fee is set by IASME, the NCSC's official Cyber Essentials delivery partner, and banded by organisation size using the UK government's employee-count definitions.
| Organisation size | Employees | Assessment fee |
|---|---|---|
| Micro | 0–9 | £320 + VAT |
| Small | 10–49 | £440 + VAT |
| Medium | 50–249 | £500 + VAT |
| Large | 250 or more | £600 + VAT |
Two things follow from this that are worth knowing before you shop around.
The fee is the same wherever you buy it. Every certification body submits your assessment through the same IASME platform, so the assessment fee does not vary. What varies is whatever support the certification body wraps around it — pre-assessment gap analysis, help completing the question set, remediation advice. If one quote is materially higher than another, you are paying for that service, not for a better certificate.
The band is based on the whole organisation, not on the part of it you are certifying. You can scope the assessment to a sub-network, but a 400-person company certifying one business unit still sits in the large band.
Cyber Essentials Plus cost
Cyber Essentials Plus has no published price, and any article quoting a single figure for it is guessing.
The reason is structural. The base certificate is a verified self-assessment — an assessor marks your answers, which takes a predictable amount of time. Plus adds a hands-on technical audit: internal and external vulnerability scans, plus testing of a sample of your actual devices, gateways and internet-facing servers. That consumes assessor time which scales with how large and how complicated your network is, so it is quoted per organisation.
IASME's own route is to submit your details once and receive quotes from three different certification bodies. Audits can be run remotely or in person.
What you can budget for with confidence:
- The base assessment fee still applies — Plus includes the Cyber Essentials question set, it does not replace it.
- Cost scales with device count, number of internet-facing services, and the number of separate locations or networks in scope, so reducing scope honestly is the main lever you have.
- If you achieved the verified self-assessment less than three months before certifying to Plus, you do not repeat the questionnaire stage. Leave it longer and you do that work — and pay for it — twice.
Cyber Essentials renewal cost
Certificates last 12 months. Both Cyber Essentials and Cyber Essentials Plus expire after a year, and IASME removes organisations from its certified list if they have not certified within the past year.
Renewal is not a discounted administrative step. It is a fresh assessment at the same published band, which means the renewal cost is the same as the initial certification cost for your size of organisation. IASME is explicit that you re-enter all the information each time, deliberately: recertification is intended to function as an annual review of your security rather than a rubber stamp.
Two practical consequences:
- Keep a copy of your submitted answers. IASME specifically advises this, because you will be answering the same question set again next year and the questions themselves may have changed in the meantime.
- Budget renewal as a recurring annual line, not a one-off. Over three years a medium-sized organisation is committing £1,500 + VAT in assessment fees alone, before Plus.
The costs that are not on the price list
The assessment fee is usually the smaller half of what Cyber Essentials actually costs. The rest is what you have to do to pass it.
Remediation. The five controls are a floor, but they are a real floor. If you do not currently enforce multi-factor authentication on cloud services, separate administrative accounts from everyday ones, or patch high-risk vulnerabilities within 14 days, the work to close those gaps is the genuine cost of certification. For some organisations that is a policy change; for others it is licences, tooling or a device management platform.
Unsupported software. This one deserves separating out, because it is an automatic fail rather than a finding. IASME's position is unambiguous: any company using unsupported software within the scope of the assessment will not achieve certification. An end-of-life operating system on one in-scope machine is enough, and the fix is replacement or upgrade, not configuration. Inventory before you apply, not after.
Re-assessment fees. If you fail, you get two working days to review the assessor's feedback, correct simple issues and resubmit, and the assessor re-marks at no extra charge. Miss that window and you reapply and pay the fee again. Two days is enough for a misconfiguration and nowhere near enough for a migration.
The six-month clock. You have six months from application to complete and submit. After that your account may be closed, and you would have to apply and pay again — with no refund.
Internal time. If you prepare your answers in advance the self-assessment can take about an hour to fill in. Getting to the point where those answers are true is the part that takes weeks.
What the fee actually includes
For the assessment fee you get the assessment itself, the certificate, and listing on IASME's certified organisations register. Most UK-domiciled organisations with turnover under £20 million also receive cyber liability insurance as part of the basic certification — check current terms with IASME, since eligibility conditions apply.
You should also expect a board-level commitment: one of your board members has to sign a declaration confirming the answers you submitted are true. That is not an administrative formality — it is why the self-assessment carries weight despite nobody scanning your network at the basic level.
How to keep the cost down without gaming it
- Scope honestly, but scope deliberately. A defined, coherent sub-network is a legitimate scope. A scope drawn to exclude the awkward estate tends to be undone by the external scan at Plus.
- Download the question set first. It is free, and reading it before you pay turns unpleasant surprises into planned work.
- Fix the automatic-fail items before applying. Unsupported software and missing MFA are the two that most reliably cost people a second fee.
- Plan Cyber Essentials and Plus as one project if you need both, so you stay inside the three-month window and complete the question set once.
- Diarise renewal at ten months, not twelve. Certification lapses on the date, and a lapsed certificate is a procurement problem the week you discover it.
Is it worth it?
For most organisations the question answers itself, because a customer or a public sector contract has already required it. Where it is discretionary, the honest case is that Cyber Essentials is cheap relative to what it forces you to tidy up, and the tidying is the value. The certificate is the receipt.
What it is not is evidence about your suppliers. Your certificate describes your estate on one day; theirs describes theirs, in whatever scope they chose, on the day they were audited. If you are being asked for Cyber Essentials because your customers are managing their supply chain risk, it is worth understanding what a supplier's certificate does and does not prove — and applying the same scepticism to the certificates your own suppliers send you.
Fees in this article are IASME's published assessment fees, verified on 23 August 2026. Cyber Essentials Plus is quoted individually and has no published price. Check iasme.co.uk before relying on any figure — the bands are reviewed periodically.
