Skip to content
DreamSolve

How much does Cyber Essentials cost?

Tanmoy Hossain

Last updated

The short answer

Cyber Essentials costs £320 if you have up to 9 employees, £440 for 10 to 49, £500 for 50 to 249 and £600 for 250 or more, all plus VAT. Cyber Essentials Plus adds an independent technical audit and is quoted individually by a certification body. Either way, the fee pays for the assessment, not for the work of getting your systems ready to pass.

Source: IASME, Cyber Essentials pricing (opens in a new tab), correct as of 5 October 2026.

What Cyber Essentials is, and who asks for it

Cyber Essentials is the UK government's recommended minimum standard of cyber security for organisations of all sizes. The NCSC (opens in a new tab) owns the scheme and IASME (opens in a new tab) delivers it, licensing the certification bodies whose assessors mark your answers. It protects against the most common internet-based attacks: the everyday kind that walk through an unpatched laptop, a default password or an admin account without a second factor.

The requirements are grouped under five technical controls:

  • Firewalls: control what can reach your devices and services from the internet.
  • Secure configuration: remove default passwords, unused accounts and software you do not need.
  • Security update management: keep software supported and patched.
  • User access control: give people only the access they need, and protect it with multi-factor authentication.
  • Malware protection: stop malicious software from running.
Source: NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (opens in a new tab), correct as of 5 October 2026.

Who asks for it? Central government made it mandatory for contracts advertised after 1 October 2014 that involve handling personal information and providing certain ICT products and services (Procurement Policy Note 09/14 (opens in a new tab)). The Ministry of Defence requires it across the parts of its supply chain that handle defence information (IASME FAQ (opens in a new tab)). Beyond government, the NCSC notes that a growing number of organisations ask suppliers to be certified before they can bid. In practice it often arrives as one line in a tender or a security questionnaire: do you hold Cyber Essentials?

What does the certificate tell a buyer? That you had the basics in place when you were assessed, and that a director signed to say the answers are true. What it does not tell them is how you build your product. The bespoke parts of your web application are out of scope, and backups are recommended rather than required. It says nothing about incident response, your own suppliers or how you handle their data day to day. Those are the questions that come next.

Cyber Essentials or Cyber Essentials Plus?

Both levels check exactly the same five controls. The difference is how much the assessor checks for themselves.

ComparedCyber EssentialsCyber Essentials Plus
How it is checkedA self-assessment questionnaire, signed by a board member and marked by an assessorThe same questionnaire, plus a technical audit by an assessor
TestingNo vulnerability scanInternal and external vulnerability scans, and hands-on checks of a sample of user devices, every internet gateway and every server reachable from the internet
Price£320 to £600 plus VAT, set by headcountQuoted individually, by size and complexity of network
Valid for12 months12 months
Source: IASME, Cyber Essentials FAQ (opens in a new tab), correct as of 5 October 2026.

For Plus, the assessor typically tests a random sample of around 10 per cent of the systems in scope, then decides whether more testing is needed. Audits can run remotely or in person.

My rule of thumb: start with Cyber Essentials. You need it for Plus anyway, and doing it properly is most of the work. Move to Plus when a contract or a buyer names it, or when customers trust you with the kind of data where they will want proof rather than a declaration. Plan the two together. If you certify to Plus within three months of the basic certificate, you do not answer the questionnaire twice.

What the cost does not include

The fee pays for an assessor to mark your answers. It does not pay for the work of making those answers true, and that is where the real cost sits: your time, and sometimes some kit.

The work usually looks like this:

  • Replacing or retiring unsupported devices and software. Anything in scope that no longer gets security updates from its vendor is an automatic fail.
  • Turning on multi-factor authentication for every cloud service. Under the current requirements, authentication to cloud services must always use it. That means your email, file storage, accounting, CRM and anything else that holds company data.
  • Separating admin accounts. Administrative accounts should be used for admin only, not for email or browsing.
  • Getting updates on a schedule. Automatic updates wherever possible, and high and critical fixes applied within 14 days.
  • Writing down your scope. Which devices, networks and cloud services are covered, agreed with the certification body before the assessment.

If your laptops are recent and your tools are cloud services, much of the gap is configuration rather than spending: switching settings on, not buying kit. Older hardware, a mix of personal devices or nobody technical in the team is when outside help earns its fee. IASME offers free help first: the question set to preview (opens in a new tab), a Readiness Tool and 30 minutes with a Cyber Advisor.

One thing the fee does include: if you are UK based, turn over less than £20 million and certify your whole organisation, you are entitled to cyber liability insurance with a £25,000 limit and a 24-hour incident helpline (IASME (opens in a new tab), correct as of 5 October 2026).

Then there is renewal. The certificate lasts 12 months and you answer every question again each year, against whichever version of the requirements is current. Keep a copy of this year's answers. It turns next year's renewal into a check, not a project.

Common reasons small firms fail

You need to be compliant on nearly every question to pass. These are the requirements that most often need real work, all from the current NCSC requirements (opens in a new tab) (version 3.3, in force from 27 April 2026; correct as of 5 October 2026):

  1. Unsupported software in scope. An old laptop on an operating system that no longer gets updates, or an old version of an app nobody uninstalled. This is an automatic fail.
  2. Slow patching. Updates that fix vulnerabilities the vendor calls critical or high risk, or that score 7 or above under CVSS version 3, must be installed within 14 days of release. The same applies when the vendor does not say how serious the fix is.
  3. Cloud services without multi-factor authentication. Every cloud service needs it, so one shared login or one forgotten tool is a gap.
  4. Everyday work on admin accounts. Browsing and email belong on a standard account.
  5. A scope with holes. Cloud services cannot be excluded, a scope without end-user devices is not acceptable, and home or personal devices used for work are in scope by default.
  6. Leftovers. Default passwords, unused accounts and accounts belonging to people who have left.

Check yourself before you pay. Download the free question set and answer it honestly. List every device and every cloud service the business uses, then check each one: is it still supported, are updates automatic, is multi-factor authentication on, who has admin rights? A director signs the declaration, so do not tick anything you would not defend. If you do fail, you get two working days to fix simple issues and resubmit for free.

What enterprise buyers ask for next

Cyber Essentials is often the first question a bigger buyer asks, rarely the last. Once you have it, the usual follow-ups are a supplier security questionnaire, sometimes ISO 27001, data protection terms in the contract, and commitments on uptime and support.

The mistake is treating each one as a separate project. They overlap heavily. The access controls, update process and device list you put in place for Cyber Essentials are the same evidence a questionnaire asks for, and the same controls an ISO 27001 auditor will look at. Do the work once, write it down once, and map it to each request as it arrives.

It is the approach I took as CTO of a small SaaS company that held ISO 27001:2022 with zero nonconformances across three audit cycles. If bigger customers are starting to ask, here is how I help small companies get enterprise-ready.

Questions

  • Approximately how much does the Cyber Essentials certificate cost?

    IASME, the NCSC's delivery partner, prices the assessment by headcount: £320 plus VAT for 0 to 9 employees, £440 plus VAT for 10 to 49, £500 plus VAT for 50 to 249 and £600 plus VAT for 250 or more (IASME (opens in a new tab), correct as of 5 October 2026). That is the assessment fee only. The work of meeting the requirements is a separate cost, mostly your own time.

  • How much does Cyber Essentials Plus cost?

    Cyber Essentials Plus is quoted individually by a certification body, because the technical audit takes more expert time and depends on the size and complexity of your network. IASME's quote form sends your details to three certification bodies (IASME FAQ (opens in a new tab), correct as of 5 October 2026).

  • Do I need Cyber Essentials or Cyber Essentials Plus?

    Start with Cyber Essentials: it is a prerequisite for Plus, and doing it properly is most of the work. Move to Plus when a contract or a buyer names it, or when customers trust you with data where they will want proof rather than a signed declaration. If you certify to Plus within three months of the basic certificate, you do not repeat the questionnaire.

  • How long does a Cyber Essentials certificate last?

    Twelve months. Both Cyber Essentials and Cyber Essentials Plus certificates expire after a year, and you answer the full question set again each time you renew (IASME FAQ (opens in a new tab), correct as of 5 October 2026).

  • What happens if I fail?

    The assessor tells you which answers were not compliant. You then have two working days to fix simple issues and resubmit at no extra charge. After that you reapply and pay again. Unsupported software inside your scope is an automatic fail (IASME FAQ (opens in a new tab), correct as of 5 October 2026).

How DreamSolve helps

Cyber Essentials is often the first certificate a bigger customer asks for, and rarely the last. Enterprise Readiness gets a small company ready for it, and for what comes next: supplier questionnaires, ISO 27001 and data protection. DreamSolve prepares you for certification; it is not a certification body.

Book an intro call (opens in a new tab)A free 30 minute fit check.
Tanmoy Hossain

Written by

Tanmoy Hossain

Fractional CTO. About seven years building and leading technology at a cybersecurity SaaS company, from systems developer to CTO.

More about Tanmoy

Not sure which door you're at?

That's what the first call is for. It's 30 minutes and free: we work out whether I can help, and which door you're at.