Cyber Essentials is one of the most cost-effective cybersecurity certifications available to UK businesses, but the headline IASME assessment fee rarely tells the whole story. Preparation time, technical remediation, optional consultancy support and the step up to Cyber Essentials Plus all influence what you will actually spend in your first year and at each annual renewal.
This guide breaks down the cost areas you can expect to encounter on the path to certification, compares Cyber Essentials against other security standards such as ISO 27001 and SOC 2, and shows how to minimise spend without compromising on certification quality. For current published fees, always check the official IASME website, and visit our Cyber Essentials hub for a wider overview of the scheme.
How much does Cyber Essentials cost?
The headline cost of Cyber Essentials is the assessment fee, which is set centrally by IASME, the body that runs the scheme on behalf of the NCSC. The fee varies according to the size of your organisation. Because IASME sets and periodically reviews this pricing, the only reliable source for current figures is the official IASME website — check there before you budget.
The assessment fee typically covers your self‑assessment submission and the certificate itself. Smaller UK-based organisations under a turnover threshold may also qualify for IASME-backed cyber liability insurance included with certification; confirm the current eligibility criteria and cover levels directly with IASME.
Headcount is determined by the scope you certify, not the entire group. If you are certifying a UK subsidiary of a larger international parent and the scope only includes UK employees, you pay based on the UK headcount. This is one of the most common ways UK businesses unintentionally overpay — defining the scope sensibly can reduce the fee you pay without affecting the certificate’s usefulness in tender responses.
The fee is paid directly to your chosen IASME Certification Body when you submit your self‑assessment. Some Certification Bodies add a small administration premium on top of the IASME fee, particularly when they bundle in pre‑assessment support, so it is worth comparing three or four quotes before booking.
How much does Cyber Essentials Plus cost?
Cyber Essentials Plus builds on the standard self‑assessment with an external technical audit, including authenticated vulnerability scans of your devices, a sample of user accounts and a review of your external footprint. Because the assessor must spend time physically (or remotely) testing your environment, it costs more than the basic self‑assessment.
Cyber Essentials Plus is priced separately by your chosen Certification Body rather than set centrally by IASME, and the fee is in addition to (not instead of) the underlying Cyber Essentials assessment fee. The main factors that drive the price are:
- Sample size — The number of devices and user accounts the assessor needs to test; larger estates take longer to audit.
- Environment complexity — Multiple operating systems, mobile fleets, remote workers and cloud platforms all add to the assessment effort.
- Number of sites — Organisations spread across several locations typically require a broader sample.
For an accurate figure, request quotes from a few Certification Bodies based on your specific scope. If you only need the basic certification because a tender requires it, the standard self‑assessment is enough. If your buyers, insurers or regulators specifically ask for Cyber Essentials Plus, or you sell into central government, defence or sensitive supply chains, the Plus uplift is normally non‑negotiable. Read our guide to Cyber Essentials Plus requirements to see exactly what the audit covers.
Free yourself from a mountain of spreadsheets
Embed, expand and scale your compliance, without the mess. IO gives you the resilience and confidence to grow securely.
What hidden costs should you budget for?
The IASME and Plus fees are only the visible portion of the iceberg. Most organisations spend at least as much again on the work needed to pass the assessment first time. Treating these costs as part of the project budget from day one avoids nasty surprises later.
Preparation time and internal resourcing
Even the simplest Cyber Essentials self‑assessment covers dozens of questions across the five control areas — firewalls, secure configuration, user access control, malware protection and security update management. A first‑time applicant typically spends between 20 and 60 person‑hours gathering evidence, configuring controls and completing the questionnaire, which represents a real internal time cost on top of the assessment fee.
Technical remediation
Most organisations discover at least one control they cannot evidence on day one. Common remediation costs include:
- Endpoint replacement — Devices running unsupported operating systems (older Windows versions, end‑of‑life macOS) must be retired or upgraded.
- MFA roll‑out — Multi‑factor authentication is mandatory for all cloud services and administrative accounts.
- Patch management tooling — Automated patching for operating systems, applications and firmware, with high and critical severity updates applied within 14 days.
- Endpoint protection — Anti‑malware on every applicable device, centrally managed where possible.
- Account hygiene — Removing dormant accounts, separating administrative and standard accounts and enforcing strong password policies.
Consultancy and managed support
Engaging a Cyber Essentials consultant or IT managed service provider adds a further cost that varies with the scope of support you need. This buys you a gap analysis, evidence templates, policy drafting and a sense check before submission. For organisations with no internal security resource, this is usually cheaper than failing the first submission and paying for a resit.
Annual renewal fees
Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months. Renewal is not discounted — you pay the full IASME assessment fee and (if applicable) the full Plus audit fee each year. Some Certification Bodies offer multi‑year packages with a small saving, but the underlying IASME fee is unchanged.
How should you budget for Cyber Essentials over time?
To get a realistic picture of cost, look at the total across a multi‑year cycle rather than just the year‑one outlay. Your budget should account for several components: the IASME assessment fee, the Cyber Essentials Plus audit fee if you need it, preparation and consultancy support, technical remediation and internal staff time.
Year one is almost always the most expensive, because it carries the bulk of the remediation and preparation effort. From the second year onwards, once your controls, evidence and processes are embedded, the ongoing cost usually falls to the assessment fee plus a much smaller preparation overhead. Organisations that already operate good IT hygiene, MFA and patching can reduce the year‑one outlay significantly. Read our guide on how long Cyber Essentials takes to see how preparation effort maps onto cost.
How does Cyber Essentials cost compare to ISO 27001 and SOC 2?
Cyber Essentials is deliberately positioned as the entry point to certified cybersecurity for UK businesses, and it sits at the lowest end of the certification cost spectrum.
| Standard | Relative Cost | Best Suited For |
|---|---|---|
| Cyber Essentials | Lowest — entry level | UK businesses bidding for government and supply chain contracts |
| Cyber Essentials Plus | Low to moderate | UK businesses where buyers require external audit assurance |
| ISO 27001 | Moderate to high | UK and international businesses needing globally recognised assurance |
| SOC 2 (Type II) | Highest | SaaS and technology businesses selling into the US market |
Cyber Essentials is substantially cheaper than ISO 27001 and dramatically cheaper than SOC 2 Type II. For many UK businesses, Cyber Essentials covers the most common procurement and insurance requirements at a fraction of the cost of the larger frameworks. If your customer base is largely UK based and your contracts specify Cyber Essentials or Cyber Essentials Plus, there is rarely a commercial reason to spend more. See our comparison of Cyber Essentials vs ISO 27001 for a deeper breakdown.
Manage all your compliance, all in one place
ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.
What is the return on investment for Cyber Essentials?
The fee is only one side of the equation. For most UK organisations the certificate pays for itself within the first year through several main channels.
Contract eligibility
Cyber Essentials is mandatory for many UK central government contracts that involve handling personal data or operational information. It is also increasingly required by local authorities, NHS suppliers, defence primes and large enterprises in their supplier onboarding processes. A single won tender can pay for several years of certification.
Cyber insurance premium discounts
UK cyber insurers routinely offer premium discounts to Cyber Essentials certified organisations, and many will simply not quote without it. Where eligible, the IASME-backed cyber liability insurance included with certification can itself be worth more than the certification fee for businesses that would otherwise need to purchase their own cover. Confirm current eligibility and cover levels with IASME.
Reduced breach probability
The UK Government’s Cyber Security Breaches Survey consistently shows that organisations with the basic technical controls in place experience fewer and less severe incidents. With the cost of a typical cyber incident for a UK SMB running well into the thousands of pounds, even a modest reduction in incident probability more than justifies the cost.
Faster sales cycles
Holding the certificate shortens supplier due diligence questionnaires significantly. Many buyers accept Cyber Essentials Plus as a substitute for completing their own multi‑page security questionnaire, accelerating procurement timelines. Our analysis of whether Cyber Essentials is worth it explores the ROI in more detail.
DIY vs consultant: which route saves the most money?
There is no single right answer to the DIY vs consultant question. The cheapest option on paper (DIY) often becomes the most expensive if a failed submission forces remediation work under time pressure. Use the table below to choose the route that matches your situation.
| Route | Relative Cost | Best For | Watch Out For |
|---|---|---|---|
| Pure DIY | No extra cost beyond internal time | Organisations with an experienced IT lead and good security hygiene already in place | Significant internal time investment; risk of failing first submission |
| Platform‑assisted | Low ongoing subscription | SMBs that want structure, templates and progress tracking without paying full consultancy rates | Choose a platform that maps directly to the IASME question set |
| Consultant‑led | Moderate, usually a one‑off fee | Organisations with little internal security expertise or tight deadlines | Make sure the consultant transfers knowledge so renewal cost falls in year two |
| Fully managed | Ongoing monthly cost | Micro and small organisations outsourcing IT and security to a managed service provider | Lock‑in to a specific MSP; renewal pricing can creep up |
For most UK small businesses, the platform‑assisted route delivers the best balance of cost and certainty. Read our guide for Cyber Essentials for small business for sector specific advice on choosing between the routes.
Why Choose ISMS.online for Cyber Essentials?
ISMS.online is built to make Cyber Essentials preparation faster, more predictable and a great deal less stressful than spreadsheets and shared drives.
- Mapped to the full IASME question set — Every Cyber Essentials control is pre‑mapped in the platform, so you assess against the standard without building your own checklist.
- Pre‑built policies and evidence templates — Acceptable use, patching, access control and incident response policies are ready to customise, cutting preparation time from weeks to days.
- Evidence vault with version control — Screenshots, configuration exports and signed‑off policies are stored against each control, ready to share with your assessor.
- Maturity dashboards — Track your readiness in real time and see exactly which questions you can already answer with full confidence.
- Multi‑framework reuse — If you later progress to ISO 27001 or SOC 2, the same evidence and policies map across, so ISMS.online helps you achieve those certifications faster too.
- Assured Service Provider partnerships — Connect directly to certified IASME assessors through the platform when you are ready to submit.
- Predictable subscription pricing — A single annual platform fee, no surprise consultancy bills, and full transparency on what you are paying for.
Related Cyber Essentials guides
Continue your Cyber Essentials journey with the other guides in this series:
- Cyber Essentials Requirements — The five control areas, scope decisions and what evidence assessors look for.
- Is Cyber Essentials Worth It? — An honest assessment of the benefits, drawbacks and who actually needs certification.
- Cyber Essentials Plus Requirements — The technical audit, vulnerability scans and what Plus delivers over the basic certification.
- Cyber Essentials Self Assessment — The SASQ workflow, scope, evidence and common pitfalls.
- How Long Does Cyber Essentials Take? — Typical UK timeline, fast-track options and what slows the process.
- Cyber Essentials Renewal — The 12-month cycle, control changes and how to prepare ahead of expiry.
- Cyber Essentials for Small Business — SMB-specific scope and the cost-benefit case.
- Cyber Essentials vs ISO 27001 — Scope, cost, time and recognition compared.
FAQs
How much does Cyber Essentials cost in the UK?
The Cyber Essentials assessment fee is set by IASME and depends on the size of your organisation, so what you pay is based on your certified headcount. IASME reviews its pricing from time to time, so check the official IASME website for the current fees. The assessment fee is the headline cost only — most UK businesses also incur preparation, remediation and (optionally) consultancy costs, so budget for more than the fee alone in year one.
How much is Cyber Essentials Plus?
Cyber Essentials Plus is priced separately by your chosen Certification Body rather than set centrally by IASME, and the cost depends on the size and complexity of your environment — principally the number of devices and user accounts sampled. It is charged in addition to the standard Cyber Essentials assessment fee, so budget for both. Request quotes from a few Certification Bodies for an accurate figure.
What is the annual cost of Cyber Essentials?
Cyber Essentials certificates are valid for 12 months, after which you renew to stay certified. The renewal fee is set by IASME and depends on the size of your organisation, so check the official IASME website for current pricing. If you also hold Cyber Essentials Plus, its audit fee is payable at each renewal too. Your internal preparation effort normally falls after the first year, once your controls and evidence are established, so the ongoing all‑in cost is typically lower than year one.
Are there any hidden costs for Cyber Essentials?
Yes. Beyond the IASME fee you should budget for internal preparation time (20‑60 person hours typically), technical remediation such as MFA roll‑out and endpoint upgrades, and optionally a consultant or compliance platform to guide the process. These hidden costs often equal or exceed the assessment fee in year one, which is why many organisations choose ISMS.online to make the workload predictable.
Is Cyber Essentials cheaper than ISO 27001?
Yes, by a significant margin. Cyber Essentials sits at the entry level of certification cost, while ISO 27001 is considerably more expensive to achieve and maintain. The two standards address different needs — Cyber Essentials is a technical baseline focused on the UK market, while ISO 27001 is a full information security management system recognised globally. Many UK businesses start with Cyber Essentials and progress to ISO 27001 only when international customers or larger contracts demand it.
Can I reduce my Cyber Essentials cost by narrowing the scope?
In principle yes — the fee is based on the size of the organisation within the certified scope, so a well‑defined sub‑scope can reduce the applicable fee. However, your scope must still satisfy whoever requires the certificate. If a customer needs the certificate to cover all of your operations, an artificially narrow scope will fail to win the contract. Define the scope to match the assurance your buyers need, not to minimise the fee at any cost.






