Skip to content
Phishing for Trouble –
The IO Podcast returns for Series 2
Listen now

Cyber Essentials is one of the most cost-effective cybersecurity certifications available to UK businesses, but the headline IASME assessment fee rarely tells the whole story. Preparation time, technical remediation, optional consultancy support and the step up to Cyber Essentials Plus all influence what you will actually spend in your first year and at each annual renewal.

This guide breaks down the cost areas you can expect to encounter on the path to certification, compares Cyber Essentials against other security standards such as ISO 27001 and SOC 2, and shows how to minimise spend without compromising on certification quality. For current published fees, always check the official IASME website, and visit our Cyber Essentials hub for a wider overview of the scheme.

How much does Cyber Essentials cost?

The headline cost of Cyber Essentials is the assessment fee, which is set centrally by IASME, the body that runs the scheme on behalf of the NCSC. The fee varies according to the size of your organisation. Because IASME sets and periodically reviews this pricing, the only reliable source for current figures is the official IASME website — check there before you budget.

The assessment fee typically covers your self‑assessment submission and the certificate itself. Smaller UK-based organisations under a turnover threshold may also qualify for IASME-backed cyber liability insurance included with certification; confirm the current eligibility criteria and cover levels directly with IASME.

Headcount is determined by the scope you certify, not the entire group. If you are certifying a UK subsidiary of a larger international parent and the scope only includes UK employees, you pay based on the UK headcount. This is one of the most common ways UK businesses unintentionally overpay — defining the scope sensibly can reduce the fee you pay without affecting the certificate’s usefulness in tender responses.

The fee is paid directly to your chosen IASME Certification Body when you submit your self‑assessment. Some Certification Bodies add a small administration premium on top of the IASME fee, particularly when they bundle in pre‑assessment support, so it is worth comparing three or four quotes before booking.

How much does Cyber Essentials Plus cost?

Cyber Essentials Plus builds on the standard self‑assessment with an external technical audit, including authenticated vulnerability scans of your devices, a sample of user accounts and a review of your external footprint. Because the assessor must spend time physically (or remotely) testing your environment, it costs more than the basic self‑assessment.

Cyber Essentials Plus is priced separately by your chosen Certification Body rather than set centrally by IASME, and the fee is in addition to (not instead of) the underlying Cyber Essentials assessment fee. The main factors that drive the price are:

  • Sample size — The number of devices and user accounts the assessor needs to test; larger estates take longer to audit.
  • Environment complexity — Multiple operating systems, mobile fleets, remote workers and cloud platforms all add to the assessment effort.
  • Number of sites — Organisations spread across several locations typically require a broader sample.

For an accurate figure, request quotes from a few Certification Bodies based on your specific scope. If you only need the basic certification because a tender requires it, the standard self‑assessment is enough. If your buyers, insurers or regulators specifically ask for Cyber Essentials Plus, or you sell into central government, defence or sensitive supply chains, the Plus uplift is normally non‑negotiable. Read our guide to Cyber Essentials Plus requirements to see exactly what the audit covers.




climbing

Embed, expand and scale your compliance, without the mess. IO gives you the resilience and confidence to grow securely.




What hidden costs should you budget for?

The IASME and Plus fees are only the visible portion of the iceberg. Most organisations spend at least as much again on the work needed to pass the assessment first time. Treating these costs as part of the project budget from day one avoids nasty surprises later.

Preparation time and internal resourcing

Even the simplest Cyber Essentials self‑assessment covers dozens of questions across the five control areas — firewalls, secure configuration, user access control, malware protection and security update management. A first‑time applicant typically spends between 20 and 60 person‑hours gathering evidence, configuring controls and completing the questionnaire, which represents a real internal time cost on top of the assessment fee.

Technical remediation

Most organisations discover at least one control they cannot evidence on day one. Common remediation costs include:

  • Endpoint replacement — Devices running unsupported operating systems (older Windows versions, end‑of‑life macOS) must be retired or upgraded.
  • MFA roll‑out — Multi‑factor authentication is mandatory for all cloud services and administrative accounts.
  • Patch management tooling — Automated patching for operating systems, applications and firmware, with high and critical severity updates applied within 14 days.
  • Endpoint protection — Anti‑malware on every applicable device, centrally managed where possible.
  • Account hygiene — Removing dormant accounts, separating administrative and standard accounts and enforcing strong password policies.

Consultancy and managed support

Engaging a Cyber Essentials consultant or IT managed service provider adds a further cost that varies with the scope of support you need. This buys you a gap analysis, evidence templates, policy drafting and a sense check before submission. For organisations with no internal security resource, this is usually cheaper than failing the first submission and paying for a resit.

Annual renewal fees

Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months. Renewal is not discounted — you pay the full IASME assessment fee and (if applicable) the full Plus audit fee each year. Some Certification Bodies offer multi‑year packages with a small saving, but the underlying IASME fee is unchanged.

How should you budget for Cyber Essentials over time?

To get a realistic picture of cost, look at the total across a multi‑year cycle rather than just the year‑one outlay. Your budget should account for several components: the IASME assessment fee, the Cyber Essentials Plus audit fee if you need it, preparation and consultancy support, technical remediation and internal staff time.

Year one is almost always the most expensive, because it carries the bulk of the remediation and preparation effort. From the second year onwards, once your controls, evidence and processes are embedded, the ongoing cost usually falls to the assessment fee plus a much smaller preparation overhead. Organisations that already operate good IT hygiene, MFA and patching can reduce the year‑one outlay significantly. Read our guide on how long Cyber Essentials takes to see how preparation effort maps onto cost.

How does Cyber Essentials cost compare to ISO 27001 and SOC 2?

Cyber Essentials is deliberately positioned as the entry point to certified cybersecurity for UK businesses, and it sits at the lowest end of the certification cost spectrum.

Standard Relative Cost Best Suited For
Cyber Essentials Lowest — entry level UK businesses bidding for government and supply chain contracts
Cyber Essentials Plus Low to moderate UK businesses where buyers require external audit assurance
ISO 27001 Moderate to high UK and international businesses needing globally recognised assurance
SOC 2 (Type II) Highest SaaS and technology businesses selling into the US market

Cyber Essentials is substantially cheaper than ISO 27001 and dramatically cheaper than SOC 2 Type II. For many UK businesses, Cyber Essentials covers the most common procurement and insurance requirements at a fraction of the cost of the larger frameworks. If your customer base is largely UK based and your contracts specify Cyber Essentials or Cyber Essentials Plus, there is rarely a commercial reason to spend more. See our comparison of Cyber Essentials vs ISO 27001 for a deeper breakdown.




ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.

ISMS.online supports over 100 standards and regulations, giving you a single platform for all your compliance needs.




What is the return on investment for Cyber Essentials?

The fee is only one side of the equation. For most UK organisations the certificate pays for itself within the first year through several main channels.

Contract eligibility

Cyber Essentials is mandatory for many UK central government contracts that involve handling personal data or operational information. It is also increasingly required by local authorities, NHS suppliers, defence primes and large enterprises in their supplier onboarding processes. A single won tender can pay for several years of certification.

Cyber insurance premium discounts

UK cyber insurers routinely offer premium discounts to Cyber Essentials certified organisations, and many will simply not quote without it. Where eligible, the IASME-backed cyber liability insurance included with certification can itself be worth more than the certification fee for businesses that would otherwise need to purchase their own cover. Confirm current eligibility and cover levels with IASME.

Reduced breach probability

The UK Government’s Cyber Security Breaches Survey consistently shows that organisations with the basic technical controls in place experience fewer and less severe incidents. With the cost of a typical cyber incident for a UK SMB running well into the thousands of pounds, even a modest reduction in incident probability more than justifies the cost.

Faster sales cycles

Holding the certificate shortens supplier due diligence questionnaires significantly. Many buyers accept Cyber Essentials Plus as a substitute for completing their own multi‑page security questionnaire, accelerating procurement timelines. Our analysis of whether Cyber Essentials is worth it explores the ROI in more detail.

DIY vs consultant: which route saves the most money?

There is no single right answer to the DIY vs consultant question. The cheapest option on paper (DIY) often becomes the most expensive if a failed submission forces remediation work under time pressure. Use the table below to choose the route that matches your situation.

Route Relative Cost Best For Watch Out For
Pure DIY No extra cost beyond internal time Organisations with an experienced IT lead and good security hygiene already in place Significant internal time investment; risk of failing first submission
Platform‑assisted Low ongoing subscription SMBs that want structure, templates and progress tracking without paying full consultancy rates Choose a platform that maps directly to the IASME question set
Consultant‑led Moderate, usually a one‑off fee Organisations with little internal security expertise or tight deadlines Make sure the consultant transfers knowledge so renewal cost falls in year two
Fully managed Ongoing monthly cost Micro and small organisations outsourcing IT and security to a managed service provider Lock‑in to a specific MSP; renewal pricing can creep up

For most UK small businesses, the platform‑assisted route delivers the best balance of cost and certainty. Read our guide for Cyber Essentials for small business for sector specific advice on choosing between the routes.

Why Choose ISMS.online for Cyber Essentials?

ISMS.online is built to make Cyber Essentials preparation faster, more predictable and a great deal less stressful than spreadsheets and shared drives.

  • Mapped to the full IASME question set — Every Cyber Essentials control is pre‑mapped in the platform, so you assess against the standard without building your own checklist.
  • Pre‑built policies and evidence templates — Acceptable use, patching, access control and incident response policies are ready to customise, cutting preparation time from weeks to days.
  • Evidence vault with version control — Screenshots, configuration exports and signed‑off policies are stored against each control, ready to share with your assessor.
  • Maturity dashboards — Track your readiness in real time and see exactly which questions you can already answer with full confidence.
  • Multi‑framework reuse — If you later progress to ISO 27001 or SOC 2, the same evidence and policies map across, so ISMS.online helps you achieve those certifications faster too.
  • Assured Service Provider partnerships — Connect directly to certified IASME assessors through the platform when you are ready to submit.
  • Predictable subscription pricing — A single annual platform fee, no surprise consultancy bills, and full transparency on what you are paying for.

Related Cyber Essentials guides

Continue your Cyber Essentials journey with the other guides in this series:

FAQs

How much does Cyber Essentials cost in the UK?

The Cyber Essentials assessment fee is set by IASME and depends on the size of your organisation, so what you pay is based on your certified headcount. IASME reviews its pricing from time to time, so check the official IASME website for the current fees. The assessment fee is the headline cost only — most UK businesses also incur preparation, remediation and (optionally) consultancy costs, so budget for more than the fee alone in year one.


How much is Cyber Essentials Plus?

Cyber Essentials Plus is priced separately by your chosen Certification Body rather than set centrally by IASME, and the cost depends on the size and complexity of your environment — principally the number of devices and user accounts sampled. It is charged in addition to the standard Cyber Essentials assessment fee, so budget for both. Request quotes from a few Certification Bodies for an accurate figure.


What is the annual cost of Cyber Essentials?

Cyber Essentials certificates are valid for 12 months, after which you renew to stay certified. The renewal fee is set by IASME and depends on the size of your organisation, so check the official IASME website for current pricing. If you also hold Cyber Essentials Plus, its audit fee is payable at each renewal too. Your internal preparation effort normally falls after the first year, once your controls and evidence are established, so the ongoing all‑in cost is typically lower than year one.


Are there any hidden costs for Cyber Essentials?

Yes. Beyond the IASME fee you should budget for internal preparation time (20‑60 person hours typically), technical remediation such as MFA roll‑out and endpoint upgrades, and optionally a consultant or compliance platform to guide the process. These hidden costs often equal or exceed the assessment fee in year one, which is why many organisations choose ISMS.online to make the workload predictable.


Is Cyber Essentials cheaper than ISO 27001?

Yes, by a significant margin. Cyber Essentials sits at the entry level of certification cost, while ISO 27001 is considerably more expensive to achieve and maintain. The two standards address different needs — Cyber Essentials is a technical baseline focused on the UK market, while ISO 27001 is a full information security management system recognised globally. Many UK businesses start with Cyber Essentials and progress to ISO 27001 only when international customers or larger contracts demand it.


Can I reduce my Cyber Essentials cost by narrowing the scope?

In principle yes — the fee is based on the size of the organisation within the certified scope, so a well‑defined sub‑scope can reduce the applicable fee. However, your scope must still satisfy whoever requires the certificate. If a customer needs the certificate to cover all of your operations, an artificially narrow scope will fail to win the contract. Define the scope to match the assurance your buyers need, not to minimise the fee at any cost.



Max Edwards

Max works as part of the ISMS.online marketing team and ensures that our website is updated with useful content and information about all things ISO 27001, 27002 and compliance.

Watch a platform demo

See how 1,000+ teams run their compliance frameworks in a 3-minute platform tour

platform dashboard full on mint

We’re a Leader in our Field

4/5 Stars
Users Love Us
Leader - Summer 2026
High Performer - Summer 2026 Small Business UK
Regional Leader - Summer 2026 EU
Regional Leader - Summer 2026 EMEA
Regional Leader - Summer 2026 UK
High Performer - Summer 2026 Mid-Market EMEA

"ISMS.Online, Outstanding tool for Regulatory Compliance"

— Jim M.

"Makes external audits a breeze and links all aspects of your ISMS together seamlessly"

— Karen C.

"Innovative solution to managing ISO and other accreditations"

— Ben H.