The question that comes up more than any other from prospective clients: what does Cyber Essentials actually cost? The published fees are one answer. The realistic total-cost-of-getting-certified is another, usually two to four times higher once remediation and time are counted. This article walks through both, so you can budget honestly before you commit.
The published fees
Certification fees are set by IASME, the organisation appointed by the National Cyber Security Centre to administer Cyber Essentials. IASME's published fees for the basic certificate, excluding VAT, are:
Cyber Essentials (basic):
- Micro (0 to 9 employees): £320 excluding VAT
- Small (10 to 49 employees): £440 excluding VAT
- Medium (50 to 249 employees): £500 excluding VAT
- Large (250+ employees): £600 excluding VAT
Cyber Essentials Plus: prices are not fixed. Each certification body sets its own. Typical ranges:
- Micro: £1,900 to £2,800
- Small: £2,500 to £4,500
- Medium: £4,500 to £8,000
- Large: quoted on request based on scope
The basic fee is paid to whichever certification body you choose. Plus is quoted based on the number of devices to be sampled and the location of the assessment.
What the fee actually covers
The basic fee covers:
- Access to the self-assessment questionnaire on IASME's platform
- One review round by a qualified assessor
- One remediation round if the initial submission needs corrections
- The certificate itself, valid for twelve months
- Listing in the public IASME directory of certified organisations
- Automatic cyber liability insurance (£25,000 cover) for UK-domiciled organisations under £20 million turnover
The Plus fee additionally covers:
- The external vulnerability scan
- The authenticated device scan
- Email and browser test execution
- Assessor time on-site or via remote session
- A written report of test findings
- A remediation window (typically 30 days) with retest
What the fee does not cover
This is where most first-time budgeteers get caught out. The published fee is only the assessment fee. Everything else you need to actually pass is on you.
Remediation work
If your controls do not meet the requirement on the day you submit, you have to fix them before you get certified. Common remediations and their real-world costs:
- Updating unsupported operating systems. A Windows 10 machine that has run out of support cannot be in scope. Replacing it or upgrading it: £600 to £1,500 per device.
- Enabling MFA on services that do not currently have it. Free in most cases. Time-cost is typically half a day per service to plan the rollout, plus another half day to run it. In a team where nobody has done this before, budget a full day per major service.
- Removing unsupported software. Free, but requires deciding whether the person who used that software actually needed it, and if so what replaces it.
- Router or firewall replacement if the internet-facing device is out of support or cannot be configured to meet the requirement. £150 to £600 for a business-grade replacement.
- Password manager rollout if you do not already use one. £30 to £60 per user per year for a business plan on Bitwarden, 1Password, or similar.
- Endpoint management tooling to enforce update policies on devices, if you are certifying Plus and cannot manually verify each device. £4 to £12 per device per month.
Time cost
The invisible cost. For a first-time certifier:
- Reading the question set and understanding what is being asked: two to four hours
- Auditing your current controls against the questions: half a day to a full day
- Remediating gaps (highly variable, this is what usually drives the timeline)
- Completing the questionnaire: two to four hours
- Responding to assessor questions: one to two hours across a couple of exchanges
Total effort for a well-prepared micro-business with no significant gaps: one to two working days spread across two to three weeks.
Total effort for a first-timer with several gaps to close: one to two weeks of actual work spread across two months of elapsed time.
Consultant fees (if you use one)
Cyber Essentials consultants operate at three price points:
- DIY guidance: £200 to £400 for a two-hour advisory call and template pack. Useful if you are confident enough to fill the questionnaire yourself and just want a sanity check on your answers.
- Assisted: £800 to £1,500 for a consultant to walk you through the questionnaire, help remediate gaps, and submit on your behalf. Appropriate if this is your first time and you value certainty over cost.
- Fully managed: £2,000 to £4,000 for a consultant to handle everything including ongoing monitoring of your controls between annual renewals. Appropriate if compliance is not core to your business and you want to outsource it entirely.
For Plus, add £500 to £1,500 to any of the above tiers, because the assessor's tests need to be planned for and remediated against, not just described in a questionnaire.
The honest total for a first-time micro-business
Assume:
- Sole trader or one-person limited company
- Windows 11 laptop, an iPhone, uses Microsoft 365
- No MFA on anything currently
- Router is the one supplied by the ISP with default password unchanged
- No password manager
Realistic total to first certificate:
- Basic Cyber Essentials fee: £320
- Router password change: £0 (free, ten minutes)
- MFA enrolment across email, cloud storage, accounting, one client platform: £0 (free, two hours)
- Password manager: around £48 a year for one seat of a business password manager such as Bitwarden
- Removing old Windows software you no longer use: £0
- Time investment: 6 to 10 hours of your own time
Total out-of-pocket: £368 excluding VAT. Total time: 6 to 10 hours across two to three weeks.
Plus for the same profile:
- Plus fee: £1,950 (typical for a single-device scope at the smallest bodies)
- Same remediation as above
- Additional preparation time to make sure the automated tests will pass: 2 to 4 hours
Total out-of-pocket for Plus: £1,998 excluding VAT.
The honest total for a first-time team of ten
Assume:
- Ten employees, mixed Windows and Mac
- Existing Microsoft 365 tenant, no MFA enforced yet
- Ad hoc IT with no formal endpoint management
- Some staff have been there for years and have accumulated old software
Realistic total to first basic certificate:
- Basic Cyber Essentials fee: £440
- MFA rollout across ten users on three or four platforms: £0 in fees, one to two days of time from whoever runs the rollout
- Password manager: around £480 a year for ten seats
- One or two device replacements for anything out of support: £1,500 to £3,000
- Consultant fee if you use one (assisted tier): £1,200
- Time investment: 40 to 60 hours across the team
Total out-of-pocket without consultant: £2,420 to £3,920 excluding VAT. Total out-of-pocket with consultant: £3,620 to £5,120 excluding VAT.
Plus for the same profile:
- Plus fee: £3,200 (typical for ten-device scope)
- Same remediation
- Endpoint management tooling to enforce update policies: £480 to £1,440 annually
- Consultant fee, including Plus preparation: £2,700
Total out-of-pocket for Plus with consultant: £8,360 to £10,820 excluding VAT.
Where the money goes if it goes wrong
Two common ways a Cyber Essentials budget balloons:
You certify without remediating first, fail the assessment, and pay again. Some certification bodies charge for the initial assessment even if it fails. Read the terms before you commit. Fixing the gap and resubmitting can be free if you catch it in the remediation window, or a full re-fee if you miss it.
You certify basic when the client actually needs Plus, do the work, then find you need to upgrade six weeks later. The basic fee is not refundable and the Plus fee is separate. Ask the client which they need before you start.
Annual costs after the first year
Renewal costs match new certification costs. There is no discount for renewing. The main annual cost is:
- Recertification fee (same as initial): £320 for a micro-business
- Password manager subscription: £48 for one seat
- Whatever endpoint management or MFA tooling you introduced for the initial certification
- Time investment: roughly half of the initial year because you already know how the questionnaire works and your controls are largely in place
Realistic annual ongoing cost for a certified sole trader: £400 to £500 excluding VAT.
Realistic annual ongoing cost for a certified team of ten: £2,500 to £5,000 excluding VAT.
The value the certificate returns
The cost is only defensible if the certificate returns value. For most small businesses it does, in three ways:
- It unlocks contracts. Public-sector work, larger enterprise clients, and regulated-sector clients increasingly require the certificate. Without it, you cannot bid.
- It reduces breach cost. The insurance included with the basic certificate provides £25,000 of incident cover. Real breach costs run higher, but the certification process itself forces you to implement controls that measurably reduce the probability of a breach.
- It reduces ICO liability. If the ICO investigates a breach at a certified organisation, the certificate is a mitigating factor. If they investigate an uncertified organisation that clearly should have had basic controls, the absence of certification is an aggravating factor.
Sources
- IASME, Cyber Essentials fees and eligibility, https://iasme.co.uk/cyber-essentials/
- National Cyber Security Centre (NCSC), Cyber Essentials overview, https://www.ncsc.gov.uk/cyberessentials/overview
- GOV.UK, Cyber Essentials scheme overview, https://www.gov.uk/government/publications/cyber-essentials-scheme-overview
- IASME, Cyber liability insurance included with certification, https://iasme.co.uk/cyber-essentials/cyber-liability-insurance/
- Information Commissioner's Office, ICO fining guidance on aggravating and mitigating factors, https://ico.org.uk/media/about-the-ico/documents/2618797/data-protection-act-2018-sec-155-guidance-2020.pdf
Want to know where you stand?
We assess your public web and email surface and send you a written report. No charge, no obligation.
Book a free audit