“How much is Cyber Essentials?” sounds like it should have a one-line answer. It does have one, but it is only part of the story. The certificate itself is a few hundred pounds. The work to earn it is where the real cost sits, and that is the part most businesses forget to budget for.
Here is the whole picture, so you can put a sensible number in front of your board.
The certification fee
Cyber Essentials is run by IASME on behalf of the National Cyber Security Centre, and the fee for the basic, self-assessed certificate is set on a sliding scale by organisation size. At the time of writing, the published prices are:
- Micro (0 to 9 employees): £320 plus VAT
- Small (10 to 49 employees): £440 plus VAT
- Medium (50 to 249 employees): £500 plus VAT
- Large (250 or more employees): £600 plus VAT
So for most of the businesses we work with, the certificate is either £320 or £440 a year. The certificate lasts twelve months, so this is an annual cost, not a one-off.
Cyber Essentials Plus, where an assessor tests your systems rather than taking your word for it, is priced separately by each certification body based on the size and complexity of your setup. Expect a four-figure sum on top of the basic fee, and get a quote rather than relying on a blog post.
One thing that is included at no extra charge: eligible UK organisations that certify their whole business and have a turnover under £20 million can opt in to cyber liability insurance with a £25,000 limit. It is not a substitute for a proper policy, but it is a useful backstop and it is free.
The cost people actually feel
The fee is the easy part. Cyber Essentials asks you to confirm that five technical controls are in place across every device and account in scope. If they are not, you fix them before you submit, and that is where budgets get stretched. The usual culprits:
- Old kit. Any laptop or PC running an operating system that no longer gets security updates fails the assessment. Windows 10 machines are the obvious example now that Microsoft has stopped supporting it. Replacing three or four of those costs more than the certificate ever will.
- Multi-factor authentication everywhere. Rolling it out is not expensive, but somebody has to do it, help the people it confuses and deal with the shared account nobody wants to give up.
- Admin rights. Everyday accounts must not have administrator access. Taking it away usually breaks one piece of old software, which then needs sorting out.
- Personal devices. If people read work email on their own phones, those phones are in scope. Either you manage them or you change how people work.
- The questionnaire itself. Answering it properly takes time and a fair amount of technical knowledge. Guessing is how people fail.
- Doing it again next year. Certification lapses after twelve months, so anything you fixed once has to stay fixed.
None of this is a reason not to certify. These are the things that stop the most common attacks, so the money is well spent. It just needs to be planned rather than discovered halfway through.
What we include, and what we do not
Our Protect package is built around the Cyber Essentials framework. For £70 per user per month, the five controls are put in place and kept in place: Microsoft 365 configured in line with Cyber Essentials guidance, patching, endpoint detection and response, vulnerability scanning, security awareness training and the IT policies the assessment expects to see. We do the gap assessment, fix what needs fixing, and support you through the questionnaire. We do not put a client forward until we are confident they will pass.
What Protect does not include is the IASME certification fee itself, which you pay to the certification body, or the cost of replacing hardware that has reached the end of its life. We will tell you about both up front, so there are no surprises. Registered charities get 10% off our packages.
If your team uses AI tools, it is worth knowing that our Protect & AI package brings those inside the Cyber Essentials boundary too, so the tools your staff use are approved, managed and covered by the same controls as everything else.
What this means for a business with 5 to 50 people
A realistic first-year budget has three lines: the certificate (£320 or £440 plus VAT), any hardware that has to be replaced, and the time or support to get the controls in place. After the first year, it is mostly the certificate and keeping things maintained. Set against a lost tender or a cyber insurance claim that gets declined, it is one of the better-value things you can do.
Where to start
Find out where you stand before you spend anything. A gap assessment tells you which of the five controls you already meet, which you do not, and what fixing them would cost. Then you can decide with real numbers rather than a guess.
If you would like that honest picture, talk to us about Cyber Essentials. We will tell you where you stand, what needs to change and how long it will take, and whether certification is worth it for your business right now.