Cyber Security
How much does Cyber Essentials cost in 2026?
Cyber Essentials fees in 2026: IASME size bands from around £320 plus VAT, what Cyber Essentials Plus costs, and the remediation costs that really vary.
By Dig IT SolutionsUpdated 8 September 20265 min read
Short answer
The Cyber Essentials certification fee is set by IASME and banded by organisation size, starting from around £320 plus VAT for micro organisations and rising by band to a few hundred pounds more for larger ones. Cyber Essentials Plus is priced separately by the certification body, usually four figures. The real variable is remediation before you apply.
Cyber Essentials is one of the few security certifications with a published, fixed price for the basic level, which makes budgeting straightforward for the certificate itself. What catches businesses out is everything around it: the Plus audit, the remediation needed to pass, and the time. This article sets out all of it for a UK business of up to 250 people, with 2026 figures where they are published and honest ranges where they are not.
The certificate fee: banded by size
The basic Cyber Essentials assessment has a national fee set by IASME, the NCSC's delivery partner, and charged through whichever licensed certification body you use. Since 2024 the fee has been banded by organisation size rather than a single flat rate.
The widely published starting point is around £320 plus VAT for micro organisations (fewer than ten employees), rising by band for small, medium and large organisations, with the largest band a few hundred pounds above the smallest. IASME publishes the current bands on its Cyber Essentials pages, and they should be checked before you budget because they are revised periodically.
The fee covers the assessment of your self-assessment questionnaire by a qualified assessor, the certificate, listing on the public register and, for eligible organisations, the included cyber liability insurance described below. It does not cover any help completing the questionnaire.
Cyber Essentials Plus: priced by the certification body
Cyber Essentials Plus has no fixed national fee. It is an audit carried out by an assessor from a certification body, and each body prices it according to your size, the number of sites, the number of devices to be sampled and whether the work is remote or on-site. For a small business expect a four-figure sum. You must hold a current basic certificate first and complete Plus within three months of it, so the basic fee is always paid as well.
If a contract requires Plus, ask two or three certification bodies for quotes. Prices vary and so does responsiveness. Our guide to what Cyber Essentials is explains what the Plus audit involves.
The real cost is remediation
For most small businesses the certificate fee is the smallest line on the invoice. The larger figure is the work needed to actually meet the five controls, and that depends entirely on where you start.
| Typical gap | What fixing it involves | Cost pattern |
|---|---|---|
| Unsupported operating systems (Windows 10 without extended support, old servers) | Replace or upgrade hardware, migrate services | The single biggest variable: several hundred pounds per PC, more for servers |
| MFA not enforced, or exceptions for some users | Configure conditional access, enrol users, handle shared mailboxes | Mostly labour, MFA is included in Microsoft 365 licences |
| No managed patching or no way to prove it | Deploy remote monitoring and management, set schedules, report monthly | Per-device monthly fee |
| Basic or missing anti-malware | Deploy endpoint detection and response on every device | Per-device monthly fee |
| Users with local administrator rights | Remove rights, create separate admin accounts, handle the applications that complain | Labour |
| Firewall out of support or exposed services | Replace or update firewall, close ports, move remote access to VPN with MFA | Hardware plus labour |
| Personal devices accessing work email with no management | Intune app protection or MDM, a BYOD policy | Labour, Intune is often already licensed |
| No device or software inventory | Build and maintain it | Labour, then ongoing |
A business that already has a managed IT service delivering patching, EDR, enforced MFA and a supported firewall may find its remediation cost is close to zero and the whole exercise is a few hours of questionnaire work. A business with a mixed, unmanaged estate might spend several thousand pounds, most of it on hardware that needed replacing anyway. Our self-assessment guide will show you which end of that range you are at.
Consultancy and preparation
You can complete the questionnaire yourself, and IASME publishes a free readiness tool to help. Many businesses choose to have an IT partner run a gap assessment, do the remediation and support the submission, because the questions are technical and an inaccurate answer either fails the assessment or, worse, results in a director signing a declaration that is not true.
Preparation is usually priced as a fixed project for the assessment and questionnaire support, with remediation quoted separately once the gaps are known. For businesses on a managed service, much of the preparation is already covered. We describe the engagement on our Cyber Essentials preparation page, note that we prepare, we do not certify, because the same firm should not both fix the systems and mark the exam.
Ongoing costs
The certificate lasts twelve months, so the fee recurs annually, and Plus must be repeated each year if you need it. More significantly, the controls must remain in place: patching, endpoint protection and MFA are continuous, not one-off, and the question set is updated so requirements can tighten between years. Those ongoing items are exactly what a managed IT agreement provides, which is why for supported businesses renewal is a light annual task rather than a fresh project. Our cost calculator gives indicative per-device figures for managed support that includes these controls.
What you get for the money
Beyond the certificate itself, three things have direct commercial value.
Eligibility for contracts. Central government requires Cyber Essentials for suppliers on contracts involving personal data or certain IT services, and the requirement has spread through defence, NHS, local authority and education supply chains. One tender won covers the cost many times over.
Included insurance. Organisations that certify their whole organisation and fall under a turnover threshold are offered cyber liability insurance at no extra cost, with the terms published by IASME. It is a genuine benefit for very small firms, though businesses handling client money or sensitive data should still hold a proper policy.
Easier questionnaires and lower premiums. Cyber insurers and larger customers ask about the same five controls. Holding the certificate answers most of their questions in one line and, in our experience, makes insurance applications considerably less painful.
A worked example
A 25-person professional services firm on Microsoft 365, with a small office server, two Windows 10 PCs still in use, MFA enabled but not enforced, consumer antivirus and an ISP router as the firewall. Realistic budget: two replacement PCs, a business firewall, EDR and managed patching on around 28 devices at a monthly per-device fee, a preparation engagement to enforce MFA and conditional access, remove local admin rights and build the inventory, then the basic certificate fee in the small band. Total in the low thousands, most of it on equipment and controls the firm needed regardless, followed by a modest annual renewal.
What to do next
If you want a figure rather than a range, an IT health check assesses your estate against the five controls and produces a costed list: what must change to pass, what it would cost, and how long it would take.

