Cyber Essentials: what it costs and how long it takes

The certification fee is published and modest. The work to pass is the part nobody quotes you for.

Compliance · 5 min read

Almost nobody researches Cyber Essentials for fun. Something has forced it: a tender, a customer's procurement team, an insurer, or public-sector work where it is mandatory. And the deadline is usually closer than is comfortable.

So here are the real numbers.

The certification fee

Cyber Essentials is a UK government-backed scheme overseen by the NCSC and delivered through IASME. The fee is fixed and published, banded by organisation size:

Organisation sizeFee (excluding VAT)
Micro — 0 to 9 employees£320
Small — 10 to 49 employees£440
Medium — 50 to 249 employees£500
Large — 250+ employees£600

Certification lasts twelve months. These are the IASME published figures as at September 2026 — worth confirming when you come to apply, as they are reviewed periodically.

What that fee does not cover

This is where budgets go wrong. The fee buys the assessment: somebody reviews your answers and issues the certificate. It does not buy any of the work required to make those answers true.

If your IT is already in good order, the fee may genuinely be most of what you spend. If the gap analysis finds problems, the remediation is the real cost — and it varies enormously, because it depends entirely on what it finds. Anyone quoting you a fixed all-in price before looking at your estate is guessing.

Cyber Essentials Plus

Plus covers the same five controls but adds independent technical testing — an assessor checks a sample of your devices rather than accepting your self-assessment. There is no published flat fee; the certification body quotes based on how many devices need sampling, so a 25-person single-site business and a 200-person business across four sites are very different jobs.

Two things worth knowing before you commit: you must hold basic Cyber Essentials first, and Plus has to follow within three months of it. Check which one your tender actually asks for — plenty of buyers specify Plus, and plenty specify basic and get quoted for Plus.

How long it takes

The assessment itself is quick. The honest answer to "how long" is "depends what the gap analysis finds", but as a rough guide:

  • IT already in decent shape: two to four weeks, most of which is scheduling and evidence-gathering rather than work.
  • A handful of real gaps: four to eight weeks. MFA rollouts and patch policy changes need to be communicated to staff, not just switched on.
  • Unsupported operating systems in use: longer, and with a hardware budget attached.

The thing that derails most first attempts: unsupported software still in use. An old Windows version, a phone no longer getting security updates, or a line-of-business application that will not run on anything current. Everything else on the list can be fixed in an afternoon. This one can mean new hardware or a conversation with a software vendor, so check it first — before you commit to a date.

The five controls, briefly

  1. Firewalls — every device behind a properly configured firewall, default passwords changed.
  2. Secure configuration — default accounts removed, unused software gone.
  3. Security update management — everything supported and patched, high-risk updates inside 14 days.
  4. User access control — individual accounts, least privilege, MFA on cloud services, leavers removed promptly.
  5. Malware protection — present, updating, actually enabled.

None of it is unreasonable. It is a floor, not a ceiling — which is rather the point of the scheme.

Is it worth it beyond the tender?

Honestly: the certificate itself is a procurement tick. The value is in the controls, and in the fact that an outside party checked. Most businesses that go through it find at least one thing they genuinely did not know about — a forgotten admin account, a machine nobody was patching, a former employee whose access was never removed.

It also tends to help with cyber insurance, where insurers increasingly require MFA, patching and tested backups, and can decline a claim if the controls you declared were not really in place.

Staying certified

It expires after twelve months, and the common pattern is a scramble each year because things drifted. The controls are the ordinary business of decent IT management: patching stays current, MFA stays on, leavers actually get removed. Keep those going and renewal is a formality.

That is most of why clients on managed IT support find their second renewal much quieter than their first. More on how we run certification on our Cyber Essentials page.