How much does Cyber Essentials cost in 2026?
The certification fee is published and predictable. The total cost is not — and the gap between the two is where organisations get caught out.
The short answer
The Cyber Essentials certification fee is £320 to £600 plus VAT, set by IASME and banded by organisation size: from £320 for a micro business (under 10 people), around £400 for a small one (10–49), £450 for medium (50–249) and £500–600 for large. That buys the assessment. A typical small business all-in — fee, a provider that reviews your answers before submission and covers a resubmission, and a few hours of configuration — lands between £600 and £1,500. Cyber Essentials Plus adds £1,500 to £3,000 on top. Everything below explains where each of those numbers comes from.
The certification fee
This part is straightforward. The fee is set by IASME, the body that runs the scheme for the NCSC, and it is banded by organisation size. It starts at £320 plus VAT for the smallest organisations and rises to around £600 plus VAT for the largest.
| Organisation size | Indicative fee |
|---|---|
| Micro — under 10 people | from £320 |
| Small — 10 to 49 | around £400 |
| Medium — 50 to 249 | around £450 |
| Large — 250 and over | around £500–600 |
Bands and figures are reviewed periodically, so check IASME's current published pricing before you budget. Note also that the band is determined by the size of the organisation being certified rather than by how many people happen to be in scope — a point worth confirming for your circumstances, because it catches out organisations that assumed a narrow scope would mean a lower fee.
All IASME-licensed bodies issue the identical government-backed certificate, with the same NCSC badge and the same twelve-month validity. What differs between them is price, turnaround speed, resubmission policy and how much help you get. If you are comparing quotes, you are comparing service — not the certificate.
The free insurance most organisations miss
UK organisations with turnover under £20 million that certify their whole organisation are automatically entitled to cyber liability insurance arranged through IASME, including 24/7 incident response support with technical, legal and crisis management help.
This matters for two reasons. It is genuine value included in the fee, and it is one more argument against engineering a narrow scope — certifying a carved-out fragment can forfeit it. Eligibility criteria apply, so confirm your position rather than assuming.
The cost nobody quotes: remediation
The fee buys the assessment. Getting to the point where you can pass it is a separate cost, and for organisations starting from a weak position it is by far the larger one. Government research put the mean total cost of certifying — including consultancy, hardware and software changes and policy work — at close to £5,000, though that average is pulled sharply upward by organisations with significant technical debt.
The realistic picture for a small organisation:
- Nothing at all if MFA is already on everywhere, devices are supported and patched, and accounts are individual. Some organisations genuinely are ready.
- A few hours of configuration — enabling MFA across services, splitting admin from standard accounts, turning on automatic updates, removing old accounts. This is the most common case.
- Hardware replacement where a machine runs an unsupported operating system and cannot be upgraded. One laptop is a few hundred pounds; a set of ageing machines is the real budget item.
- Software or licence changes where a service in use cannot support individual accounts or MFA and has to be replaced.
The variance is enormous, and it is entirely knowable in advance. An hour spent establishing what you actually have — devices, operating system versions, cloud services, accounts — tells you which of the four cases above you are in, before any money is spent. Our free readiness check is a shortcut to the same answer.
What if you fail?
Less painful than people fear. The assessment fee generally covers a period of self-assessment attempts rather than one submission, so an organisation that fails can fix the problem and resubmit without paying again. Policies vary between certification bodies, so check the resubmission terms — that is one of the few things that genuinely differs between them.
The real cost of failing is time, and the awkwardness of having told a customer certification was in hand. Our guide on why applications fail covers what to check first.
Cyber Essentials Plus
Plus is not banded by headcount. It is priced by the size and complexity of the network, because an assessor has to carry out an independent technical audit. Market prices commonly run from around £1,500 to £3,000 plus VAT, and you need a valid base certification first — so the base fee is on top, not included.
Get a quote based on your actual device numbers rather than a headline price. And read whether you need Plus at all before budgeting for it, because most organisations asked for "Cyber Essentials" are being asked for the base certification.
Renewal, every year
Certification lasts twelve months. Renewal is a fresh assessment at the fee applying at the time, not a rubber stamp — and because the question set changes between scheme years, the bar at renewal may be higher than the one you originally cleared. Organisations that treat it as an annual formality are the ones that fail their second assessment having passed their first.
Adding it up
Three worked cases, all excluding VAT:
- Ready already — MFA on everywhere, supported devices, individual accounts. The fee (£320–£400) plus a provider’s service charge if you use one. Around £400–£800 total.
- Nearly ready — a few hours of configuration: MFA switched on across services, admin accounts separated, an old browser retired. Fee plus £200–£600 of work. Around £600–£1,500 total.
- Starting from behind — unsupported machines to replace, no MFA, shared logins. Fee plus a hardware and configuration project that is worth doing regardless of certification: £1,500–£5,000 depending on how many machines. This is where the government’s ~£5,000 mean figure comes from.
Add £1,500–£3,000 for Cyber Essentials Plus if a customer, framework or insurer specifically requires it — most that say “Cyber Essentials” mean the base certificate. And remember the £25,000 of cyber liability insurance included with a pass, which offsets a good part of the fee for any business that would otherwise buy cover.
Which is the honest way to think about the whole thing. Almost everything you spend to pass Cyber Essentials is money spent on defences you should have had — the certificate is the receipt, not the product.
Find out which case you are in — free
The readiness check tells you what would currently fail, which is the only way to know whether your remediation is an afternoon or a project. No sign-up needed to see the result.
If you would rather hand it over: we quote a fixed fee before starting, and if a submission we have prepared does not pass, we fix it and resubmit at no extra charge.
Take the readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Fees are set by IASME and reviewed periodically; figures here are indicative and exclude VAT. Insurance eligibility criteria and cover levels are set by IASME and its insurance partner. Confirm current pricing, bands and eligibility on the IASME website before budgeting.