PassCyber
PassCyber / Guides

What does Cyber Essentials Plus actually cost?

More than basic Cyber Essentials — because with Plus, an assessor doesn't take your word for it: they test your systems. Here's what genuinely drives the price, realistic figures for a small organisation, the hidden costs nobody quotes, and the question to answer before spending anything: do you actually need Plus?

Honest pricing guideReading time 5 minutes

Why Plus costs more: someone has to test you

Basic Cyber Essentials is a verified self-assessment — you answer the question set, an assessor reviews your answers. Plus adds a hands-on technical audit: within three months of passing basic, an assessor tests a sample of your actual devices — vulnerability scans, checks that malware protection genuinely blocks test files, that email and browsers handle hostile attachments correctly, that your MFA and account separation are real rather than claimed. You're paying for skilled assessor time, and the price scales with how much of it your organisation needs.

What drives your price

Four things, in order of impact: how many devices and users are in scope (the sample size grows with you); how many different setups you run (five identical laptops are one test; a laptop, a Mac, a server and two phone types are five); whether testing is remote or on-site (remote suits most small organisations and keeps travel off the bill); and how ready you are — a failed test means remediation and retesting, which is where budgets actually blow up.

Realistic figures for a small organisation

ComponentTypical range
Basic Cyber Essentials (prerequisite — scheme-set fee, size-banded)a few hundred pounds
Plus audit, micro/small organisation, remote, simple estate£1,400 – £2,500
Larger or mixed estates, on-site testing£2,500 upwards

Treat any quote outside those shapes with questions — in both directions. Suspiciously cheap usually means a rigid pass/fail with no help when something fails; suspiciously expensive usually means bundled consultancy you didn't ask for. The quote you want is fixed, in writing, and explicit about what happens if a test fails.

The hidden cost: failing the audit

Plus is tested within a three-month window of your basic pass. Fail the technical audit — an unpatched machine in the sample, MFA missing on one service, malware protection that doesn't actually block — and you're paying for remediation and retest time, sometimes for the basic assessment again if the window lapses. This is why preparation is the cheapest part of the whole exercise: our free readiness check flags the classic failures in two minutes, before anyone's charging you to discover them.

Do you actually need Plus?

Genuinely required: certain MoD and defence supply-chain contracts, a growing set of frameworks and enterprise procurement lists, and some cyber insurers' better terms. Increasingly requested: larger clients who want the tested version, not the declared one. Probably not needed: if no contract, framework, client or insurer is asking, basic Cyber Essentials delivers most of the security benefit for a fraction of the cost — and you can step up to Plus later in the year if a requirement appears. We'll tell you which side you're on for free; it takes one email describing who's asking.

Get a real number for your organisation — free

Tell us your email and we'll ask three questions (devices, setups, who's requiring Plus), then give you a fixed written quote — and an honest "you don't need Plus" if that's the truth.

Done — we'll be in touch, usually the same working day.
Related reading

Not sure of the difference? Start with our guide to Cyber Essentials vs Plus — then run the readiness check to see where you'd stand today.

PassCyber

Plus, without the budget surprise

Fixed written price, readiness review before the assessor goes near anything, and remediation help included — so the audit is a formality, not a gamble.

hello@passcyber.co.uk

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd