The certification fee is the small, predictable part. The real number — the one nobody quotes up front — is the work to get you ready to pass. Here’s both, honestly.
Published: 2 July 2026
Ask “how much does Cyber Essentials cost?” and most answers give you the assessment fee and stop there. That’s honest as far as it goes — but it’s like quoting the cost of a driving test without mentioning the lessons. The full picture has three parts: the certification fee, the optional Plus audit, and the remediation work to bring your systems up to the standard. Only the first one has a price tag you can look up.
Basic Cyber Essentials is a verified self-assessment, and the fee is set by IASME (who run the scheme for the government), banded by organisation size. At the time of writing, expect roughly £300–£350 + VAT for a micro organisation (under 10 people), around £400–£450 for a small one (10–49), £450–£500 for a medium (50–249) and £500–£600 for large. Certification bodies — the companies licensed to assess you — can price a little either side of that, so it’s worth checking the current figures rather than trusting any blog, including this one.
For a typical SME, then: the certificate itself costs about as much as a decent office chair. If that were the whole story, everyone would have one.
Plus covers the same five control areas but adds an independent technical audit — an assessor actually tests a sample of your devices, checks your builds and verifies the controls really exist. Pricing isn’t fixed the way the basic fee is: it depends on your size, number of locations and device sample, but for most SMEs it lands somewhere between £1,400 and £2,500+, on top of the basic certification (which you need first, within three months).
Is it worth the difference? If a contract, framework or insurer specifically asks for Plus — increasingly common in defence supply chains and public-sector work — then yes, because nothing else satisfies the requirement. If nobody is asking, the honest answer is that basic certification plus genuinely maintained controls beats a Plus badge on top of drifting ones.
Here’s the part the fee-only articles skip. Cyber Essentials requires every in-scope device to run supported software, users without admin rights for daily work, MFA on cloud services, firewalls configured properly and malware protection everywhere. If your environment already meets that, remediation costs you nothing. Most environments we assess don’t.
The common gaps, and what they really mean: a handful of machines on an out-of-support Windows version (replacement or upgrade — potentially hundreds of pounds per device); staff working day-to-day with local admin rights (engineering time to remove safely without breaking the awkward application that caused it); no MFA on email or cloud services (rollout effort and user wrangling more than licence cost); an internet router with the default config from whoever installed the broadband (a proper firewall review); unmanaged personal devices reading company email (policy decisions before technical ones).
That’s why quoting remediation without an assessment is guesswork. For one business it’s a quiet afternoon; for another it’s several thousand pounds of catch-up spending — usually accumulated over years of “we’ll sort that later”. Anyone who quotes you a flat remediation price before looking at your environment is guessing with your money.
Certification lasts twelve months. The renewal fee is the same banded assessment fee each year — but the meaningful annual cost is keeping the controls true between certificates. A business that lets things drift for eleven months buys itself a small remediation project every renewal; a business whose IT is managed to the standard continuously finds renewal is mostly paperwork. Over three years, the second business pays less in total and is safer the whole time.
Genuinely, sometimes yes. If you’re a small, cloud-only business with modern devices, no server room and a competent IT-literate owner, the self-assessment is within reach: read the requirements carefully, fix what falls short, answer truthfully. The scheme was designed to be accessible and we’d rather tell you that than pretend otherwise.
Where DIY goes wrong is scale and honesty. As soon as there are more than a dozen devices, legacy kit, or nobody with time to actually do the fixing, the questionnaire becomes a list of things you now know are broken. And the worst outcome isn’t failing — it’s passing by answering generously, which leaves you with a certificate that misdescribes your real position. If that’s ever tested by an insurer after an incident, the generous answers become the problem.
Our approach is different, and it’s the honest reason this article exists: for NorthMSP managed clients, Cyber Essentials — the remediation and the certification — is built into onboarding, with no upfront project fee. The onboarding assessment scopes exactly what your environment needs, the work is amortised into the monthly service rather than billed as a surprise project, and the controls are then maintained continuously so renewal stays boring. (Hardware, licensing and larger transformation projects are scoped and quoted separately — we’d rather say that plainly than hide it.)
The certificate costs a few hundred pounds. Readiness costs whatever your environment has been quietly accumulating. The cheapest version of Cyber Essentials is the one where your IT was being run to the standard all along.
Want to know where you stand before spending anything? Our free Cyber Essentials readiness check gives you an honest read in a couple of minutes, or see how our certification support and secure onboarding fit together.
The certificate is the easy part. A free health check tells you what remediation you’d actually be looking at — in writing, with no obligation.