Finance wants a number. Procurement wants the certificate before the bid closes. Somebody searches for a price, finds four different figures on four different pages, and comes back none the wiser.
Cyber Essentials costs between £320 and £600 plus VAT in 2026, depending on headcount. IASME charges £320 for micro organisations, £440 for small, £500 for medium and £600 for large. That fee covers the assessment only. Most UK firms spend more on the remediation work needed to pass first time.
What Does Cyber Essentials Cost in 2026?
The assessment fee is set by IASME, the delivery partner for the Cyber Essentials scheme, and it is identical whichever of the 400 or so certification bodies you go through. The tier is decided by employee count, not turnover.
- Micro, 0 to 9 employees: £320 plus VAT
- Small, 10 to 49 employees: £440 plus VAT
- Medium, 50 to 249 employees: £500 plus VAT
- Large, 250 or more employees: £600 plus VAT
Any quote above those figures includes a certification body’s own consultancy on top of the IASME fee. There is no discount for certifying part of the business, because the scope has to cover the whole organisation for the certificate to carry weight with a buyer.
Why Is the Fee Only Half the Number?
Because the fee buys an assessment, not a pass. The second half of the Cyber Essentials cost is the work needed to answer the question set honestly, and that is the half Transputec sees catch people out.
A £320 fee is trivial against a tender worth six figures. Three weeks of unplanned work to retire unsupported software, roll out multi-factor authentication and get device configuration under control is not trivial, particularly when the submission date is already fixed.
The gap between the two halves varies enormously. A business with centrally managed devices, current operating systems and multi-factor authentication already switched on may spend nothing beyond the fee. A business that has not looked at its estate in three years can spend twenty times the fee before it is ready to submit.
What follows sets out both halves in plain numbers, so you can budget properly rather than discovering the real figure two days before the deadline.
Is Your Estate Ready for the Five Controls?
Cyber Essentials tests firewalls, secure configuration, update management, user access control and malware protection. Those are the things Transputec manages day to day. Tell us what your estate looks like and we will tell you where it stands against those five controls, so the readiness work is not a surprise when you apply.
Get a Strategic ConsultationWhat Is the Cyber Essentials Cost by Company Size?
The Cyber Essentials cost in 2026 is a tiered assessment fee from £320 to £600 plus VAT, banded by employee count. The fee buys one assessment cycle and is the same through every certification body.
| Organisation size | Employees | IASME fee 2026 |
|---|---|---|
| Micro | 0 to 9 | £320 + VAT |
| Small | 10 to 49 | £440 + VAT |
| Medium | 50 to 249 | £500 + VAT |
| Large | 250 or more | £600 + VAT |
The bands use the UK government definition of organisation size. Counting is by employees, so a twelve person business with £30m of revenue still pays the small organisation rate.
The audited tier is priced differently. We cover that separately in our guide to Cyber Essentials Plus, because it is quoted individually rather than banded and mixing the two misleads more than it helps.
What Does the Certification Fee Actually Buy?
The Cyber Essentials certification fee covers one assessment of the verified self-assessment questionnaire, marking by a qualified assessor, and the certificate itself if you pass. For smaller organisations it also unlocks cyber liability insurance at no extra charge.
Paying the fee gives you:
- Portal access to the online assessment, valid for six months from application.
- One marked submission by an assessor, with results typically returned within three working days.
- A two working day window to correct simple issues and be re-marked at no extra charge.
- The certificate and use of the Cyber Essentials badge for twelve months.
- Cyber liability insurance with a £25,000 limit of indemnity, where turnover is under £20m, the organisation is domiciled in the UK or Crown Dependencies, the whole organisation is certified and you opt in.
The insurance carries 24/7 incident response support alongside the indemnity. For a business with no existing cyber cover, that changes how the certification reads on a spreadsheet.
What the fee does not include is help getting ready. The question set and the readiness tool are both free to download from IASME, but interpreting them against a real estate is where most organisations need support.
Why Is the Real Cost Higher Than the Certification Fee?
The real figure is higher because passing requires the five controls to be genuinely in place across every in-scope device, and most organisations have gaps they have not priced. A board member signs the declaration, so the answers have to be true.
The gaps that generate unplanned spend most often:
- Unsupported software anywhere in scope. This is an automatic fail. Windows 10 reached end of support on 14 October 2025, so any remaining Windows 10 device without extended security updates will sink an application on its own.
- Multi-factor authentication missing on cloud services and administrative accounts.
- No central configuration or update management, which makes the security update questions impossible to evidence honestly.
- Personally owned devices reaching organisational data with no policy or controls around them.
- Firewall rules nobody has reviewed since the last office move, and open services that should have been closed years ago.
None of those are exotic. All of them take time and, usually, licences or hardware. A twelve person consultancy replacing four end-of-life laptops and adding multi-factor authentication across Microsoft 365 will spend well beyond £440, and the assessment fee was never the expensive part.
A worked example makes the shape of it clearer. Take a 30 person professional services firm with 35 laptops, of which six are still on Windows 10, no mobile device management, and multi-factor authentication switched on for email but not for the finance system.
- Assessment fee: £440 plus VAT, fixed.
- Six replacement laptops: the single largest line, and the one with no shortcut.
- Device management licensing: a per-user monthly cost that continues after certification, so it belongs in the operating budget rather than the project.
- Internal time: typically the most underestimated item. Scoping, evidence gathering and answering assessor queries pulls somebody away from their day job for the better part of a fortnight.
The fee is under two per cent of that total. Any budget request built around the published figure alone will need revisiting, which is usually a worse conversation than asking for the right number at the start.
What Happens If You Fail the Assessment?
If you fail, you get two working days to fix simple issues and be re-marked for free. Miss that window and you reapply and pay the full fee again, so a failed attempt can double your Cyber Essentials cost.
Two working days is short by design. It is enough time to correct a policy, tighten a setting or supply evidence the assessor asked for. It is not enough time to procure hardware, migrate an operating system or negotiate a licence uplift. Treating it as a safety net is how organisations end up paying twice.
There is a second deadline worth noting. You have six months from application to submit, after which the account may be closed with no refund. Paying early to secure budget and then letting the work drift is a common and avoidable way to lose the fee.
Scope is the other quiet source of failure. The certificate has to cover the whole organisation, which means every device that touches organisational data: home workers’ laptops, personal phones used for email, and the cloud services nobody in IT formally owns. Scoping narrowly to save effort usually ends with the assessor pulling the wider estate back in, at which point the saving has evaporated.
One softer cost rarely gets counted. Where an assessor cannot mark an answer because there is not enough detail, the submission comes back for clarification. Each round trip adds a few days and another block of internal time, and two or three of those turn a fortnight into a month. Writing fuller answers first time is free, and it is the cheapest saving available anywhere in this process.
Is Cyber Essentials Worth the Money?
For any UK organisation bidding for public sector work, Cyber Essentials is worth the money because it is frequently a condition of entry rather than a differentiator. Procurement Policy Note 09/23 requires it across a large number of central government contracts, and the Ministry of Defence requires it throughout its supply chain wherever defence information is handled.
Outside the public sector the calculation is commercial. Large enterprises ask for it in supplier due diligence questionnaires, insurers ask about the same five controls when pricing cyber cover, and holding the certificate shortens both conversations considerably.
Cyber Essentials for small business buyers carries a second benefit larger firms cannot claim. Under £20m turnover, with the whole organisation certified, the included insurance and incident response support arrive at no extra charge. Priced on the open market that cover alone would usually exceed the assessment fee.
Transputec holds Cyber Essentials Plus alongside ISO 9001, ISO/IEC 27001 and ISO 14001, and is a named supplier on the Crown Commercial Service TePAS 2 framework and G-Cloud 14. Our current certifications are maintained for exactly these reasons, not recommended from a distance.
How Do You Keep the Cyber Essentials Cost Down?
You keep the total down by doing the readiness work before you pay, not after. The fee is fixed, so every pound of avoidable spend sits in remediation, failed attempts and rushed procurement.
A sequence that works:
- Answer the question set first. It is free to download. Work through it honestly against your current estate before spending anything.
- Run the readiness tool to produce a tailored action plan.
- Build an accurate inventory of devices and cloud services. Scope disputes and forgotten laptops cause more failures than technical weakness does.
- Retire or replace anything unsupported first, because it is the one issue with no workaround.
- Close the remaining control gaps, then apply and submit while the evidence is still current.
Organisations already on managed IT services with centrally managed patching, multi-factor authentication and device configuration tend to find readiness cheap, because the controls already run as business as usual. Organisations doing it once a year from a standing start tend to find it expensive. That difference, rather than the fee, is what determines your total bill.
Timing matters as much as preparation. Applying three weeks before a tender deadline removes every cheap option, because procurement, licensing and migration all take longer than the two day re-mark window allows. Applying three months out lets you fix problems in the order that suits your budget rather than the order the assessor finds them. Our IT services cost calculator is a useful starting point when you are scoping the wider support budget around it.
Conclusion
Budget £320 to £600 plus VAT for the assessment, then budget properly for the work behind it. The published Cyber Essentials cost is the easy half: fixed, predictable and identical through every certification body. The readiness effort is neither, and it decides whether you pass first time or pay twice.
The organisations that find this straightforward treat the five controls as ongoing operational hygiene rather than an annual scramble. Unsupported software is retired on a schedule. Multi-factor authentication is already everywhere. Device configuration is managed centrally and can be evidenced on request. For them the yearly recertification is a form-filling exercise, and the fee is genuinely the whole expense.
Getting to that position is an IT estate problem rather than a paperwork one. Transputec keeps those five controls running as business as usual through cyber security services and day-to-day managed IT. If you are not sure where your estate stands against them, talk to our UK team.
FAQs
How Much Does Cyber Essentials Cost for Small Business Buyers?
A small business with 10 to 49 employees pays £440 plus VAT for the IASME assessment in 2026, and a micro business with fewer than 10 employees pays £320 plus VAT. Those fees cover the assessment only. Budget separately for any remediation needed to pass, which is usually the larger number.
What Is Included in the Cyber Essentials Certification Fee?
The fee covers portal access for six months, one assessor-marked submission, a free re-mark within two working days if you fail, and the certificate for twelve months if you pass. It also includes cyber liability insurance with a £25,000 limit for organisations under £20m turnover that certify the whole organisation and opt in.
Is Cyber Essentials Worth the Money?
Yes for most UK organisations selling to government, enterprise or regulated sectors, because it is often a condition of bidding rather than an advantage. Procurement Policy Note 09/23 requires it for many central government contracts. The certificate also shortens supplier due diligence and insurance conversations.
Does the Cyber Essentials Price Include Cyber Essentials Plus?
No. Cyber Essentials Plus is quoted separately, because it adds a technical audit priced on the size and complexity of your network. Certifying to the audited tier within three months of the base certificate lets you skip the self-assessment stage, which keeps the combined cost lower.
How Often Do You Have to Renew Cyber Essentials?
Every twelve months. Both certificates expire after a year and IASME removes lapsed organisations from its certified list. Keeping the five controls running continuously is what makes renewal cheap, which is why patching, device configuration and access control are better handled inside managed IT services than rebuilt from scratch each year.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



