The advertised price of Cyber Essentials is one of the most misleading numbers in small-business IT: a few hundred pounds, prominently displayed, technically true. It is the assessment fee, and for a business whose systems already meet the standard, it really is most of the bill. For everyone else (which is most first-time applicants) the assessment fee is the ticket price, and the journey costs more.

This guide gives you the whole picture: the official fee bands, what Plus adds, what preparation and remediation genuinely cost at different starting points, and the realistic first-year totals to put in a budget. All figures are 2026, UK, excluding VAT.

The assessment fees (the official bit)

Cyber Essentials assessment is priced by IASME in bands based on organisation size:

The fee buys the assessment portal, the self-assessment questionnaire, one assessor review, one free resubmission within 48 hours of feedback, the certificate on passing, and (for eligible smaller organisations) the scheme’s included cyber liability insurance. Certification lasts twelve months, and the fee repeats annually at renewal.

Cyber Essentials Plus adds an independent technical audit priced by device count rather than headcount: typically £1,500 to £2,500 for estates up to about 20 devices, rising through £2,500 to £4,000 for 21 to 50 devices and onwards with scale. Basic certification is a prerequisite, so Plus budgets always include both fees. (Which level you need is a contracts question, not a budget one; our Essentials vs Plus comparison settles it.)

The real cost: getting ready to pass

The five controls are not exotic, but they are absolute: one cloud account without MFA, one unsupported operating system in scope, and the assessment fails (the current question set is strict about this; the checklist covers each control’s requirements). Preparation cost is therefore entirely a function of your starting point, and it falls into recognisable tiers:

Already well-managed (cost: little beyond the fee)

Businesses on a proper managed IT service usually find the controls are already how their systems run: MFA enforced, patching automated, unsupported software gone, admin accounts separated. Certification becomes a documentation exercise, and this is the honest reason MSP clients certify cheaply: the preparation was amortised into normal service. The gap analysis still matters (it catches the forgotten scope items), but remediation is minimal.

Typical unmanaged SME (£1,000–£3,000 of work)

The common case: decent modern systems, accumulated gaps. A gap analysis (commercially £750 to £1,500 when bought standalone), then remediation labour of £500 to £3,000 covering the usual suspects: rolling out MFA everywhere, sorting admin account separation, removing or upgrading stray unsupported software, tightening firewall and device configurations, and evidencing a 14-day patching mechanism. Some fixes add small recurring tooling costs (patch management or endpoint protection at a few pounds per user per month) that you arguably should have been paying anyway.

Ageing estate (the budget-breaker tier)

Where old hardware and unsupported operating systems dominate, Cyber Essentials stops being a certification cost and becomes an overdue refresh brought forward: replacement machines at normal business-PC prices, plus the work above. Businesses still running Windows 10 without extended updates meet this tier head-on (our Windows 10 end-of-support guide covers that specific arithmetic). The certificate did not create these costs; it surfaced them with a deadline.

Realistic first-year totals

Putting the tiers together, sensible budget figures for first-time certification:

One caution on comparing quotes for preparation help: cheap fixed-fee “guaranteed pass” offers sometimes mean the questionnaire gets answered creatively rather than the systems fixed. A board member signs that declaration; buy the version where the controls genuinely operate.

Is it worth the money?

Three ways the spend pays back. Commercially: certification unlocks tenders and satisfies the client and insurer questionnaires that increasingly gate work; one retained contract usually dwarfs the cost. On risk: the five controls block the commodity attacks that actually hit SMEs, and the preparation is a forced upgrade of your real security, not paperwork. On insurance: basic certification through the scheme includes cyber liability cover for eligible smaller organisations, and certified businesses commonly see easier renewals. The businesses for whom it is *not* worth it are those with no client, insurer or tender pressure and already-excellent security; they exist, but they are rarer than they believe.

Frequently asked questions

How much does Cyber Essentials cost in 2026?

The assessment fee runs from about £300 for micro businesses to £600 for large ones, +VAT. Realistic first-year totals including preparation are £1,500 to £3,500 for a typical SME; already-well-managed businesses pay little beyond the fee.

How much does Cyber Essentials Plus cost?

The basic fee plus a device-count-priced audit: typically £1,500 to £2,500 for small estates, more as device numbers rise, plus whatever the audit’s findings cost to fix. Budget £3,500 to £7,000 all-in for a typical SME’s first Plus.

Is there a yearly cost?

Yes: certification expires after twelve months, so the assessment fee recurs, plus a pre-renewal check that the controls still hold (requirements also evolve between years). Maintained systems make renewal cheap; neglected ones repeat year one.

Are there grants or funded support for Cyber Essentials in Scotland?

Funded support schemes and vouchers have existed at various times through Scottish public bodies, with availability changing year to year. Worth checking current schemes before you start; we track what is live as part of certification engagements.

What makes the cost jump?

Unsupported operating systems and hardware, MFA gaps across many cloud services, and estates with no patching mechanism: the three findings that turn remediation from days into a project. The gap analysis prices all of it before you commit a penny to fixes.

Can we do it ourselves and skip the preparation costs?

You can: pay the fee, answer honestly, fix what you find. The risk is discovering structural failures mid-questionnaire with a tender deadline looming. Self-serve suits businesses with time and confidence; bought preparation suits businesses with deadlines.

Get your number, not the internet’s

Every figure above is a band; your business has an actual number, and it takes a gap analysis to find it. Ours comes wrapped in the free IT health check: your systems audited against all five controls, findings in plain English, and a fixed quote for exactly what stands between you and the certificate. Get in touch, and if a deadline is driving this, lead with the date. Our certification support takes it from there.