Three buckets determine your total. First, the fixed IASME assessment fee, non-negotiable and identical everywhere, so any quote above it is buying services, not a better certificate. Second, optional guided support: readiness reviews, answer-drafting help, and pre-submission checks, worth paying for if you lack time or confidence, especially under the stricter 2026 rules. Third, remediation: the engineering work of enforcing MFA, fixing patching, separating admin accounts and retiring unsupported systems.
For a well-run modern SME, bucket three is often near zero, the controls are configuration, not purchases. For organisations carrying legacy systems or no device management, it is the dominant cost, and no certification provider can honestly quote it without looking at your estate first.
If a provider's price is above the IASME fee, ask precisely what the difference buys. Good answers exist, readiness reviews and remediation help have real value, but the certificate itself costs the same everywhere.
Most certification budgets go wrong in predictable places. Failed submissions cost time and sometimes a fresh fee. Unsupported software discovered late forces unplanned upgrades on a deadline. Cyber Essentials Plus quotes balloon when device estates turn out messier than described. And internal time, the hours your team spends gathering asset lists and answers, is real money nobody itemises.
The 2026 rules raised the stakes: automatic failures for missing MFA and late patching mean optimistic answers no longer squeak through. Budgeting a modest amount for a pre-submission review is consistently cheaper than budgeting nothing and failing.
The cheapest certification is the one you pass first time, with remediation done calmly before submission rather than urgently after a failure.
The IASME-set assessment fee for Cyber Essentials (verified self-assessment). Identical through every Certification Body. Cyber Essentials Plus is quoted separately by each body based on scope.
| Organisation size | Employees | Cyber Essentials fee | Typical CE Plus range* |
|---|---|---|---|
| Micro | 0–9 | £320 + VAT | £1,400–£1,900 + VAT |
| Small | 10–49 | £440 + VAT | £1,700–£2,600 + VAT |
| Medium | 50–249 | £500 + VAT | £2,400–£4,000 + VAT |
| Large | 250+ | £600 + VAT | £3,500+ + VAT (scope-dependent) |
*CE Plus market ranges are indicative for typical UK estates as of July 2026; the audited tier is priced by each Certification Body based on device sample, sites and build complexity. Verify current IASME fees at iasme.co.uk before purchasing.
What organisations actually spend in year one, official fee plus typical remediation and support, based on estate condition.
| Scenario | Assessment fee | Remediation & support | Realistic year-one total |
|---|---|---|---|
| Modern micro business (M365, current laptops, MFA already on) | £320 + VAT | £0–£300 | £320–£620 + VAT |
| Typical small business, some gaps (MFA partial, mixed patching) | £440 + VAT | £500–£2,000 | £940–£2,440 + VAT |
| Medium organisation with legacy systems or no device management | £500 + VAT | £2,000–£10,000+ | £2,500–£10,500+ + VAT |
| Adding Cyber Essentials Plus (any size) | CE fee + CB audit quote | £1,400–£4,000+ audit | CE total + audit fee |
Indicative UK market ranges, July 2026. Remediation is estate-dependent; treat any provider quoting it without seeing your environment with suspicion.
Register your interest and receive our fixed-price rate card, assessment, readiness support and Plus, the day our certification service launches.