Cyber Essentials Cost: 2026 Fees Explained

The headline answer: the Cyber Essentials assessment fee is set by IASME, is identical through every Certification Body, and in 2026 ranges from £320 to £600 + VAT depending on your organisation’s size. Everything beyond that, remediation, support, and Cyber Essentials Plus, is where budgets actually vary.

This guide breaks down every cost honestly: the official fee tiers, what the fee includes, what Cyber Essentials Plus really costs and why it varies, and the preparation costs providers rarely mention up front.

RedSecLabs is preparing to offer Cyber Essentials certification services with transparent, fixed pricing. Register your interest to receive our rate card the day we launch.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Get Our Launch Pricing First

Register your interest and we’ll send our transparent Cyber Essentials rate card the day our certification service goes live.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
Official IASME fee tiers · No hidden extras · CE+ pricing explained honestly · 2026 (Danzell) current · Written by practitioners
Who this is for

This page is for you if you’re..

1
Budgeting for first certification
Finance and ops leads who need a defensible number for this year's budget, not a ‘from’ price.
2
Comparing providers
Buyers confused why quotes differ when the certificate is identical, we explain exactly where money goes.
3
Weighing basic vs Plus
Organisations deciding whether contracts justify the step up to the audited tier.

Cyber Essentials Costs, Quick Facts

Last reviewed: 2026-07-21
Official assessment fee
Micro (0–9 staff) £320 + VAT · Small (10–49) £440 + VAT · Medium (50–249) £500 + VAT · Large (250+) £600 + VAT
Who sets it
IASME, the scheme's delivery partner; the fee is the same via every licensed Certification Body
What it includes
Assessment portal access, assessor review of your submission, the certificate and listing, plus £25k cyber liability insurance for eligible UK organisations
Cyber Essentials Plus
Priced by each Certification Body; typically £1,400–£4,000+ VAT for SMEs, driven by device sample size and complexity
The real variable
Remediation: fixing MFA, patching, unsupported systems and access control before you submit
Renewal cost
Same fee tiers annually; well-maintained estates spend little beyond the fee
£320–£600
Official fee range + VAT, by size
£0
Extra software most SMEs need to buy
£1.4k–£4k+
Typical SME range for the Plus audit + VAT
£25,000
Insurance included for eligible organisations

Where the money actually goes

Three buckets determine your total. First, the fixed IASME assessment fee, non-negotiable and identical everywhere, so any quote above it is buying services, not a better certificate. Second, optional guided support: readiness reviews, answer-drafting help, and pre-submission checks, worth paying for if you lack time or confidence, especially under the stricter 2026 rules. Third, remediation: the engineering work of enforcing MFA, fixing patching, separating admin accounts and retiring unsupported systems.

For a well-run modern SME, bucket three is often near zero, the controls are configuration, not purchases. For organisations carrying legacy systems or no device management, it is the dominant cost, and no certification provider can honestly quote it without looking at your estate first.

What's included in the official IASME fee:
Access to the online assessment portal and the current (Danzell) question set
Review and verification of your submission by a qualified assessor
Feedback opportunity for minor clarifications within the marking rules
Your certificate and listing on the NCSC certified-organisations register
£25,000 cyber liability insurance for eligible UK organisations under £20m turnover
Use of the Cyber Essentials badge for the 12-month validity period

If a provider's price is above the IASME fee, ask precisely what the difference buys. Good answers exist, readiness reviews and remediation help have real value, but the certificate itself costs the same everywhere.

The costs nobody puts on the pricing page

Most certification budgets go wrong in predictable places. Failed submissions cost time and sometimes a fresh fee. Unsupported software discovered late forces unplanned upgrades on a deadline. Cyber Essentials Plus quotes balloon when device estates turn out messier than described. And internal time, the hours your team spends gathering asset lists and answers, is real money nobody itemises.

The 2026 rules raised the stakes: automatic failures for missing MFA and late patching mean optimistic answers no longer squeak through. Budgeting a modest amount for a pre-submission review is consistently cheaper than budgeting nothing and failing.

Hidden and underestimated costs to budget for:
Replacing or upgrading unsupported operating systems and software
Staff time: asset inventories, evidence gathering, answering 60+ questions accurately
MDM or endpoint tooling if BYOD is widespread and unmanaged
Trusting outdated fee tables online, several high-ranking guides still quote pre-2024 tiers; the current official fees are £320/£440/£500/£600 + VAT
CE+ device-sample scope creep in unstandardised estates
Rush premiums when a contract deadline forces everything into a fortnight

The cheapest certification is the one you pass first time, with remediation done calmly before submission rather than urgently after a failure.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

Official 2026 fee tiers

The IASME-set assessment fee for Cyber Essentials (verified self-assessment). Identical through every Certification Body. Cyber Essentials Plus is quoted separately by each body based on scope.

Organisation sizeEmployeesCyber Essentials feeTypical CE Plus range*
Micro0–9£320 + VAT£1,400–£1,900 + VAT
Small10–49£440 + VAT£1,700–£2,600 + VAT
Medium50–249£500 + VAT£2,400–£4,000 + VAT
Large250+£600 + VAT£3,500+ + VAT (scope-dependent)

*CE Plus market ranges are indicative for typical UK estates as of July 2026; the audited tier is priced by each Certification Body based on device sample, sites and build complexity. Verify current IASME fees at iasme.co.uk before purchasing.

Realistic year-one budgets

What organisations actually spend in year one, official fee plus typical remediation and support, based on estate condition.

ScenarioAssessment feeRemediation & supportRealistic year-one total
Modern micro business (M365, current laptops, MFA already on)£320 + VAT£0–£300£320–£620 + VAT
Typical small business, some gaps (MFA partial, mixed patching)£440 + VAT£500–£2,000£940–£2,440 + VAT
Medium organisation with legacy systems or no device management£500 + VAT£2,000–£10,000+£2,500–£10,500+ + VAT
Adding Cyber Essentials Plus (any size)CE fee + CB audit quote£1,400–£4,000+ auditCE total + audit fee

Indicative UK market ranges, July 2026. Remediation is estate-dependent; treat any provider quoting it without seeing your environment with suspicion.

Transparent Pricing, From Day One

Register your interest and receive our fixed-price rate card, assessment, readiness support and Plus, the day our certification service launches.

Frequently Asked Questions

Because providers bundle differently. The IASME assessment fee is fixed and identical everywhere; anything above it pays for services, readiness reviews, help drafting answers, remediation support, faster turnaround. Those services have genuine value, but you should always be able to see the fixed fee inside any quote.

The micro tier (£320 + VAT) is already the floor for standard certification. IASME also operates a simplified scheme aimed at the smallest organisations and sole traders; whether it satisfies your contracts depends on what buyers ask for, most procurement language specifies standard Cyber Essentials, so check before choosing it.

The scheme allows minor clarifications within a short window as part of the assessment. Substantive failures, like missing MFA on cloud services, which is an automatic fail under the 2026 rules, generally mean a new assessment and fee. This is the strongest financial argument for a pre-submission review.

Plus adds a real technical audit: an assessor's time running external scans, authenticated scans of sampled devices, and hands-on control testing, typically one to two days of qualified effort for an SME. Price scales with device sample size, number of builds and sites, which is why honest CE+ quotes follow a scoping conversation.

The same fee tier applies annually. Organisations that maintain their controls typically spend little beyond the fee at renewal; costs recur when estates drift, unmanaged SaaS adoption, lapsed patching, staff churn. Budgeting a small annual maintenance effort keeps renewals near the fee floor.

Certification fees are a legitimate business expense for UK organisations in the ordinary course of business, and remediation IT spend follows normal capital/revenue treatment. Confirm specifics with your accountant, we're security practitioners, not tax advisers.
📞 Call us Book a call