Cyber Essentials: what it costs, how long it takes and what the process involves
Cyber Essentials is the UK government-backed cyber security certification, and if you are researching it you probably have three questions: what does it cost, how long does it take, and what actually happens. As a Certification Body we assess organisations against the scheme, so here are the straight answers, including the ones most articles avoid.

Cyber Essentials is the UK government-backed certification scheme for cyber security, developed by the National Cyber Security Centre and administered by IASME. It certifies that an organisation has five fundamental technical controls in place: firewalls, secure configuration, access control, malware protection and security update management.
If you are reading this, you are probably weighing up whether to certify, and you want three things most articles on the subject dance around: the cost, the timescale and what actually happens. We are a Cyber Essentials Certification Body, which means our assessors mark the assessments, so we see this process from the side most guides never mention. Here are the straight answers.
Cyber Essentials vs Cyber Essentials Plus: the difference in one paragraph
Cyber Essentials is a verified self-assessment. You answer a structured question set about your organisation's controls, a board-level person signs to confirm the answers are accurate, and a qualified assessor reviews the submission. Cyber Essentials Plus covers the same five controls but adds independent technical testing: an assessor scans and examines a sample of your actual systems to verify that what you declared is really in place. Put simply, Cyber Essentials proves you say the right things; Plus proves your systems do them. Plus requires the base certification first, and the Plus audit must be completed within three months of it, otherwise you start again.
What does Cyber Essentials cost?
The honest answer has three parts, and the third one is the part that matters.
First, the assessment fee. This is set by IASME and scales with organisation size, so a five-person firm and a five-hundred-person trust pay different amounts. It is the smallest and most predictable part of the total.
Second, the Plus audit, if you need it. Because Plus involves hands-on technical testing by a qualified assessor, its cost depends on the size and complexity of what is in scope: how many devices, sites and servers, and how your network is arranged. Any Certification Body will quote this from your specifics rather than a price list, and you should be suspicious of one that does not ask questions first.
Third, and this is the part almost nobody prices: remediation. The real cost of Cyber Essentials is not the assessment, it is closing the gap between where your systems are and where the scheme requires them to be. For an organisation with well-managed, current systems, that gap can be close to zero and certification is cheap. For an organisation with unsupported software, no multi-factor authentication and unmanaged devices, remediation is the project and the assessment fee is a rounding error. This is why "how much does Cyber Essentials cost" has no universal answer, and why anyone who gives you one number without looking at your environment is guessing.
The practical move is to find out the size of your gap before you commit to anything. Get in touch and we will scope it with you, including an honest view on whether you are ready to go straight to assessment or have remediation to do first.
How long does Cyber Essentials take?
There are two clocks, and conflating them is how people end up with unrealistic plans.
The certification clock is short and predictable. Once your assessment account is created you have up to six months to submit. An assessor reviews your submission within three working days, and if clarification is needed, each resubmission is reviewed within three working days too. When your answers meet the requirements, the certificate is issued immediately. A well-prepared organisation can go from starting the question set to certified inside a fortnight.
The readiness clock is the variable one, and it is the same variable as the cost: the size of your remediation gap. Organisations with current, well-managed estates need days of preparation. Organisations that discover unsupported software, missing MFA or unpatched systems partway through the question set need weeks or months, because remediation, not paperwork, is the bottleneck.
For Plus, add scheduling reality: the audit itself typically takes a working day, but it has to be booked, done within three months of the base certificate, and passed with your declared scope, which cannot be shrunk between the two assessments to hide problem devices.
Our CTO Tom Goldsmith, whose team oversees our assessments, puts the most common failure pattern bluntly: "Organisations underestimate the seriousness of the accreditation. They want to review the accreditation rather than implement the actual standard." In other words, the applicants who struggle are the ones treating the question set as paperwork to be worded correctly instead of controls to be genuinely in place, and the scheme is specifically designed to catch that. It is also why our approach is that you pass and you are actually secure, in that order of difficulty and the reverse order of importance.
What the process actually involves
From the assessor's side of the desk, certification runs like this. You download and prepare against the current question set before paying for anything, which costs nothing and tells you most of what you need to know about your readiness. You purchase the assessment, sized to your organisation, and get access to the portal. You complete the question set, a board-level signatory confirms the answers, and you submit. The assessor reviews within three working days and either certifies you or comes back with specific points to address. You fix, resubmit, and each round is reviewed within three working days until you pass. For Plus, an audit is then scheduled within the three-month window: vulnerability scans and hands-on checks against a sample of your devices, your internet gateways and any internet-facing servers.
Two parts of that catch people out. The scope declaration at the start decides everything that follows, and getting it wrong is expensive in both directions: too narrow and the certificate may not satisfy the contract that prompted it, too broad and you are remediating machines that did not need to be in scope. And the board-level sign-off is contractual, not ceremonial. The person signing is confirming the answers are true, which is exactly why the scheme has teeth.
What changed in April 2026, and why it raises the bar
The scheme is updated every year, and the current version, which applies to all assessments purchased from 27 April 2026, made two changes that matter to almost everyone.
Cloud services can no longer be excluded from scope. If your organisation's data or services live in cloud platforms, those services are assessed. For most organisations that means email, file storage, finance systems and line-of-business platforms are all in, because that is where the data actually is now. For schools and trusts, it pulls in the MIS and safeguarding systems too.
Multi-factor authentication is now required wherever cloud services support it, and its absence is an automatic fail. If MFA has been sitting on your to-do list, the scheme has just done you the favour of making the decision for you.
The practical effect of both changes: certifying against the current scheme is a genuinely stronger signal than it was two years ago, and organisations that certified easily in the past should not assume renewal will be equally easy. Renewals are assessed against the current requirements, not the ones you passed last time.
Who actually needs Cyber Essentials?
Some organisations are required to hold it: colleges must certify under their funding agreement, and a growing set of public sector contracts, defence work and enterprise supply chains specify Cyber Essentials or Plus as a condition of doing business. If a tender or a client questionnaire has prompted your research, check the exact wording, because whether it says Cyber Essentials or Cyber Essentials Plus changes your cost and timeline materially.
For everyone else it is a choice, and our honest framing is this: the five controls are things a well-run organisation should have regardless, so the real question is whether the certificate itself has value to you. It does if you sell to organisations that ask about security, if you want independently verifiable evidence of your baseline for insurers and boards, or if you are a school or trust reading the direction of travel, which we covered in our article on the DfE digital and technology standards. If none of those apply, implement the controls anyway and certify when a contract makes it worthwhile.
Where to start
The zero-cost first step is a gap review against the current question set. We do this with organisations before they spend anything on assessment: a structured look at your environment against the five controls, what is already in place, what needs remediation, and a realistic view of your timeline for base certification or Plus. Because we are the Certification Body as well as an IT provider, we can also carry out the remediation, though the gap review stands on its own and you own the findings either way.
Book a Cyber Essentials gap review
Frequently asked questions
How much does Cyber Essentials cost?
The assessment fee is set by IASME and scales with organisation size. The larger and less predictable cost is remediation: closing the gaps between your current systems and the scheme's requirements. Well-managed organisations may have almost nothing to fix; others should budget for the remediation project rather than the certificate.
How long does Cyber Essentials take?
A well-prepared organisation can be certified within a fortnight: you have up to six months to submit once your assessment account is created, submissions are reviewed within three working days, and certificates are issued immediately on a pass. Preparation and remediation time is the real variable, ranging from days to months depending on your starting position.
Do I need Cyber Essentials or Cyber Essentials Plus?
Check what your contract, tender or client actually specifies. Plus adds independent technical testing of your systems and is increasingly required for defence, public sector and enterprise supply chains. Plus requires the base certification first, with the audit completed within three months of it.
Is Cyber Essentials a legal requirement?
No. It is mandatory for colleges under their funding agreement and contractually required in many tenders and supply chains, but there is no general legal obligation. For schools, it is not yet required, though the DfE's cyber security standard maps closely onto the Cyber Essentials controls.
Want advice specific to your organisation?
Articles are useful, but nothing beats a conversation about your actual setup. Start with a free health check.