Cyber Essentials Cost Breakdown for Small Businesses

Cyber Essentials Cost Breakdown for Small Businesses

By EJN Labs · 23 Jun 2026 · 11 min read

Cyber Essentials with EJN Labs is a fixed £400 plus VAT for managed certification, or £600 plus VAT with consultancy support and 48-hour expedited certification. Cyber Essentials Plus adds an independent hands-on technical audit, from £1,200 to £3,500 plus VAT for organisations of 50 to 250 employees and £3,500+ for larger or complex cloud estates, depending on the number of devices, servers and cloud services in scope.

The Cyber Essentials cost question is straightforward for the base certificate and far less obvious for the Plus level, where an assessor actually tests your systems. This guide breaks down both for a small UK business in 2026: the fixed managed certification fee, what Cyber Essentials Plus adds, how long each takes, and the hidden remediation costs that catch most first-time applicants off guard. For the technical audit that underpins Cyber Essentials Plus, see our Cyber Essentials Plus certification page.

Cyber Essentials cost: the fixed certification fee

Cyber Essentials is a UK government-backed scheme owned by the National Cyber Security Centre (NCSC) and delivered by IASME, its sole accreditation body. With EJN Labs the base certificate is a fixed managed price rather than a fee you administer yourself. As an active IASME Cyber Essentials Certification Body, we manage the whole certification end to end: £400 plus VAT covers submission and direct liaison with IASME, for organisations already confident they meet the five controls. If you want help getting there, the consultancy option at £600 plus VAT adds targeted gap analysis and hands-on remediation guidance, with certification expedited within 48 hours where other providers take five to eight days. Most managed certifications complete in two to four working days.

Cyber Essentials optionWhat it coversCost (2026)
Managed certificationWe handle submission and direct liaison with IASME; best if you already meet the five controls£400 + VAT
With consultancy and expedited certificationManaged certification plus targeted gap analysis and hands-on remediation guidance, certified within 48 hours£600 + VAT
EJN Labs fixed Cyber Essentials prices for 2026. One flat price regardless of headcount; the IASME certification fee is included in the managed service.

For most small businesses the managed £400 plus VAT option is the relevant Cyber Essentials cost. It covers submission of the self-assessment and our management of the certification end to end. It does not cover any remediation you need to do to pass the controls, or the separate Plus audit. If you would rather have expert support completing the controls and a faster turnaround, the £600 plus VAT consultancy option folds that in and certifies you within 48 hours.

Cyber Essentials vs Cyber Essentials Plus cost

The single biggest driver of total Cyber Essentials cost is whether you need the base certificate or Cyber Essentials Plus. The base level is a self-declared questionnaire that you complete and an assessor reviews. Cyber Essentials Plus keeps the same five technical controls but adds an independent, hands-on technical audit carried out by a qualified assessor: the controls are tested on a sample of your actual devices and cloud services rather than self-declared. That audit is real work by a real engineer, so it is priced as its own banded service rather than the flat base fee.

A useful guide for a small UK business in 2026: the managed base certificate is £400 plus VAT, and Cyber Essentials Plus runs from £1,200 to £3,500 plus VAT for organisations of 50 to 250 employees, rising to £3,500+ for larger teams or complex cloud estates. The Plus figure scales with the size of your device estate and cloud footprint, which is why scope matters so much. Cyber Essentials Plus builds on the base self-assessment, so you hold the base certificate, or achieve it at the same time, as part of the Plus engagement. Plus certification typically completes in five to fifteen working days end to end.

LevelWhat it involvesCost (2026)
Cyber EssentialsManaged self-assessment certification, handled end to endFrom £400 + VAT
Cyber Essentials PlusIndependent hands-on technical audit of all five controls on a device sample, plus boundary and internal vulnerability scans£1,200 to £3,500 + VAT (50 to 250 employees); £3,500+ for 250+ or complex cloud
EJN Labs fixed prices for 2026. The Plus fee scales with the number of devices, servers and cloud services in scope and is confirmed in writing after scoping.

What drives the Cyber Essentials Plus audit fee

Effort drives the Cyber Essentials Plus audit fee. The assessor must authenticate to a representative sample of your endpoints, run an internal vulnerability scan, attempt the malware and email-attachment tests, and verify that the five controls hold in practice, so the bigger and more varied your estate, the larger the sample and the longer the audit.

Unlike the base fee, the Plus price is therefore built from effort, much like a focused security assessment, and these estate factors are what move the figure within the range above.

Number of devices and the sample size

The audit tests a sample of your in-scope devices rather than every machine, but the sample grows with your fleet, especially where you run several operating systems or device types. A handful of identical Windows laptops is quick; a mix of Windows, macOS, mobile devices and a couple of servers takes longer because each platform needs its own checks. More devices in the sample means more audit time and a higher fee.

Operating system and device diversity

A homogeneous estate is cheaper to certify than a mixed one. Every distinct operating system version, build and configuration baseline in the sample typically adds checks, because the malware protection, patching and account-separation controls behave differently across platforms. Businesses that have standardised on one managed device image tend to sit at the lower end of the Plus audit range; those with bring-your-own-device or a long tail of legacy machines sit higher.

Cloud services and remote workers

Cyber Essentials now treats cloud services, including software-as-a-service and infrastructure-as-a-service, as firmly in scope, and Plus must verify the controls reach them. Multi-factor authentication on administrative and user accounts, account separation and secure configuration all have to be evidenced across your cloud platforms. A fully remote or hybrid workforce, where home-working devices and personal networks come into scope, can also widen the audit and lift the fee.

Readiness and remediation

The cheapest Plus audit is one you pass first time. If the assessor finds unsupported software, missing patches, weak account separation or absent multi-factor authentication, you have a defined window to fix the issues and re-evidence them. Repeated remediation cycles consume assessor time and can edge the cost up, quite apart from the internal effort. This is why a short readiness review before the formal audit usually pays for itself by avoiding a failed first attempt.

The hidden costs of Cyber Essentials

The certification and audit fees are only part of the true Cyber Essentials cost. The figures most first-time applicants underestimate are the changes they have to make to meet the five controls, plus the time spent completing the assessment correctly. None of these are charged by IASME, but they are real budget lines for a small business.

  • Remediation to pass the controls. Replacing unsupported Windows versions or end-of-life hardware, buying a managed antivirus or endpoint product, or rolling out multi-factor authentication can all cost more than the certificate itself if you are starting from a weak baseline.
  • Multi-factor authentication and password tooling. The scheme expects MFA on cloud services and strong password policies. Licences for a password manager or MFA across your team are a recurring cost, not a one-off.
  • Internal time. Completing the questionnaire accurately, gathering asset inventories and evidencing controls typically takes a competent person one to three days. That time has a cost even when no external help is bought.
  • Consultancy or readiness support. Many small businesses pay a partner to help complete the self-assessment or run a pre-audit readiness check. With EJN Labs that support is the £600 plus VAT consultancy option, and it is separate from the standalone managed fee.
  • Annual recertification. Cyber Essentials lasts twelve months. The fee, and a slimmer version of the internal effort, recur every year, so treat it as an ongoing line rather than a one-time spend.

Cyber Essentials and Cyber Essentials Plus are certifications against a defined baseline, not a penetration test, and they should not be confused with one. A pen test probes for exploitable weaknesses in depth and is scoped and priced as its own engagement; if you also need that level of assurance, our penetration testing cost guide sets out our published UK price ranges by test type. Many regulated buyers hold Cyber Essentials Plus and commission a separate pen test, because the two answer different questions.

How EJN Labs approaches Cyber Essentials Plus

We are an active IASME Cyber Essentials Certification Body and hold Cyber Essentials and Cyber Essentials Plus ourselves, alongside CREST accreditation, ISO 27001 and ISO 9001, so we run the audit from the position of an organisation that lives by the same controls. We start with a short readiness review against the five controls and your device estate, so you go into the formal Plus audit knowing where you stand rather than discovering gaps on the day. That readiness step is the single most reliable way to keep the total Cyber Essentials cost predictable and avoid paying for a second attempt.

Our pricing is fixed against a written scope, agreed up front from your device count, operating-system mix and cloud footprint, so the number you approve is the number you pay. The hands-on audit and any related testing are delivered by UK-based, CREST-certified practitioners. Where remediation is needed, we set out exactly what has to change and re-evidence the fix without surprise charges. You can see how the Plus audit fits our wider work on our services overview, and the dedicated Cyber Essentials Plus certification page covers the audit method in detail.

Frequently Asked Questions

How much does Cyber Essentials cost for a small business in 2026?

Cyber Essentials costs a fixed £400 plus VAT with EJN Labs for managed certification, or £600 plus VAT with consultancy support and 48-hour expedited certification. Cyber Essentials Plus adds an independent technical audit on top, from £1,200 to £3,500 plus VAT for organisations of 50 to 250 employees.

Larger or complex cloud estates pay £3,500+ for the Plus audit, depending on the number of devices, servers and cloud services in scope.

Why is Cyber Essentials Plus more expensive than the base certificate?

Cyber Essentials Plus costs more because it adds a hands-on technical audit carried out by a qualified assessor, with the same five controls tested on a sample of your real devices and cloud services. That audit is chargeable effort that scales with the size of your estate.

The base certificate is a managed self-assessment, fixed at £400 plus VAT, whereas Cyber Essentials Plus is priced from £1,200 plus VAT rather than the flat base fee.

Is the Cyber Essentials fee the same for every provider?

The base fee is consistent, but the Plus fee varies by provider. The underlying IASME certification fee is standardised nationally, while the Cyber Essentials Plus audit fee is set by the individual certifying body and varies with your device count and estate complexity.

EJN Labs packages Cyber Essentials into a fixed managed price of £400 plus VAT, or £600 plus VAT with consultancy, so there are no surprises. Because the Plus audit fee is not fixed nationally, Plus quotes differ between providers while the managed base price does not.

What hidden costs should I budget for beyond the fee?

Budget for remediation to pass the five controls, such as replacing unsupported software, buying managed antivirus or rolling out multi-factor authentication, plus any password and MFA licences. Add one to three days of internal time to complete the assessment accurately.

Also allow for optional readiness or consultancy support and the annual recertification fee, since the certificate lasts twelve months.

Is Cyber Essentials the same as a penetration test?

No, Cyber Essentials is not a penetration test. Cyber Essentials and Cyber Essentials Plus certify your organisation against a defined baseline of five controls, while a penetration test probes for exploitable weaknesses in depth and is scoped and quoted as its own engagement.

Some buyers hold Cyber Essentials Plus and commission a separate pen test because the two answer different assurance questions. Our penetration testing cost guide explains how pen test pricing works.

How long does Cyber Essentials certification last?

Twelve months is the validity period for both Cyber Essentials and Cyber Essentials Plus. You recertify each year, paying the fee again and re-evidencing the controls, so it is best treated as an annual operating cost rather than a one-off purchase.

Maintaining the controls year-round makes each recertification faster and cheaper than the first attempt.

Get a fixed-price Cyber Essentials Plus quote

Tell us your device count, operating-system mix and cloud services, and we will return a fixed-price Cyber Essentials Plus quote after a short scoping call, with a readiness review to keep your total Cyber Essentials cost predictable. No obligation and no sales pipeline, just a clear figure from a CREST-accredited, Cyber Essentials Plus certified team.

Leave a Reply

Your email address will not be published. Required fields are marked *