Cyber Essentials Certification in the UK: Cost, Requirements and Timeline

Updated 31 July 20267 min read

Cyber Essentials is the UK government-backed baseline for cyber security, and it is mandatory for many public sector contracts. This guide explains what it costs, what the assessment actually asks for, and how UK organisations pass on the first attempt.

What is Cyber Essentials?

Cyber Essentials is a certification scheme created by the National Cyber Security Centre (NCSC) and delivered through IASME. It verifies that an organisation has five fundamental technical controls in place — controls that block the overwhelming majority of common internet-based attacks.

There are two levels. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit, including vulnerability scanning of your devices and a test of your email and web controls.

The five technical controls you must meet

Every question in the assessment maps back to one of these five areas. Scope covers all devices that access organisational data, including home-working laptops and staff mobiles.

  • Firewalls and internet gateways — boundary protection on every device and network in scope.
  • Secure configuration — remove default accounts, unused software and unnecessary services.
  • User access control — least privilege, separate admin accounts and multi-factor authentication on cloud services.
  • Malware protection — anti-malware, allow-listing or sandboxing on every in-scope device.
  • Security update management — supported software only, with high and critical patches applied within 14 days.

How much does Cyber Essentials cost in 2026?

Certification fees are banded by organisation size. Micro organisations (up to 9 staff) sit at the bottom of the range and large organisations (250+) at the top. Cyber Essentials Plus is priced separately because it requires an assessor to carry out hands-on testing.

The certificate fee is rarely the whole cost. Budget for remediation — usually MFA rollout, replacing unsupported operating systems, and tightening patching — plus internal time to evidence the answers. Working with a consultant to pre-assess typically costs less than a failed Plus audit and a re-test.

  • Cyber Essentials (self-assessment): a few hundred pounds, tiered by headcount.
  • Cyber Essentials Plus: significantly higher, driven by the number of devices and locations sampled.
  • Remediation: the real variable — device refresh, MFA licensing and endpoint tooling.

How long does certification take?

A prepared organisation can complete the self-assessment in one to two weeks. Where controls are missing, expect four to eight weeks to remediate, evidence and submit. Cyber Essentials Plus must be completed within three months of passing the base certification, so plan them together rather than sequentially.

Why organisations fail — and how to avoid it

Most failures are not exotic. They come from scope decisions made too late and from asset lists that do not match reality.

  • Unsupported software still in use — old Windows builds, end-of-life network devices or unpatched browsers.
  • MFA not enabled on all cloud administrator accounts.
  • Patching outside the 14-day window for high and critical vulnerabilities.
  • BYOD and home-working devices excluded from scope without justification.
  • No accurate asset inventory, so evidence cannot be produced on request.

Cyber Essentials, ISO 27001 or both?

Cyber Essentials proves technical hygiene. ISO 27001 proves you run a managed information security system with governance, risk assessment and continual improvement. Many UK buyers ask for Cyber Essentials as a gate to tender and ISO 27001 for larger or regulated contracts. Achieving Cyber Essentials first gives you a fast, evidenced win while the ISO programme runs.

Frequently asked questions

Get a fixed-price Cyber Essentials readiness review

Speak to a SafetyX consultant about scope, timelines and fixed-price options for your organisation.

Continue reading