Cyber Essentials: Cost, Requirements & Getting Certified
Cyber Essentials is the entry-level UK cyber security certification, and for many businesses it's now effectively mandatory — required to bid on government and public sector contracts. Here's what it costs, what it requires, and whether it's worth it for your business.
What it costs
The certification fee is set by the IASME consortium and is priced by organisation size (roughly a few hundred pounds depending on tier), with a fixed annual cycle. The bigger cost for most businesses isn't the fee — it's the time to prepare. Companies routinely spend days gathering evidence and fixing configuration gaps before they're ready to apply.
What the requirements are
Certification requires you to demonstrate the five technical controls (firewalls, secure configuration, access control, malware protection, and patching) across all devices that touch your data — not just the office desktop. The scope includes mobiles, home workers, and cloud services.
Who needs it (and who doesn't)
- Required: suppliers to UK government and public sector, and increasingly to larger corporates who demand it from their supply chain.
- Strongly recommended: any SME handling customer personal data — it's the fastest way to prove you take data protection seriously, and it can reduce insurance premiums.
- Nice-to-have: very small businesses with no contractual or bidding requirements.
How long it takes
From starting preparation to holding the certificate is typically 2–4 weeks. The assessment itself is a self-submitted set of answers reviewed by an assessor; Cyber Essentials Plus adds a technical audit.
Cyber Essentials Gap Assessment Workbook
Know your exact gaps before you spend a penny on the assessment. The workbook mirrors what assessors look for, control by control.
Get it nowSME Cyber Compliance Kit
The all-in-one policy and compliance pack: policies, templates and checklists to satisfy Cyber Essentials, GDPR and more.
Get it now