Cyber Essentials

What does Cyber Essentials actually cost?

About £100 a month for a business of up to 30 staff, if we already look after your IT. That is for the whole business, not per user. It is that low because we can already see and control everything Cyber Essentials checks, and we bill it monthly on purpose, because a certificate that only gets thought about every twelve months is a certificate that expires.

About £100 a month for a business of up to 30 staff, if we already support your IT. That is for the whole business rather than per user, and it includes the certification body’s fee.

Above 30 staff it goes up, and at that point we price and quote it properly so everybody has agreed the number before anything starts. If we do not support you, it is quoted separately and so is the remediation. More on both below.

We charge it monthly rather than as a job once a year, and that is a deliberate choice rather than a payment plan.

Why bill it monthly?

Because an annual job gets forgotten, and a forgotten certificate is an expired one.

The pattern with the once a year version is familiar. Somebody does the work in March, the certificate arrives, everyone is pleased, and then nothing happens for eleven months. In that time a new cloud service gets signed up for without multi factor authentication, three laptops fall out of support, somebody gets given admin rights for one job and keeps them, and a member of staff leaves with their account still live. Then renewal comes round and it is a scramble, or worse, a fail.

Running it monthly means it is a service rather than an event. We are keeping you compliant across the year and you arrive at renewal already in the state you need to be in. It also means the thing you signed a declaration about stays true, which matters more now than it used to.

Why is it so cheap for support clients?

Because we can already see and control everything Cyber Essentials checks.

The scheme covers five things: firewalls, secure configuration, security updates, user access and malware protection. For a business we support, all five are already ours. Multi factor authentication is on, updates are managed, every device reports in to us, and admin rights sit where they should. So the certification work is confirming and evidencing what is already there, rather than finding out and fixing it.

The £100 covers the certification body’s assessment fee, the readiness work, getting you through the submission, and keeping you compliant across the year. One monthly line on the invoice.

And if we do not support you?

We still do it, and it is priced differently, because the work is different.

We start with no visibility of your devices, your accounts or your configuration, so the first job is finding out where you stand. Then there is remediation, and that depends entirely on how much technical debt you are carrying. We quote the certification and invoice the remediation separately, and you get both numbers before you commit to anything.

Nobody enjoys being quoted a number and then being sent a second invoice for the bit that was not mentioned. So we do not do that.

What about Cyber Essentials Plus?

Different thing, and I am deliberately not going to put a number on it here.

Plus adds internal and external vulnerability scanning and hands on testing of a sample of your devices, gateways and accessible servers. Somebody actually checks rather than taking your word for it, which is the point of it and also why it costs more. The range runs into the thousands, and where you sit in that range depends on how many devices you have and how much work is needed to get them to a state where they will pass.

Quoting an average would be misleading enough to be useless, so we quote it per business.

Is it worth the money?

Yes, and it is a tick box exercise. Both of those are true at once, and I say that as somebody whose company gets clients certified.

The certificate tells you that on the day you were assessed, you met the controls. It does not tell you whether somebody set up a forwarding rule on your finance inbox this morning, or whether a scheduled task has been sitting on your domain controller since 2019. We found exactly that on a network once, running every ten minutes for six years, on a system with antivirus installed and scanning daily. Nobody was reading what it found.

But the thinking behind the scheme is sound. Multi factor authentication, patching, endpoint protection, restricted admin access, and a proper joiners and leavers process. If every UK SME did those five things consistently, the national picture would look dramatically different.

So: if you need the badge for a contract, a tender or a regulator, get it. If you do not need the badge, you still need the controls, and you should not wait for somebody to mandate what you should be doing anyway. And do not treat the certificate as the finish line. You have got another 364 days to stay compliant, and the declaration you signed says you will.

Half the job in my world is convincing people the badge is not the goal. The goal is the thing the badge is supposed to prove.

What to do next

If a client or a tender has started asking, find out which level they actually want, because plenty of people ask for Plus when the contract only says Cyber Essentials. If you do Legal Aid criminal work, it is a condition of your contract, and the criminal defence page sets out exactly what the contract says.

The Cyber Essentials page sets out the five controls, the difference between the two levels, and what changed in the requirements in April 2026, which catches out anybody renewing against a question set they have not read. Why multi factor authentication now fails renewals goes into that one in detail. Our support pricing is published in full, and asking us for a figure for your business takes a phone call rather than a meeting.

Questions

The questions people ask us about this

Can we get certified without moving our IT support to you?

Yes. We quote the certification on its own and invoice any remediation separately, and you get both numbers before anything starts. It costs more than it does for a support client, because we start with no visibility of your devices, accounts or configuration and have to find out where you stand first.

What if we fail?

You fix what failed and resubmit. It is not a one shot exam. The more useful question is what would fail, and we would rather find that out before submitting than after, which is what the readiness work is for.

Do we have to do it every year?

Yes, if you want to stay certified. Certificates last twelve months and organisations that do not recertify come off the list of certified companies, which matters if a client is checking.

Read next

Cyber Essentials

We certified last year. Will we pass Cyber Essentials renewal?

Probably not, not without some work first. Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3, and multi-factor authentication is now mandatory on every cloud service that offers it. Miss it on one service and you fail the whole assessment.

Read this

Cyber security

Will your cyber insurance actually pay out?

Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.

Read this

All posts

Next step

Talk to Tom, not a call queue

Ring the number below and you get Tom, the owner. No hold music, and no ticket reference before anyone has heard the problem. If we’re not the right fit, we’ll tell you that too.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.