AIS Technology Logo
Cybersecurity specialist reviewing network security

Cyber Essentials and Cyber Essentials Plus

Certification starts at £320.
Passing first time is the harder part.

The fee is fixed by IASME and easy to look up. What actually decides your cost is how much needs fixing before you apply. Work out the fee below, then check in a minute whether you would pass today.

What it costs

Your certification fee, in two clicks

Fees are set by IASME, so they are the same wherever you certify. What differs between providers is how much help you get to pass.

How many people work at your organisation?
Which certification do you need?

A verified self assessment questionnaire, reviewed by a certification body.

  • Certificate valid for12 months
  • Deadline to complete Plus3 months after basic
  • Assessment scopeWhole organisation, or part

Certification fee

£440

+ VAT, for a small organisation of 10 to 49 people

IASME certification fee
£440 + VAT
AIS readiness review
Free
Any remediation needed
Quoted after the review

Certify your whole organisation with a turnover under £20m and basic certification includes £25,000 of cyber liability insurance at no extra cost, with a 24 hour incident response helpline.

Book a free readiness review

Basic fees are set by IASME and are the same wherever you certify. Plus is priced on the size and complexity of your estate, so it is shown as a typical range.

Would you pass today?

Six questions that decide most assessments

Answer honestly. Nothing is sent anywhere, the result is worked out in your browser, and you will know within a minute whether you are close.

0 of 6 answered0%
  1. 1

    Is multi factor authentication switched on for every cloud service you use?

    From 27 April 2026 this is an automatic fail, not a warning. If a service offers MFA and it is off, you do not pass.

  2. 2

    Is every operating system and application still supported by its vendor?

    Anything past end of life fails the standard. Windows 10 reached end of support in October 2025.

  3. 3

    Are high risk security updates applied within 14 days?

    The standard sets a hard 14 day window for critical and high severity patches on internet facing systems.

  4. 4

    Do administrators use separate accounts for admin work and everyday email?

    Day to day browsing on an admin account is one of the most common reasons an assessment is failed.

  5. 5

    Do you have a current list of every device and cloud service in use?

    You cannot scope an assessment without one, and unknown devices are what auditors find first.

  6. 6

    Have default passwords been changed on firewalls, routers and other kit?

    Default credentials on internet facing equipment are an immediate fail and a genuine breach risk.

100%

You look close to ready

Based on the six checks that decide most assessments.

Nothing here is standing in your way. The next step is scoping the assessment properly and making sure the evidence matches what you have told us.

Start your certification

The standard itself

Five controls, and what usually fails them

The requirements are published and short. The useful knowledge is which parts catch businesses out, so each one below says what actually gets assessments rejected.

Firewalls

Every device that connects to the internet sits behind a correctly configured firewall, whether that is the boundary firewall on your office connection or the software firewall on a laptop working from a kitchen table.

What usually fails it

Default administrative passwords left on the router, and remote administration exposed to the internet without a documented business need.

Changing 27 April 2026

MFA stops being a warning and becomes a fail

IASME moves to version 3.3 of the requirements, the Danzell question set, for any assessment account created on or after that date. The five controls do not change. How strictly they are read does.

Today, if a cloud service offers multi factor authentication and you have not switched it on, you get a major non compliance and can still pass. From April that is an automatic failure, whether the MFA is free, bundled, or a paid add on.

Going for Plus? See what the audit tests
  • MFA on every cloud serviceAutomatic fail if available and not enabled
  • Unnecessary software removedEvidence required, not just a policy
  • 14 day patchingApplies to high risk and critical updates
  • Cloud services formally scopedDefinitions tightened, more services in scope
  • Passwordless encouragedNot required, but recognised

How we help

From where you are now to certified

We take businesses across London and Essex through both Cyber Essentials and Cyber Essentials Plus. Most of the work is the remediation, not the questionnaire.

  1. Readiness review

    We look at your actual setup against the five controls and tell you plainly what would fail today. Free, no obligation, and you keep the findings either way.

  2. Close the gaps

    MFA switched on everywhere, end of life software dealt with, admin accounts separated, patching brought inside the 14 day window. This is the part that takes real time.

  3. Assessment

    We work through the question set with you so the answers match the evidence, then submit through a certification body. For Plus, we prepare the estate for the technical audit.

  4. Keep it

    Certification lapses in 12 months and controls drift long before that. Ongoing management keeps you certifiable all year, not just in assessment week.

Going for Cyber Essentials Plus? The steps are the same, but an assessor tests the controls rather than taking your word for it, and there is a three month clock.

If you already work with us, preparation is usually part of your normal service: patching, MFA and device management are what our managed IT services do anyway. If you do not, the readiness review is still free.

Questions we get asked

Cyber Essentials, answered

How much does Cyber Essentials cost?

Certification fees are set by IASME and priced on the size of your organisation: £320 + VAT for micro organisations of 0 to 9 people, £440 for small (10 to 49), £500 for medium (50 to 249) and £600 for large (250+). Cyber Essentials Plus costs more because it adds a hands on technical audit, typically from around £1,400 for a small business up to £3,000 or more for larger or more complex estates.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Basic Cyber Essentials is a self assessment questionnaire verified by a certification body. Cyber Essentials Plus covers the same five controls but adds an independent technical audit of your actual devices and cloud services. You must hold a valid basic certificate before applying for Plus, and you have three months from receiving it to complete the Plus assessment. Our Cyber Essentials Plus page walks through exactly what the assessor tests.

What is changing in April 2026?

From 27 April 2026 IASME moves to version 3.3 of the requirements, known as the Danzell question set. The five controls stay the same but the interpretation tightens. The biggest change is multi factor authentication: today a missing MFA configuration is a warning you can still pass with, and from April it becomes an automatic failure.

Does Cyber Essentials include insurance?

Organisations that certify their whole business and have a turnover under £20 million receive £25,000 of cyber liability insurance included with basic certification, along with access to a 24 hour incident response helpline covering technical, legal and crisis management support.

How long does certification take?

The assessment itself can be completed in a few hours if you are well prepared. Most businesses go from registration to certificate within two to four weeks, and you have a maximum of six months from registration to submit. Where it takes longer, it is almost always remediation work rather than the paperwork.

Do we need an IT provider to get certified?

No. The self assessment is written to be answerable by a business owner rather than a specialist. In practice most businesses work with their IT support provider because the questions expose gaps that need fixing, and fixing them is the part that takes the time.

Does the certificate expire?

Yes. Both Cyber Essentials and Cyber Essentials Plus last 12 months and must be renewed annually. The renewal is a good moment to check that the controls have not drifted since last year, which is usually where problems appear.

Information Centre

More on security and compliance

Practical guidance on certification, compliance and keeping UK businesses secure.

Data Sovereignty for UK Financial Services Firms
Compliance

Data Sovereignty for UK Financial Services Firms

In 2026, knowing your data is secure is no longer enough. Regulators, clients and insurers want to know whose laws govern it and who can compel access. Here is what data sovereignty means for UK financial services firms, and how to regain control.

AIS TechnologyAIS Technology9 min read
Microsoft 365 Copilot for SMEs: Pricing and Licensing
Cloud Solutions

Microsoft 365 Copilot for SMEs: Pricing and Licensing

A straight answer for UK SMEs weighing up Microsoft 365 Copilot: what it really costs in 2026, how the licensing works, the data governance check most buyers skip, and how to decide whether it is worth it for your team.

AIS TechnologyAIS Technology10 min read
ISO 27001 vs Cyber Essentials: Which Certification Do You Need?
Cybersecurity

ISO 27001 vs Cyber Essentials: Which Certification Do You Need?

ISO 27001 and Cyber Essentials are routinely treated as alternatives. They are not. They answer different questions, suit different organisations, and cost very different amounts. This post sets out exactly what each certification is, who it is for, what it costs, and which one your business actually needs in 2026.

AIS TechnologyAIS Technology16 min read

Book Your Free Readiness Review

We will look at your actual setup against the five controls and tell you plainly what would fail today. No obligation, and you keep the findings whatever you decide to do next.

AIS Technology, Woodland Place, Hurricane Way, Wickford, SS11 8YB