The dangers of cheap or instant Cyber Essentials

Rock-bottom prices and same-day certificates are tempting. Here is what tends to be quietly missing, and what it can cost you.

Insights · 10 September 2026

The cheapest, fastest Cyber Essentials is not always a bargain. When the price is rock bottom or the certificate is promised same-day regardless of your setup, something is usually being skipped, and it is often the part that matters.

What tends to get skipped

Real verification of your answers, help fixing the controls that are not yet in place, and the honest conversation about multi-factor authentication, unsupported software and how your remote access is configured. Strip those out and you are left with a form-filling exercise and a PDF, not assurance.

What it can cost you

A certificate that does not protect you against the attacks it is meant to stop. A certificate that can be challenged by a client audit or an insurer after a breach. And a false sense of security that stops you fixing the real gaps. Set against a genuine breach or a lost contract, the few pounds saved up front look very small.

Cheap done well is fine. Cheap done hollow is not.

Cyber Essentials should be affordable, and we keep it so, at a clear fixed price. The difference is whether that price includes a real assessment and help getting your controls right, or just a rubber stamp. Ask exactly what is included before you buy on price alone.

Common questions

Is cheap Cyber Essentials always a bad idea?

No. Cyber Essentials should be affordable. The risk is when a low price or instant turnaround means the real assessment and remediation help have been cut out.

What should a fair Cyber Essentials price include?

A genuine assessment of your controls, help fixing what is not in place, plain-English guidance, and an honest answer on whether you are ready, for a clear fixed fee.

Related

Cyber Essentials that actually means something.

A genuine assessment, honest advice, and a certificate that stands up. Fixed price, no obligation.