Why two Cyber Essentials quotes differ when the fee is published

IASME publishes the assessment fee and bands it by employee count, so the certificate costs the same wherever you buy it. Everything else in a quote is the part worth reading.

People comparing Cyber Essentials quotes often assume they are comparing the price of a certificate. They are not. IASME publishes the assessment fee and bands it by organisation size, so that part of the number is the same wherever you go. When two quotes differ by several hundred pounds, the difference is in what has been wrapped around the fee, and it is worth knowing what to look for.

The fee is published

IASME, the NCSC's delivery partner for the scheme, sets the assessment fee by total employee count:

  • Micro, 0 to 9 employees: £320 + VAT
  • Small, 10 to 49: £440 + VAT
  • Medium, 50 to 249: £500 + VAT
  • Large, 250 or more: £600 + VAT

That covers the assessment account, an assessor's review of your submission, and the certificate and badge if you pass. Those figures are public, which makes Cyber Essentials unusual among certifications and means you can always work out roughly what part of a quote is the fee.

The band follows your headcount, not your scope

This is the most common and most expensive misreading. Organisations try to bring the cost down by scoping the assessment to a department, a site or a single system, and are surprised when the fee does not move. The band is set by your total employee count, not by how many people or devices you put in scope. A 60 person organisation certifying one 12 person team still pays the medium fee.

Worse, a partial scope can cost you something. Eligible certifications include cyber liability insurance at no extra charge, currently a £25,000 limit of indemnity with an incident helpline, and the conditions include being domiciled in the UK or Crown Dependencies, having turnover under £20m, and certifying the entire organisation. Scope down and you lose that. You also get a certificate that a client will read carefully, because the scope statement is on it.

There are legitimate reasons to certify part of an organisation, usually a genuinely separate business unit with its own IT. Saving money is not one of them.

So what is the rest of the quote?

Everything other than the fee, which is to say the support. Four things in particular:

  • Whether anybody looks at your setup before you submit. A gap analysis is the difference between finding out where you stand now and finding out from an assessor's feedback.
  • Turnaround. Same day or front of queue assessment is a real service with a real cost, and it is worth nothing if your deadline is six weeks away.
  • Whether help with remediation is included, or whether you are handed a list.
  • Who reviews your answers. Worth asking directly. Ours are reviewed by a qualified, certified assessor and never fed into an AI model.

Those are legitimate differences and they explain most of the spread. What they do not explain is a price well below the published fee, which is a different conversation and one we have had separately.

Where the money actually goes

For most organisations the fee is the small part. The spend is remediation, and three items account for nearly all of it.

Licensing for multi-factor authentication across everyone. Not just administrators. Organisations frequently discover that enforcing it properly on all users, including conditional access on the accounts that matter, needs a licence tier above the one they are on. That is a recurring cost rather than a one-off, so it belongs in a budget line.

Anything unsupported. Operating systems, applications and firmware past end of support cannot be brought into line by configuration, so this is the one that turns into capital spend. It is also the one most likely to be discovered late, usually a server kept alive for a single application, or a firewall nobody has looked at since it was installed.

The mobile estate. Phones and tablets that access organisational data are in scope, and bring your own device arrangements bring personal phones in with them. Most organisations have not thought about this until it comes up.

Then there is internal time, which is real cost even though nobody invoices for it. Someone has to produce a device list, evidence the patching window, and explain how joiners and leavers are handled.

The cheapest way to make it expensive

If a submission does not pass, IASME allows a resubmission window of two working days at no extra cost. That window is the same at every certification body because IASME sets it. You get the assessor's feedback, you correct the answers, you resubmit. Miss it and you start a new application and pay the fee again.

Two working days is not long if the fix is technical rather than clerical. Fail on a Thursday and the window shuts on Monday. This is the single best argument for having somebody check your setup before you submit, because the cost of finding out late is the whole fee a second time.

If Cyber Essentials Plus is the real requirement

Plus is priced separately by each certification body, based on how many devices are in scope, because it is a hands-on technical audit rather than a reviewed self-assessment. The range in the market is wide for that reason.

The cost trap is sequencing. Cyber Essentials is a prerequisite, and the certificate has to be under three months old when the Plus audit starts. Certify in January, decide in June that a client needs Plus, and you are paying for Cyber Essentials again before the audit can begin. If Plus is where you are heading, plan both from the start. Our comparison of the two covers what the audit adds.

What a quote should tell you

  1. The IASME fee for your band, stated separately.
  2. What the support covers, and what happens if you are not ready.
  3. Whether a pre-submission review is included or an add-on, and what it costs.
  4. Turnaround, and what the urgent option actually changes.
  5. Who assesses the submission, and their qualification.
  6. What is not included, which is usually remediation.

If a quote is a single number with no breakdown, ask for one. The fee is public, so there is no commercial reason to hide which part of the price it is.

The honest version

If your controls are already in reasonable shape, the fee plus support is close to the whole cost and Cyber Essentials is a cheap thing to hold. If they are not, the certification is the small invoice and the remediation is the real one, and no provider can quote that part accurately without looking at your setup first.

Full figures, including our add-ons, are on what Cyber Essentials costs. We are an appointed IASME Certification Body, so the certificate comes directly from us.

Common questions

Is the £320 the total cost of Cyber Essentials?
It is the IASME assessment fee for a micro organisation, and it is the whole cost only if your setup already meets the five controls. The variable is remediation. If multi-factor authentication, patching and supported software are already in order, the fee plus support is close to the total.
Can we reduce the fee by certifying only part of the organisation?
No. The fee band is set by your total employee count rather than by what is in scope, so a narrower scope does not reduce it. It can also cost you the included cyber liability insurance, which requires the entire organisation to be certified. Partial scope makes sense for a genuinely separate business unit, not as a saving.
Why do certification bodies charge different amounts if the fee is published?
Because the fee buys the assessment, and the rest of the price is the support around it: whether anyone reviews your setup before you submit, how fast the turnaround is, whether help fixing things is included, and who reviews the answers. Those are real differences. Ask which of them a cheaper quote has left out.
What happens if we fail the assessment?
IASME allows a resubmission within two working days at no extra cost, which is the same at every certification body. You get the assessor's feedback, correct the answers and resubmit. Miss that window and it is a new application at the full fee, which is why a pre-submission check is usually worth more than an urgent turnaround.
Should we go straight to Cyber Essentials Plus?
If a client or contract specifically asks for Plus, plan both together, because Cyber Essentials is a prerequisite and the certificate has to be under three months old when the Plus audit starts. Certifying first and deciding on Plus months later means paying for Cyber Essentials twice. If nobody has asked for Plus, Cyber Essentials is usually the proportionate answer.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.