Why two Cyber Essentials quotes differ when the fee is published
IASME publishes the assessment fee and bands it by employee count, so the certificate costs the same wherever you buy it. Everything else in a quote is the part worth reading.
People comparing Cyber Essentials quotes often assume they are comparing the price of a certificate. They are not. IASME publishes the assessment fee and bands it by organisation size, so that part of the number is the same wherever you go. When two quotes differ by several hundred pounds, the difference is in what has been wrapped around the fee, and it is worth knowing what to look for.
The fee is published
IASME, the NCSC's delivery partner for the scheme, sets the assessment fee by total employee count:
- Micro, 0 to 9 employees: £320 + VAT
- Small, 10 to 49: £440 + VAT
- Medium, 50 to 249: £500 + VAT
- Large, 250 or more: £600 + VAT
That covers the assessment account, an assessor's review of your submission, and the certificate and badge if you pass. Those figures are public, which makes Cyber Essentials unusual among certifications and means you can always work out roughly what part of a quote is the fee.
The band follows your headcount, not your scope
This is the most common and most expensive misreading. Organisations try to bring the cost down by scoping the assessment to a department, a site or a single system, and are surprised when the fee does not move. The band is set by your total employee count, not by how many people or devices you put in scope. A 60 person organisation certifying one 12 person team still pays the medium fee.
Worse, a partial scope can cost you something. Eligible certifications include cyber liability insurance at no extra charge, currently a £25,000 limit of indemnity with an incident helpline, and the conditions include being domiciled in the UK or Crown Dependencies, having turnover under £20m, and certifying the entire organisation. Scope down and you lose that. You also get a certificate that a client will read carefully, because the scope statement is on it.
There are legitimate reasons to certify part of an organisation, usually a genuinely separate business unit with its own IT. Saving money is not one of them.
So what is the rest of the quote?
Everything other than the fee, which is to say the support. Four things in particular:
- Whether anybody looks at your setup before you submit. A gap analysis is the difference between finding out where you stand now and finding out from an assessor's feedback.
- Turnaround. Same day or front of queue assessment is a real service with a real cost, and it is worth nothing if your deadline is six weeks away.
- Whether help with remediation is included, or whether you are handed a list.
- Who reviews your answers. Worth asking directly. Ours are reviewed by a qualified, certified assessor and never fed into an AI model.
Those are legitimate differences and they explain most of the spread. What they do not explain is a price well below the published fee, which is a different conversation and one we have had separately.
Where the money actually goes
For most organisations the fee is the small part. The spend is remediation, and three items account for nearly all of it.
Licensing for multi-factor authentication across everyone. Not just administrators. Organisations frequently discover that enforcing it properly on all users, including conditional access on the accounts that matter, needs a licence tier above the one they are on. That is a recurring cost rather than a one-off, so it belongs in a budget line.
Anything unsupported. Operating systems, applications and firmware past end of support cannot be brought into line by configuration, so this is the one that turns into capital spend. It is also the one most likely to be discovered late, usually a server kept alive for a single application, or a firewall nobody has looked at since it was installed.
The mobile estate. Phones and tablets that access organisational data are in scope, and bring your own device arrangements bring personal phones in with them. Most organisations have not thought about this until it comes up.
Then there is internal time, which is real cost even though nobody invoices for it. Someone has to produce a device list, evidence the patching window, and explain how joiners and leavers are handled.
The cheapest way to make it expensive
If a submission does not pass, IASME allows a resubmission window of two working days at no extra cost. That window is the same at every certification body because IASME sets it. You get the assessor's feedback, you correct the answers, you resubmit. Miss it and you start a new application and pay the fee again.
Two working days is not long if the fix is technical rather than clerical. Fail on a Thursday and the window shuts on Monday. This is the single best argument for having somebody check your setup before you submit, because the cost of finding out late is the whole fee a second time.
If Cyber Essentials Plus is the real requirement
Plus is priced separately by each certification body, based on how many devices are in scope, because it is a hands-on technical audit rather than a reviewed self-assessment. The range in the market is wide for that reason.
The cost trap is sequencing. Cyber Essentials is a prerequisite, and the certificate has to be under three months old when the Plus audit starts. Certify in January, decide in June that a client needs Plus, and you are paying for Cyber Essentials again before the audit can begin. If Plus is where you are heading, plan both from the start. Our comparison of the two covers what the audit adds.
What a quote should tell you
- The IASME fee for your band, stated separately.
- What the support covers, and what happens if you are not ready.
- Whether a pre-submission review is included or an add-on, and what it costs.
- Turnaround, and what the urgent option actually changes.
- Who assesses the submission, and their qualification.
- What is not included, which is usually remediation.
If a quote is a single number with no breakdown, ask for one. The fee is public, so there is no commercial reason to hide which part of the price it is.
The honest version
If your controls are already in reasonable shape, the fee plus support is close to the whole cost and Cyber Essentials is a cheap thing to hold. If they are not, the certification is the small invoice and the remediation is the real one, and no provider can quote that part accurately without looking at your setup first.
Full figures, including our add-ons, are on what Cyber Essentials costs. We are an appointed IASME Certification Body, so the certificate comes directly from us.
Common questions
Is the £320 the total cost of Cyber Essentials?
Can we reduce the fee by certifying only part of the organisation?
Why do certification bodies charge different amounts if the fee is published?
What happens if we fail the assessment?
Should we go straight to Cyber Essentials Plus?
Related
Ready to talk?
Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.