Is Cyber Essentials worth it? The certificate costs between £320 and £600 plus VAT, which is cheap enough that most buyers never bother running the numbers — and that is exactly why so many of them end up disappointed. The money is not the decision. The decision is whether anyone in your market is actually going to ask you for the certificate, because the UK government’s own data says almost nobody is.
This post prices the scheme honestly: what it costs, who genuinely demands it, what it does not protect you from, and the April 2026 rule changes that raised the bar for anyone running Microsoft 365 or Google Workspace. Every figure comes from the NCSC, IASME or a published government statistic.
Is Cyber Essentials Worth It? The Short Answer
Cyber Essentials is a verified self-assessment against five technical controls, renewable every 12 months. It is not a management system, it is not an audit of your business, and it does not assure the product you sell. Whether it pays back depends almost entirely on your customer base.
| Your situation | Verdict | Why |
|---|---|---|
| You bid for central government or NHS contracts | Yes — treat it as a licence to bid | PPN 014 requires it (or proven equivalent controls) for contracts touching citizen data or OFFICIAL systems |
| You sell to large UK enterprises | Usually yes | 26% of large businesses now require suppliers to hold it specifically — up from 10% a year earlier |
| You are an MSP, IT provider or SaaS vendor | Yes | You are the supply-chain risk your clients are being told to review; the badge closes the conversation quickly |
| You already run ISO 27001 | Probably still yes | ISO 27001 does not automatically satisfy Cyber Essentials — the five controls are rarely all in scope and are rarely tested |
| You sell only to consumers or small local businesses | Not for the certificate | 3% of UK businesses require suppliers to be Cyber Essentials certified; do the controls, skip the badge |
| You have legacy systems you cannot patch | No, not yet | Unsupported software fails the assessment outright; fix the estate first or you pay to fail |
That table is the whole post in miniature. Every time someone asks is Cyber Essentials worth it, the useful follow-up question is not “how much does it cost” but “which of those six rows am I in”. The rest of this post explains the arithmetic behind each one.
What It Costs in 2026
Unusually for a certification scheme, the fee is set centrally and published. IASME, the NCSC’s delivery partner, charges by headcount only, so a 40-person software firm with a sprawling cloud estate pays exactly the same as a 40-person joinery business with a dozen laptops.
| Organisation size | Employees | IASME fee (ex VAT) |
|---|---|---|
| Micro | 0–9 | £320 |
| Small | 10–49 | £440 |
| Medium | 50–249 | £500 |
| Large | 250 or more | £600 |
The government’s own procurement guidance puts the same band at “between £300 and £500+ VAT at basic level” for smaller companies. Cyber Essentials Plus, which adds independent technical testing, is quoted per assessment rather than published, because the price tracks the size and complexity of your network; across certification bodies that publish rate cards, quotes generally land between roughly £1,200 and £4,250 plus VAT. Certificates last 12 months, so budget every figure as a recurring line rather than a one-off. Our full Cyber Essentials cost guide breaks down the licences, hardware replacements and resubmission fees that sit either side of the assessment fee.
The fee is almost never the real cost, which is why asking is Cyber Essentials worth it purely on the price list gives you the wrong answer. The real cost is the remediation: replacing machines whose vendor has stopped issuing security fixes, buying the licence tier that turns on multi-factor authentication, and the working days your IT lead spends evidencing it all.
Is Cyber Essentials Worth It When Almost Nobody Asks For It?
This is the part competitors leave out, and it is the single most useful number in the decision. The Department for Science, Innovation and Technology’s Cyber Security Breaches Survey 2025/2026 asked UK organisations whether they require their own suppliers to hold accreditations. The answers:
- 11% of businesses require suppliers to hold any standard or accreditation at all
- 3% of businesses require suppliers to hold Cyber Essentials specifically
- That rises to 26% of large businesses — significantly up from 10% the previous year
- And to 10% of high-income charities
So the certificate is a procurement gate in exactly two places: the public sector, and the large-enterprise supply chain. That single split is why the answer to is Cyber Essentials worth it differs so sharply between two firms of identical size. Everywhere else, demand is thin and growing slowly. If your pipeline is mid-market and private, buying the badge and waiting for it to generate leads is a reliable way to be disappointed.
Adoption tells the same story from the other side. Only 5% of UK businesses held Cyber Essentials in 2025/2026, up from 3% — large businesses moved from 21% to 35%, small businesses from 5% to 12%. Prompted awareness sits at 17% of businesses, and 18% did not know whether they held Cyber Essentials, Cyber Essentials Plus or ISO 27001 at all, despite the survey being answered by the person named as most responsible for cyber security.
The Public-Sector Gate, Read Off the Actual Policy
Procurement Policy Note 014, in force since 24 February 2025 and replacing PPN 09/14 and PPN 09/23, is the document that creates the demand. It applies to all central government departments, their executive agencies and non-departmental public bodies, and to NHS bodies. It bites where a contract involves citizens’ personal information, government employees’ personal information, ICT systems handling data at OFFICIAL, or information about the day-to-day business of government.
If you bid for this work, is Cyber Essentials worth it stops being a question — it is a condition of award. Four details in the policy change how you should plan:
- The certificate is needed before contract award, not at bid stage — and in exceptional cases a buyer may let a contract start on a lapsed certificate, provided you hold a valid one “at the point when data is to be passed to the supplier”.
- It must be renewed annually for the duration of the contract. This is a standing cost attached to the contract, not a one-time entry ticket.
- Buyers must not apply it to everything. The PPN states in terms that in-scope organisations “must not take a blanket approach” and warns against over-burdening or deterring SMEs. If a tender demands Cyber Essentials for work with no personal data and no OFFICIAL systems, that is a challengeable requirement.
- Equivalents must be accepted. Under section 56 of the Procurement Act 2023, buyers must accept independently verified equivalent controls. The certificate is the quickest route, not the only one.
The same policy is blunt about what it is buying. Cyber Essentials “does not assure specific products or services being supplied” and “is not designed to address more advanced, targeted attacks”. A supplier who sells the certificate as proof of security maturity is overselling it, and sophisticated buyers know that.
Is Cyber Essentials Worth It For a Small Business?
Run the arithmetic for a 25-person firm. The assessment fee is £440 plus VAT. Assume two to five days of internal effort to inventory devices, close gaps and answer the question set, plus some licence uplift. Call the realistic first-year all-in cost £2,000 to £5,000 as a typical range, most of which is time and licences rather than the fee. Year two, if nothing structural changes, drops back towards the fee plus a day or two.
Against that, three returns are real and one is not.
Real: the bid you would otherwise not be allowed to submit. One in-scope public contract or one enterprise onboarding that clears because the badge is already on file will normally cover several years of fees. This is the only return with a hard number attached, and it is the one to base the decision on.
Real: the free cyber liability insurance. Any UK organisation with turnover under £20m that certifies its whole organisation is automatically entitled to Cyber Liability Insurance arranged by IASME, including 24/7 incident response with technical, legal and crisis management support. Two conditions catch people out — the turnover cap and the whole-organisation scope. Narrow the scope to make the assessment easier and the insurance does not apply.
Real, and badly under-counted: the controls you were going to need anyway. Here is the gap that decides it for a lot of firms. 24% of UK businesses already report having controls in all five Cyber Essentials areas, but only 5% hold the certificate. If you are in that 24%, most of your spend is already sunk and the certificate is a few hundred pounds and a fortnight of evidencing. If you are not, the certificate is not what you are buying — the remediation is, and you would be buying that whether or not you certified.
Not real: the security guarantee. See the next section.
What Cyber Essentials Does Not Give You
Four limits, all of them stated by the scheme itself rather than by critics. Anyone answering is Cyber Essentials worth it with a security argument rather than a procurement argument needs to read these first.
Backups are not a requirement. Section C of the Requirements for IT Infrastructure v3.3 says plainly that backing up your data “is not a technical requirement of Cyber Essentials”, and only recommends it. The control that most reliably decides whether a ransomware incident is an outage or an extinction event is outside the scheme. Do not let a certificate persuade your board otherwise.
It is a point-in-time check. Government guidance is explicit that certified organisations “failing to regularly patch their ICT or control secure configuration may become non-compliant in substantially less than one year”. The badge on your website says what was true on assessment day.
Your suppliers are not in your scope. If you pass a client’s data to a cloud provider, Cyber Essentials “does not ensure that the security of the third party is in scope of certification”. Buyers are told to check, so expect to be asked.
ISO 27001 does not carry you across. The government’s position is that companies holding ISO 27001 “will not automatically conform to Cyber Essentials”, because it is unusual for all five technical controls to be inside an ISO 27001 scope and unlikely that any of them are tested. If you hold ISO 27001 and assume it covers you, you are wrong in the eyes of the buyer who matters. We compare the two schemes in detail in Cyber Essentials vs ISO 27001.
The April 2026 Changes That Moved the Bar
The scheme is reissued every April. Since 27 April 2026 the question set is named Danzell and the requirements document is v3.3, applying to assessment accounts created on or after that date; accounts opened earlier continue on the previous version, and once an account exists you have six months to finish. Three changes affect the cost-benefit case directly.
Cloud services cannot be excluded from scope. v3.3 adds a definition of a cloud service and states that where your data or services are hosted on cloud services, “these services must be in scope. Cloud services cannot be excluded from scope.” Microsoft 365 and Google Workspace are named in the definition of an organisational service. The old habit of scoping out the SaaS estate is gone.
MFA on cloud services is unconditional. The user access control requirement now reads: “implement MFA, where available – authentication to cloud services must always use MFA”. Not where convenient, not for admins only. If your licence tier does not support it across every cloud service you use, that is a real budget line to price before you apply.
Passwordless now names FIDO2. The definition of passwordless authentication was updated to include FIDO2 authenticators alongside biometrics, security keys, one-time codes, QR codes and push notifications. Organisations moving toward passkeys will find the assessment easier each year, not harder.
None of these make the scheme harder to justify — if anything they make it a better buy, because the controls they add are ones a serious buyer would ask about anyway. Also new: the Software Security Code of Practice is introduced in the software development section, and the scope criteria no longer refer to “untrusted connections”. The five controls themselves are unchanged.
When It Is Not Worth It
Three situations where the honest answer is no, or not yet.
First, if you run legacy systems that cannot be patched. Unsupported software fails the assessment; the government’s own guidance gives legacy IT provision as an example where Cyber Essentials cannot be applied wholesale and alternative controls are needed instead. Fix or segregate the estate first, then certify.
Second, if you would only certify a narrow sub-set to make it easy. A partial scope has to be justified to your assessor, it forfeits the free insurance, and a buyer reading the certificate will see exactly what you left out. A sub-set is a legitimate answer for a genuinely segregated business unit, and a bad answer for everything else.
Third, if you are certifying in the hope of marketing lift. Nearly three-quarters of the annual certificate volume is recertification rather than new organisations, and prompted awareness among businesses is 17%. Customers in most markets have not heard of it. Certify because a named buyer asks, or because you want the controls — not because you expect the logo to sell.
How to Make the Return Larger
If you have decided is Cyber Essentials worth it in your case, four moves change the payback, in order of size.
Certify the whole organisation rather than a sub-set, so the insurance applies and your certificate answers a buyer’s question without a caveat. Use the assessment as your annual control review — you re-enter every answer each year anyway. Sequence it before ISO 27001 rather than after, because the five controls are the technical floor an ISMS sits on and the evidence carries over. And if a named client or public buyer is the reason you are certifying, ask them in writing whether basic or Plus is required before you pay.
If the documentation is the part slowing you down, our Cyber Essentials Toolkit ($99) gives you 25 editable templates mapped to the five controls — scope statement, asset register, patching and access control policies, and the evidence pack an assessor expects — so the effort goes into fixing the estate rather than drafting from a blank page.
Frequently Asked Questions
Is Cyber Essentials worth it if I already hold ISO 27001?
Usually yes. Government procurement guidance states that ISO 27001 holders “will not automatically conform to Cyber Essentials”, because the five technical controls are rarely all inside an ISO 27001 scope and rarely tested. Most organisations with ISO 27001 either add Cyber Essentials or demonstrate equivalent controls to a buyer’s satisfaction, and adding the certificate is normally faster and cheaper than arguing equivalence on every bid.
Do I need Cyber Essentials Plus, or is basic enough?
Basic is enough unless a buyer has specifically assessed higher risk and asked for Plus. Plus tests the same five controls, but adds remote and on-site vulnerability testing to check the controls actually work, and costs several times more. Ask the buyer before you pay. Our guide to the Cyber Essentials Plus audit covers what the technical assessor actually does.
How long does certification take?
The assessment is a questionnaire reviewed by a certified assessor, and a clean submission can be turned around in days. The realistic timeline is set by remediation — typically two to eight weeks where IT hygiene is already decent, and longer where unsupported software or unmanaged devices must be dealt with first. Once your assessment account is open you have six months to complete it.
Does the certificate expire?
Yes, after 12 months. Where a public contract requires Cyber Essentials, the supplier must renew annually for the duration of the contract. You re-enter every answer at renewal rather than confirming last year’s, which is why it is worth treating the renewal as your annual control review.
Is Cyber Essentials worth it for a charity or a school?
The same test applies: who is asking. 10% of high-income charities now require their own suppliers to hold Cyber Essentials, and charities and schools bidding for public-sector or NHS work fall under the same PPN 014 characteristics as any other supplier. Where no funder or buyer asks, implement the five controls and spend the fee on backups instead — which the scheme, notably, does not require.
The Verdict
Is Cyber Essentials worth it? If you sell to government, the NHS, or large enterprises, yes — unambiguously, because it is a gate rather than a marketing asset, and the annual fee is trivial next to a single lost bid. If you sell elsewhere, the certificate itself buys you very little today, and the answer turns on whether you want the five controls. Most organisations want them. Fewer need the badge than the industry’s marketing implies, and saying so is the only way to make the decision on the numbers rather than on fear.
Whichever way you land, start with the controls. Our guide to Cyber Essentials certification and the five controls walks through what each one asks for, and the NCSC’s own Cyber Essentials overview is the authoritative source for the scheme’s current requirements and pricing.