Table of Contents
Introduction
Purpose of the guide
A Cyber Essentials audit runs £300 to £1,500 depending on your assessor and company size—but most small businesses can pass without one. The certification itself is free; you’re paying for someone to verify you’ve actually done the basics (firewalls, patching, antivirus). Whether that’s worth it depends entirely on whether your customers or insurers demand it.
We focus on business owners and leaders who need clear, actionable guidance. We explain concepts plainly so you can move from awareness to readiness with confidence.
What Cyber Essentials auditing involves
Cyber Essentials combines a self assessment with an independent audit. The assessor verifies your controls align with the five core areas and checks evidence you provide. This confirms you meet the minimum standards set by UK government bodies.
Key factors in the audit process include preparation time, evidence collection, and the assessor’s review. The length and cost depend on your organisation size and the complexity of your IT environment.
Practical steps to get ready
Begin with a quick gap analysis a month before submission. Identify missing controls in at least two core areas and map each gap to a remedy owner and a target date.
Collect evidence in a central repository. Use dated screenshots, policy documents, and change logs. Keep a running checklist and attach a short narrative for each item to speed assessor review.
-

1. Cost Structure by Organisation Size
Official assessment fees by micro, small, medium, and large organisations
The official fee structure for Cyber Essentials is set by IASME and scales with organisation size. This base fee covers the independent assessment itself, not extra services or remediation work. The government defines size by employee count, which drives the price tier:
- Micro (0-9 employees): £320 + VAT
- Small (10-49 employees): £440 + VAT
- Medium (50-249 employees): £500 + VAT
- Large (250+ employees): £600 + VAT
These figures represent the official assessment cost. All certification bodies charge the same base amount for the audit portion, so differences come from additional services rather than the official fee itself.
What additional costs to expect (preparation, remediation, and certification body fees)
Beyond the official fee, many organisations incur extra costs as they prepare and remediate. Typical areas include:
- Preparation time for evidence gathering and documentation
- Remediation work to align controls with requirements
- Assessment round due to gaps or failed controls
- Optional advisory or consultancy support from the certification body
Prices for these add-ons vary by complexity and scope, and can influence total year-one expenditure more than the base assessment fee.
Practical steps to manage the total cost
Plan a 60 day readiness window and assign a single owner to coordinate evidence collection. Create a checklist aligned to the five Cyber Essentials controls, then map each item to a responsible team and a due date. Use internal audits to flag gaps before engaging the certification body.
Ask for a formal scoping document from your chosen body before signing. This should break down preparation, remediation, and any advisory fees, with a rough timeline and milestone payments. requesting at least two quotes and confirming whether remote assessments are possible to reduce travel costs.
2. What Assessors Check: The Five Technical Controls
Firewalls: proper filtering and boundary protection
Assessors verify that firewalls separate trusted networks from untrusted ones and enforce clear rules. They look for documented policies and logs showing traffic is filtered according to the organisation’s risk profile.
- Defined inbound and outbound rules
- Regular review of firewall configurations
- Evidence of firewall deployment at network boundaries and staging segments
Secure configuration: securely configured endpoints and systems
Endpoints and core systems must be configured to minimize exploitable settings. Auditors check baselines, disabled unused services, and hardened configurations aligned to guidance.
- Standardised build configurations
- Removal of unnecessary accounts and services
- Audit trails showing configuration changes
Security update management: timely patching and vulnerability handling
Keeping software up to date reduces exposure. Assessors review patch management processes, CVE handling, and evidence of timely updates across devices.
- Defined patching windows and SLAs
- Inventory of assets with patch status
- Records of failed patches and remediation steps
User access control: appropriate permissions and authentication
Access controls ensure users have only the rights they need. The assessor checks governance for user provisioning, review cycles, and authentication strength.
- Role-based access where applicable
- Multi-factor authentication for sensitive systems
- Regular access reviews and orphan account management
Boundary and device protection: ensuring controls are enforced across the network
Controls extend beyond a single device to protect the network edge and connected endpoints. Evidence includes network segmentation, endpoint protection, and monitored traffic patterns.
- Network segmentation and secure demarcations
- Endpoint protection with monitored status
- Consistent policy enforcement across devices and locations
3. The Self-Assessment vs. Independent Audit Process
How self-assessment works within Cyber Essentials
You begin with a self-assessment questionnaire that maps to the five controls. The form guides you to confirm policy, configuration, and process details before you submit for review.
- Complete the online questionnaire to capture administrative and technical evidence
- Prepare concrete artifacts such as updated policies, system logs, and configuration baselines
- Submit the self-assessment for initial qualification before the independent review
What an independent assessor reviews and how evidence is provided
An independent assessor verifies a sample of controls against the documented evidence. They check that controls align with requirements and operate as described in practice.
- Evaluate evidence across all five controls with emphasis on real-world configuration and operation
- Review submitted documents, logs, and policy statements for accuracy and completeness
- Provide structured feedback and request additional evidence if gaps are found

4. Preparation Best Practices to Speed the Audit
Gathering documentation and evidence in advance
Centralize policy documents, network diagrams, and asset inventories in a single, indexed repository. Include baseline configurations, change logs, and approval records from the past 90 days to reflect current operations. This readiness reduces back and forth with assessors and speeds validation.
- Compile firewall rules, device configurations, patch histories, and recent incident reports
- Document asset owners, lifecycle status, and last verification date
- Attach security policies, access control lists, incident response playbooks, and tabletop exercise notes
Common pitfalls and how to avoid them
Timing and scope drive delays. Align the audit scope with official controls and tailor it to your organisation size. Ensure evidence is current and clearly labeled to prevent reassessment loops.
- Pitfall: incomplete evidence. Mitigate by running a pre-audit checklist against the five controls and updating gaps
- Pitfall: inconsistent naming. Standardise asset IDs, user identifiers, and document versions
- Pitfall: outdated configurations. Establish a quarterly refresh window and automate reminders
5. What Happens If You Fail and How Remediation Works
Post-audit remediation steps
If the assessment identifies gaps, you receive actionable feedback detailing nonconformities and recommended actions. Assign owners for each item, set clear remediation timelines, and gather updated evidence. Prioritise fixes that impact the five controls to prevent repeat delays.
- Documented corrective actions with owners and due dates
- Reconfigurations, patching, and policy updates as needed
- Recollection of revised evidence that demonstrates closure
Resubmission timelines and expectations
- Typical resubmission cycles align with the original audit SLA
- Evidence should show closure of gaps without introducing new issues
- Expect targeted verification rather than a full re-issue of all materials
FAQ
Here are concise answers to common questions about the UK Cyber Essentials audit process, cost, and outcomes. All guidance is grounded in the official framework and typical industry practice.
What affects the cost of Cyber Essentials
The price is tiered by organisation size and can vary by readiness and complexity. Micro organisations typically see the lowest base fee, with increases for small, medium, and large organisations reflecting the scope of assessment.
Real world example: a micro charity with 6 staff may pay a fraction of a larger manufacturer, but if the charity stores sensitive member data, you might incur extra charges for additional controls review or on-site verification.
How long does the audit take
The timeline depends on how quickly you prepare and provide evidence. A well-prepared self-assessment can move faster, while larger organisations may require more time to gather documentation and evidence across multiple sites or teams.
Actionable tip: schedule evidence collection in 2 week blocks, assign a point person per site, and pre-fill sections of the self-assessment to avoid backtracking.
What evidence do assessors review
Assessors look for policy alignment, secure configurations, documented processes, and demonstrable evidence across the five controls. Evidence can include policies, asset inventories, patch histories, and configuration baselines.
Practical detail: include a current asset register with owner contact, latest security patch report, and a baseline configuration screenshot for each critical system.
Can a micro organisation do Cyber Essentials on a tight schedule
Yes. Micro organisations often benefit from compact timetables due to smaller asset sets and simpler environments. Efficient preparation and use of the self-assessment can shorten the overall cycle.
What happens if there are gaps
Feedback identifies nonconformities and recommended actions. You assign owners, set remediation timelines, and gather updated evidence for verification by the assessor.
Common mistake: treating remediation as a one-off task. Create a live tracker, review weekly, and validate fixes with screenshots or logs before resubmission. pairing remediation with a brief internal audit to prevent repeat issues.
Conclusion
Understanding the cost and the assessor focus helps you plan Cyber Essentials with clarity. The price scales with organisation size, and the audit combines self-assessment with an independent review to validate your controls.
Practical expansion tips
For a small business with 10 employees, plan a concise 2 to 3 week window and assemble a focused evidence package. Centralize policy documents, asset inventories, and patch histories to speed review. Expect assessors to verify the five controls and confirm evidence aligns with your statements.
If pursuing Cyber Essentials Plus, allocate extra time for the technical audit and any remediation gaps. your team can map readiness to the formal controls, outline remediation steps, and maintain a single source of truth for evidence.
