🚀 Your daily business tech & AI briefing — Subscribe free →

Cyber Essentials audit costs: £300-£1,500, here’s what you actually get

Share this article Table of Contents Introduction 1. Cost Structure by Organisation Size 2. What Assessors Check: The Five Technical Controls 3. The Self-Assessment vs. Independent Audit Process 4. Preparation Best Practices to Speed the Audit 5. What Happens If You Fail and How Remediation Works FAQ Conclusion Introduction Purpose of the guide A Cyber […]

Zain A
Share this article

Introduction

Purpose of the guide

A Cyber Essentials audit runs £300 to £1,500 depending on your assessor and company size—but most small businesses can pass without one. The certification itself is free; you’re paying for someone to verify you’ve actually done the basics (firewalls, patching, antivirus). Whether that’s worth it depends entirely on whether your customers or insurers demand it.

We focus on business owners and leaders who need clear, actionable guidance. We explain concepts plainly so you can move from awareness to readiness with confidence.

What Cyber Essentials auditing involves

Cyber Essentials combines a self assessment with an independent audit. The assessor verifies your controls align with the five core areas and checks evidence you provide. This confirms you meet the minimum standards set by UK government bodies.

Key factors in the audit process include preparation time, evidence collection, and the assessor’s review. The length and cost depend on your organisation size and the complexity of your IT environment.

Practical steps to get ready

Begin with a quick gap analysis a month before submission. Identify missing controls in at least two core areas and map each gap to a remedy owner and a target date.

Collect evidence in a central repository. Use dated screenshots, policy documents, and change logs. Keep a running checklist and attach a short narrative for each item to speed assessor review.

  • How much does a UK Cyber Essentials audit take and what do assessors check

    1. Cost Structure by Organisation Size

    Official assessment fees by micro, small, medium, and large organisations

    The official fee structure for Cyber Essentials is set by IASME and scales with organisation size. This base fee covers the independent assessment itself, not extra services or remediation work. The government defines size by employee count, which drives the price tier:

    • Micro (0-9 employees): £320 + VAT
    • Small (10-49 employees): £440 + VAT
    • Medium (50-249 employees): £500 + VAT
    • Large (250+ employees): £600 + VAT

    These figures represent the official assessment cost. All certification bodies charge the same base amount for the audit portion, so differences come from additional services rather than the official fee itself.

    What additional costs to expect (preparation, remediation, and certification body fees)

    Beyond the official fee, many organisations incur extra costs as they prepare and remediate. Typical areas include:

    • Preparation time for evidence gathering and documentation
    • Remediation work to align controls with requirements
    • Assessment round due to gaps or failed controls
    • Optional advisory or consultancy support from the certification body

    Prices for these add-ons vary by complexity and scope, and can influence total year-one expenditure more than the base assessment fee.

    Practical steps to manage the total cost

    Plan a 60 day readiness window and assign a single owner to coordinate evidence collection. Create a checklist aligned to the five Cyber Essentials controls, then map each item to a responsible team and a due date. Use internal audits to flag gaps before engaging the certification body.

    Ask for a formal scoping document from your chosen body before signing. This should break down preparation, remediation, and any advisory fees, with a rough timeline and milestone payments. requesting at least two quotes and confirming whether remote assessments are possible to reduce travel costs.

    2. What Assessors Check: The Five Technical Controls

    Firewalls: proper filtering and boundary protection

    Assessors verify that firewalls separate trusted networks from untrusted ones and enforce clear rules. They look for documented policies and logs showing traffic is filtered according to the organisation’s risk profile.

    • Defined inbound and outbound rules
    • Regular review of firewall configurations
    • Evidence of firewall deployment at network boundaries and staging segments

    Secure configuration: securely configured endpoints and systems

    Endpoints and core systems must be configured to minimize exploitable settings. Auditors check baselines, disabled unused services, and hardened configurations aligned to guidance.

    • Standardised build configurations
    • Removal of unnecessary accounts and services
    • Audit trails showing configuration changes

    Security update management: timely patching and vulnerability handling

    Keeping software up to date reduces exposure. Assessors review patch management processes, CVE handling, and evidence of timely updates across devices.

    • Defined patching windows and SLAs
    • Inventory of assets with patch status
    • Records of failed patches and remediation steps

    User access control: appropriate permissions and authentication

    Access controls ensure users have only the rights they need. The assessor checks governance for user provisioning, review cycles, and authentication strength.

    • Role-based access where applicable
    • Multi-factor authentication for sensitive systems
    • Regular access reviews and orphan account management

    Boundary and device protection: ensuring controls are enforced across the network

    Controls extend beyond a single device to protect the network edge and connected endpoints. Evidence includes network segmentation, endpoint protection, and monitored traffic patterns.

    • Network segmentation and secure demarcations
    • Endpoint protection with monitored status
    • Consistent policy enforcement across devices and locations

    3. The Self-Assessment vs. Independent Audit Process

    How self-assessment works within Cyber Essentials

    You begin with a self-assessment questionnaire that maps to the five controls. The form guides you to confirm policy, configuration, and process details before you submit for review.

    • Complete the online questionnaire to capture administrative and technical evidence
    • Prepare concrete artifacts such as updated policies, system logs, and configuration baselines
    • Submit the self-assessment for initial qualification before the independent review

    What an independent assessor reviews and how evidence is provided

    An independent assessor verifies a sample of controls against the documented evidence. They check that controls align with requirements and operate as described in practice.

    • Evaluate evidence across all five controls with emphasis on real-world configuration and operation
    • Review submitted documents, logs, and policy statements for accuracy and completeness
    • Provide structured feedback and request additional evidence if gaps are found
    How much does a UK Cyber Essentials audit take and what do assessors check

    4. Preparation Best Practices to Speed the Audit

    Gathering documentation and evidence in advance

    Centralize policy documents, network diagrams, and asset inventories in a single, indexed repository. Include baseline configurations, change logs, and approval records from the past 90 days to reflect current operations. This readiness reduces back and forth with assessors and speeds validation.

    • Compile firewall rules, device configurations, patch histories, and recent incident reports
    • Document asset owners, lifecycle status, and last verification date
    • Attach security policies, access control lists, incident response playbooks, and tabletop exercise notes

    Common pitfalls and how to avoid them

    Timing and scope drive delays. Align the audit scope with official controls and tailor it to your organisation size. Ensure evidence is current and clearly labeled to prevent reassessment loops.

    • Pitfall: incomplete evidence. Mitigate by running a pre-audit checklist against the five controls and updating gaps
    • Pitfall: inconsistent naming. Standardise asset IDs, user identifiers, and document versions
    • Pitfall: outdated configurations. Establish a quarterly refresh window and automate reminders

    5. What Happens If You Fail and How Remediation Works

    Post-audit remediation steps

    If the assessment identifies gaps, you receive actionable feedback detailing nonconformities and recommended actions. Assign owners for each item, set clear remediation timelines, and gather updated evidence. Prioritise fixes that impact the five controls to prevent repeat delays.

    • Documented corrective actions with owners and due dates
    • Reconfigurations, patching, and policy updates as needed
    • Recollection of revised evidence that demonstrates closure

    Resubmission timelines and expectations

    • Typical resubmission cycles align with the original audit SLA
    • Evidence should show closure of gaps without introducing new issues
    • Expect targeted verification rather than a full re-issue of all materials

    FAQ

    Here are concise answers to common questions about the UK Cyber Essentials audit process, cost, and outcomes. All guidance is grounded in the official framework and typical industry practice.

    What affects the cost of Cyber Essentials

    The price is tiered by organisation size and can vary by readiness and complexity. Micro organisations typically see the lowest base fee, with increases for small, medium, and large organisations reflecting the scope of assessment.

    Real world example: a micro charity with 6 staff may pay a fraction of a larger manufacturer, but if the charity stores sensitive member data, you might incur extra charges for additional controls review or on-site verification.

    How long does the audit take

    The timeline depends on how quickly you prepare and provide evidence. A well-prepared self-assessment can move faster, while larger organisations may require more time to gather documentation and evidence across multiple sites or teams.

    Actionable tip: schedule evidence collection in 2 week blocks, assign a point person per site, and pre-fill sections of the self-assessment to avoid backtracking.

    What evidence do assessors review

    Assessors look for policy alignment, secure configurations, documented processes, and demonstrable evidence across the five controls. Evidence can include policies, asset inventories, patch histories, and configuration baselines.

    Practical detail: include a current asset register with owner contact, latest security patch report, and a baseline configuration screenshot for each critical system.

    Can a micro organisation do Cyber Essentials on a tight schedule

    Yes. Micro organisations often benefit from compact timetables due to smaller asset sets and simpler environments. Efficient preparation and use of the self-assessment can shorten the overall cycle.

    What happens if there are gaps

    Feedback identifies nonconformities and recommended actions. You assign owners, set remediation timelines, and gather updated evidence for verification by the assessor.

    Common mistake: treating remediation as a one-off task. Create a live tracker, review weekly, and validate fixes with screenshots or logs before resubmission. pairing remediation with a brief internal audit to prevent repeat issues.

    Conclusion

    Understanding the cost and the assessor focus helps you plan Cyber Essentials with clarity. The price scales with organisation size, and the audit combines self-assessment with an independent review to validate your controls.

    Practical expansion tips

    For a small business with 10 employees, plan a concise 2 to 3 week window and assemble a focused evidence package. Centralize policy documents, asset inventories, and patch histories to speed review. Expect assessors to verify the five controls and confirm evidence aligns with your statements.

    If pursuing Cyber Essentials Plus, allocate extra time for the technical audit and any remediation gaps. your team can map readiness to the formal controls, outline remediation steps, and maintain a single source of truth for evidence.

References

Share this article

Stay in the Loop

Weekly tech insights, AI news and tools — straight to your inbox.

Newsletter Form (#4)

Contents