Independent cost guide. Not affiliated with any certification body or compliance platform. Published prices are cited to their source; certification-body and consultant fees are quoted per engagement, so we do not state them. Always obtain a formal quote.

ISO 27001 vs Cyber Essentials: the UK read

Cyber Essentials is the rarest thing in this market: a certification scheme that publishes its actual price, banded by organisation size, on its own website. That makes this the one comparison on this site where one side has a real number. It also makes the other half of the story sharper than expected, because Cyber Essentials Plus does not publish a price at all. IASME says it has to be quoted for individually, which is precisely what ISO 27001 certification bodies say.

Updated July 2026

Three schemes, one published price between them

Published

Cyber Essentials

from £320

+ VAT, micro organisation band

Banded by organisation size and published openly by IASME, the scheme operator. You can look up your band before you speak to anyone.

Quote-only

Cyber Essentials Plus

Not published

Quoted individually by certification bodies

Same controls, independently tested. IASME states the assessment has to be quoted for individually and that cost depends on the size and complexity of the network.

Quote-only

ISO 27001

Not published

Quoted per engagement by accredited bodies

No accredited certification body publishes a rate card, and the audit-time tables sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells.

The pattern is worth naming. Pricing gets published when the assessment is standardised enough to band, and it disappears the moment a human has to look at your specific estate. That is the real dividing line in this market, and it runs straight through the Cyber Essentials scheme itself rather than between schemes.

The Cyber Essentials published bands

"The pricing of Cyber Essentials has a tiered structure based on organisation size."
"The pricing structure uses the criteria used by the UK government which defines the size of an organisation based on number of employees"
Organisation sizeEmployees, as the scheme defines itCyber Essentials
Micro0-9 employees£320 + VAT
Small10-49 employees£440 + VAT
Medium50-249 employees£500 + VAT
Large250 employees or more£600 + VAT

Read from the IASME Cyber Essentials FAQ, checked July 2026. VAT is excluded. The NCSC independently states: "The cost of certification is priced according to the size of your organisation, starting at £320 +VAT." NCSC Cyber Essentials overview. Note that these bands are the scheme certification cost. They do not cover the work of getting the controls in place, which is yours and which nobody can price from a table.

Why Cyber Essentials Plus has no published price

The scheme operator explains it directly, and it is the clearest short statement of why this whole market prices the way it does:

"As the Cyber Essentials Plus assessment needs more dedicated time from technical experts, it is more expensive than the verified self-assessment. The cost will depend on the size and complexity of the network."
"The Cyber Essentials Plus assessment has to be quoted for individually."

What separates Plus from the basic scheme is not more controls. IASME is explicit: "The controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different. Cyber Essentials Plus offers a higher level of assurance as the controls have been checked by a third party to ensure they are correctly implemented."

So the moment an independent expert has to look at your actual network, the published band disappears and the price becomes a quote against your complexity. That is the same mechanism that makes ISO 27001 audit fees unpublishable: audit time is determined against your scope, your headcount and your risk, and no table can do that for you in advance. IASME routes buyers to certification bodies for Plus quotes. We publish no figure for it, because there is not one to publish.

IASME Cyber Essentials FAQ, checked July 2026.

What each scheme actually is

Cyber Essentials: a technical baseline

A UK government-backed scheme operated by IASME Consortium and backed by the UK National Cyber Security Centre (NCSC). It covers five technical control areas:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

The basic scheme is a verified self-assessment. Plus adds independent technical testing of those same controls. It is a baseline, deliberately: the scheme is designed to be achievable and to cover common attack patterns rather than to describe a whole security programme.

ISO 27001: a management system

An international standard certified by a body accredited for ISMS certification. What is audited is the system, not just the controls:

  • ISMS scope and context
  • Risk assessment and risk treatment
  • A Statement of Applicability across 93 Annex A controls
  • Internal audit programme and management review
  • Two-stage audit, then a three-year cycle with surveillance

Controls are selected on the basis of risk and excluding one with justification is a normal outcome. The certificate asserts that the management system conforms, which is a claim about how you run security rather than about a fixed control list.

The subject matter overlaps: the five Cyber Essentials areas map onto Annex A technological controls, and an organisation running a mature ISMS is generally doing this work already. But overlap is not substitution. Holding ISO 27001 does not give you a Cyber Essentials certificate, because Cyber Essentials is a separate scheme with its own assessment and its own certification bodies. If a UK buyer asks for Cyber Essentials by name, that is the certificate you need, and the published band tells you what the basic one costs.

Which one do you actually need

The honest answer is the same as for every framework question on this site: whichever your buyers ask for, by name, in the document that decides the deal. We are not going to publish a contract-value threshold at which UK procurement switches from one to the other, because no published source states one and inventing a number for a tender you have not read would be worse than useless.

Cyber Essentials answers

  • A UK tender naming Cyber Essentials or Cyber Essentials Plus specifically
  • A UK buyer wanting evidence of a technical baseline
  • Your own need for a credible, achievable starting point with a known price

ISO 27001 answers

  • A buyer asking for an accredited ISMS certification
  • Procurement outside the UK, where Cyber Essentials carries no recognition
  • A buyer wanting one certificate that travels across regions
  • A supplier-risk workflow asking how you manage security, not what you have installed

They are complementary rather than exclusive, and the sequencing question is a real one for UK companies. Cyber Essentials has a published price and a short path, so it is a reasonable first certificate where UK buyers accept it. ISO 27001 has a lead time that does not compress: the ISMS has to actually run before Stage 2 can test it. If you can see an ISO 27001 tender coming, the useful thing is to start early enough that the evidence exists by the time someone asks for it, rather than to discover the lead time when the clock has already started.

Frequently asked questions

How much does Cyber Essentials cost?
Cyber Essentials is one of the very few certifications in this space that publishes a real price. IASME Consortium, which operates the scheme, states that the pricing has a tiered structure based on organisation size, using the criteria used by the UK government which defines the size of an organisation based on number of employees. A micro organisation of 0-9 employees pays £320 + VAT. A small organisation of 10-49 employees pays £440 + VAT. A medium organisation of 50-249 employees pays £500 + VAT. A large organisation of 250 employees or more pays £600 + VAT. The NCSC independently states: "The cost of certification is priced according to the size of your organisation, starting at £320 +VAT." Both checked July 2026.
How much does Cyber Essentials Plus cost?
There is no published price, and IASME says so plainly: the Cyber Essentials Plus assessment has to be quoted for individually. IASME explains that as the Cyber Essentials Plus assessment needs more dedicated time from technical experts, it is more expensive than the verified self-assessment, and that the cost will depend on the size and complexity of the network. IASME routes buyers to certification bodies for quotes. So on the pricing question, Cyber Essentials Plus behaves exactly like ISO 27001: the work is quoted per engagement against your estate, and anyone showing you a precise figure is showing you an assumption.
Is Cyber Essentials Plus a substitute for ISO 27001?
No. They are different kinds of thing. Cyber Essentials covers five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. The Plus variant tests the same controls with independent technical verification rather than covering more ground. IASME states that the controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different. ISO 27001 certifies an information security management system: scope, risk assessment, risk treatment, a Statement of Applicability across 93 Annex A controls, internal audit, and management review, audited in two stages by an accredited body on a three-year cycle. One verifies a technical baseline; the other certifies a management system.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
The assurance level, not the controls. IASME states that the controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different, and that Cyber Essentials Plus offers a higher level of assurance as the controls have been checked by a third party to ensure they are correctly implemented. Basic Cyber Essentials is a verified self-assessment with a published price band. Plus adds independent technical testing by an assessor, which is why it is quoted individually rather than priced from a table.
When is Cyber Essentials enough on its own?
When it is what your buyer actually asks for. Cyber Essentials is a UK government-backed scheme and it appears by name in UK public sector procurement requirements, so where a tender asks for Cyber Essentials or Cyber Essentials Plus specifically, that is the thing to hold. It is also a coherent technical baseline in its own right. What it is not is a certification of a management system, so where a buyer asks for an accredited ISMS certification, or asks for something recognised outside the UK, Cyber Essentials does not answer that ask. Read the tender rather than generalising about tiers.
Does ISO 27001 cover the Cyber Essentials control areas?
The subject matter overlaps substantially. The five Cyber Essentials areas map onto ISO 27001:2022 Annex A technological controls, and an organisation running a mature ISMS will generally be doing this work already. But holding ISO 27001 does not give you a Cyber Essentials certificate. Cyber Essentials is a separate scheme with its own assessment, its own certification bodies, and for Plus its own independent technical test. If a UK buyer asks for Cyber Essentials by name, you need the Cyber Essentials certificate, and the published bands tell you exactly what the basic one costs.

Related reading

Updated July 2026