ISO 27001 vs Cyber Essentials: the UK read
Cyber Essentials is the rarest thing in this market: a certification scheme that publishes its actual price, banded by organisation size, on its own website. That makes this the one comparison on this site where one side has a real number. It also makes the other half of the story sharper than expected, because Cyber Essentials Plus does not publish a price at all. IASME says it has to be quoted for individually, which is precisely what ISO 27001 certification bodies say.
Updated July 2026
Three schemes, one published price between them
Published
Cyber Essentials
from £320
+ VAT, micro organisation band
Banded by organisation size and published openly by IASME, the scheme operator. You can look up your band before you speak to anyone.
Quote-only
Cyber Essentials Plus
Not published
Quoted individually by certification bodies
Same controls, independently tested. IASME states the assessment has to be quoted for individually and that cost depends on the size and complexity of the network.
Quote-only
ISO 27001
Not published
Quoted per engagement by accredited bodies
No accredited certification body publishes a rate card, and the audit-time tables sit in ISO/IEC 27006-1:2024 Annex C, which ISO sells.
The pattern is worth naming. Pricing gets published when the assessment is standardised enough to band, and it disappears the moment a human has to look at your specific estate. That is the real dividing line in this market, and it runs straight through the Cyber Essentials scheme itself rather than between schemes.
The Cyber Essentials published bands
"The pricing of Cyber Essentials has a tiered structure based on organisation size."
"The pricing structure uses the criteria used by the UK government which defines the size of an organisation based on number of employees"
| Organisation size | Employees, as the scheme defines it | Cyber Essentials |
|---|---|---|
| Micro | 0-9 employees | £320 + VAT |
| Small | 10-49 employees | £440 + VAT |
| Medium | 50-249 employees | £500 + VAT |
| Large | 250 employees or more | £600 + VAT |
Read from the IASME Cyber Essentials FAQ, checked July 2026. VAT is excluded. The NCSC independently states: "The cost of certification is priced according to the size of your organisation, starting at £320 +VAT." NCSC Cyber Essentials overview. Note that these bands are the scheme certification cost. They do not cover the work of getting the controls in place, which is yours and which nobody can price from a table.
Why Cyber Essentials Plus has no published price
The scheme operator explains it directly, and it is the clearest short statement of why this whole market prices the way it does:
"As the Cyber Essentials Plus assessment needs more dedicated time from technical experts, it is more expensive than the verified self-assessment. The cost will depend on the size and complexity of the network."
"The Cyber Essentials Plus assessment has to be quoted for individually."
What separates Plus from the basic scheme is not more controls. IASME is explicit: "The controls for Cyber Essentials and Cyber Essentials Plus are exactly the same but the level of assurance is different. Cyber Essentials Plus offers a higher level of assurance as the controls have been checked by a third party to ensure they are correctly implemented."
So the moment an independent expert has to look at your actual network, the published band disappears and the price becomes a quote against your complexity. That is the same mechanism that makes ISO 27001 audit fees unpublishable: audit time is determined against your scope, your headcount and your risk, and no table can do that for you in advance. IASME routes buyers to certification bodies for Plus quotes. We publish no figure for it, because there is not one to publish.
IASME Cyber Essentials FAQ, checked July 2026.
What each scheme actually is
Cyber Essentials: a technical baseline
A UK government-backed scheme operated by IASME Consortium and backed by the UK National Cyber Security Centre (NCSC). It covers five technical control areas:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
The basic scheme is a verified self-assessment. Plus adds independent technical testing of those same controls. It is a baseline, deliberately: the scheme is designed to be achievable and to cover common attack patterns rather than to describe a whole security programme.
ISO 27001: a management system
An international standard certified by a body accredited for ISMS certification. What is audited is the system, not just the controls:
- ISMS scope and context
- Risk assessment and risk treatment
- A Statement of Applicability across 93 Annex A controls
- Internal audit programme and management review
- Two-stage audit, then a three-year cycle with surveillance
Controls are selected on the basis of risk and excluding one with justification is a normal outcome. The certificate asserts that the management system conforms, which is a claim about how you run security rather than about a fixed control list.
The subject matter overlaps: the five Cyber Essentials areas map onto Annex A technological controls, and an organisation running a mature ISMS is generally doing this work already. But overlap is not substitution. Holding ISO 27001 does not give you a Cyber Essentials certificate, because Cyber Essentials is a separate scheme with its own assessment and its own certification bodies. If a UK buyer asks for Cyber Essentials by name, that is the certificate you need, and the published band tells you what the basic one costs.
Which one do you actually need
The honest answer is the same as for every framework question on this site: whichever your buyers ask for, by name, in the document that decides the deal. We are not going to publish a contract-value threshold at which UK procurement switches from one to the other, because no published source states one and inventing a number for a tender you have not read would be worse than useless.
Cyber Essentials answers
- A UK tender naming Cyber Essentials or Cyber Essentials Plus specifically
- A UK buyer wanting evidence of a technical baseline
- Your own need for a credible, achievable starting point with a known price
ISO 27001 answers
- A buyer asking for an accredited ISMS certification
- Procurement outside the UK, where Cyber Essentials carries no recognition
- A buyer wanting one certificate that travels across regions
- A supplier-risk workflow asking how you manage security, not what you have installed
They are complementary rather than exclusive, and the sequencing question is a real one for UK companies. Cyber Essentials has a published price and a short path, so it is a reasonable first certificate where UK buyers accept it. ISO 27001 has a lead time that does not compress: the ISMS has to actually run before Stage 2 can test it. If you can see an ISO 27001 tender coming, the useful thing is to start early enough that the evidence exists by the time someone asks for it, rather than to discover the lead time when the clock has already started.