lead

If a client questionnaire, a tender document or an insurance renewal has just told you to get Cyber Essentials, you have two immediate

If a client questionnaire, a tender document or an insurance renewal has just told you to get Cyber Essentials, you have two immediate questions: which level, and what will it cost? The short answers: Cyber Essentials Plus if a contract or framework explicitly demands it or you handle genuinely sensitive data; standard Cyber Essentials otherwise, at least to start. Costs run from a few hundred pounds for the standard certificate to a few thousand all-in for Plus, once assessment and remediation are counted.

At Indigo IT we hold Cyber Essentials Plus ourselves and take clients through both levels of the scheme regularly, so this guide reflects how the process actually plays out for businesses of 20–250 people – including the parts the certificate price doesn’t tell you.

What both certifications actually assess

Cyber Essentials is the UK government-backed scheme, run by the NCSC’s delivery partner IASME, built around five technical controls: firewalls and internet gateways; secure configuration; user access control; malware protection; and security update management. The scheme’s premise, supported by NCSC analysis, is that these five controls stop the large majority of common, unsophisticated attacks — the ones that actually hit SMEs, as opposed to the nation-state stories that make the news.

Both levels assess the same five controls. The difference is entirely in how the assessment is done.

The real difference: self-assessment vs independent audit

  • Cyber Essentials — You (or your IT provider on your behalf) complete a detailed self-assessment questionnaire, a board member signs to confirm its accuracy, and a qualified assessor reviews the answers. It’s a declaration, verified on paper. Certification is typically achievable within days once your environment actually meets the controls.
  • Cyber Essentials Plus — Everything in the standard level, plus an independent technical audit: an assessor tests a sample of your devices and systems — vulnerability scans, malware-protection checks, verification that what the questionnaire claimed is true in practice. It must be completed within three months of the underlying Cyber Essentials certificate. It’s the difference between telling someone your locks work and having a locksmith try the doors.

That difference is why Plus carries more weight with the organisations that check. When Indigo IT chose to certify its own business, we went to Plus for exactly the reason we recommend it to clients handling sensitive work: a claim you’ve had independently tested is worth more than a claim you’ve signed.

What they cost, realistically

The standard Cyber Essentials assessment is priced by IASME on a sliding scale by organisation size – from roughly £320 + VAT for the smallest firms to around £600 + VAT for larger ones (check IASME’s current pricing, as it’s revised periodically). Cyber Essentials Plus audit fees vary by assessor and by the size and complexity of your environment; for a typical 20–250 person business, expect the audit itself to run from around £1,500 to £3,000 + VAT.

But the certificate fee is rarely the real cost. The real cost is remediation – the work to make your environment genuinely meet the five controls: retiring unsupported software, enforcing multi-factor authentication, tightening admin accounts, fixing patching. For a well-run environment that’s minimal; for a neglected one it can be several days of work. This is also the honest answer to “why do quotes for Cyber Essentials vary so much”: some quote the certificate, others quote getting you to the point where you’ll pass. When Indigo IT scopes certification for a new client, the first step is always a gap assessment against the five controls – so the quote you receive covers reaching the standard, not just sitting the exam.

Both certifications last twelve months and must be renewed annually. Standard Cyber Essentials also includes cyber liability insurance (currently £25,000 of cover) for eligible smaller organisations, which for some firms offsets a meaningful slice of the cost.

Which level does your business need?

  • Contract-driven — Chasing public-sector or defence work? Many government contracts mandate Cyber Essentials as a minimum, and MOD-related work frequently specifies Plus. Check the tender wording – the required level is usually explicit. This comes up constantly among the defence and aerospace supply-chain businesses Indigo IT supports around Farnborough.
  • Assurance-driven — Being asked by a large customer or insurer? Standard Cyber Essentials usually satisfies supplier questionnaires and demonstrates the baseline insurers increasingly expect. If a specific customer demands Plus, they’ll say so.
  • Self-driven — Doing it for your own security? Start with standard – the value is in implementing the controls, not the badge – and step up to Plus when you want independent proof, typically once you’re selling into supply chains that check.

A sensible path for most SMEs: achieve standard Cyber Essentials properly (not just on paper), live with the controls for a cycle, then add Plus when a commercial reason arrives. Businesses that jump straight to Plus with a weak environment pay for remediation under audit-deadline pressure – the most expensive way to do it.

How Indigo IT handles certification for clients

For businesses across Surrey, Hampshire and Berkshire, Indigo IT runs Cyber Essentials as a managed process: a gap assessment against the five controls, remediation of whatever falls short, completion of the assessment itself, and – because the certificate expires annually – keeping the environment compliant year-round so renewal is an administrative event rather than an annual scramble. For clients on our managed IT support contracts, most of the controls are simply how their environment is already run, which is why their certifications tend to be quick. If you’ve been handed a deadline by a customer or a tender, talk to us early: the timeline is nearly always set by remediation, not paperwork.

Frequently asked questions

How long does certification take?

If your environment already meets the controls: days for standard, two to four weeks for Plus including audit scheduling. If it doesn’t, remediation sets the timetable – typically two to six weeks for an SME with moderate gaps.

Can we fail?

Yes, both levels. Standard assessments are returned with feedback if answers reveal non-compliance; Plus audits fail if devices don’t withstand testing. In practice, a provider that pre-checks everything against the controls – as Indigo IT does before any client submission – makes a failed formal assessment rare.

Does Cyber Essentials make us secure?

It makes you resistant to the common, automated attacks that cause most SME breaches – which is genuinely valuable – but it’s a baseline, not a ceiling. It says nothing about backup quality, incident response or staff behaviour. Treat it as the floor your security stands on, not the building.

Matt profile picture

Matt Elson
Managing Director

Passionate about empowering UK SMBs with innovative IT, telecoms, and cybersecurity solutions. As a Director at INDIGO IT, I believe in the power of technology to drive growth and innovation in a free market. With a career dedicated to B2B cloud technologies and IT solutions, I thrive in the fast-paced world of UK telecommunications, helping businesses navigate and embrace the future.