Insights

How Much Does Cyber Essentials Plus Cost?

What affects the cost of Cyber Essentials Plus and how to obtain a clear, fixed-price quotation.

A customer being shown a CE+ scope checklist followed by a fixed price quotation by a Plainsight Security consultant

Cyber Essentials Plus starts from £900 plus VAT with Plainsight Security. Our standard starting prices are based on the size of the organisation:

Organisation sizeNumber of employeesCyber Essentials Plus from
Micro1–9£900 + VAT
Small10–49£1,000 + VAT
Medium50–249£1,100 + VAT
Large250 or more£1,200 + VAT

These prices apply to the Cyber Essentials Plus technical audit. If your organisation does not already hold a sufficiently recent Cyber Essentials certificate, the separate Cyber Essentials assessment will also be required.

The final price can be affected by the complexity of the organisation’s technology. We therefore complete a short scoping exercise and provide a fixed quotation before any work begins.

Why does Cyber Essentials Plus cost more than Cyber Essentials?

Cyber Essentials and Cyber Essentials Plus assess the same five technical controls:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

The difference is how those controls are assessed.

Cyber Essentials is a verified self-assessment. Your organisation completes a questionnaire, which is reviewed by a qualified assessor.

Cyber Essentials Plus includes an independent technical audit. An assessor tests a representative sample of your devices and checks that the controls described in your Cyber Essentials assessment work in practice.

This additional technical testing requires more time, planning and specialist expertise, which is why Cyber Essentials Plus costs more than the basic certification.

What do Plainsight Security’s starting prices mean?

Our published prices are starting points for organisations with a relatively straightforward and consistently managed environment.

For example, a micro organisation with a small number of centrally managed Windows laptops, Microsoft 365 and a single office may qualify for the £900 plus VAT starting price.

A similarly sized organisation could require more work if it has:

  • Several operating systems
  • Physical or virtual servers
  • Multiple offices
  • Numerous internet-facing services
  • Remote workers in different countries
  • Employee-owned devices
  • Several cloud platforms
  • Inconsistent device configurations
  • Multiple IT providers

Employee numbers provide a useful starting point, but they do not always reflect the amount of technical work required.

This is why we confirm the scope before providing a fixed quotation. You know the full price before the engagement starts, with no unexpected costs appearing after the audit has been booked.

Is Cyber Essentials included in the price?

Cyber Essentials is a prerequisite for Cyber Essentials Plus. The Plus audit must normally be completed within three months of achieving the associated Cyber Essentials certification.

There are three common situations.

You already hold Cyber Essentials

If your organisation has achieved Cyber Essentials recently enough, we may be able to proceed directly to the Cyber Essentials Plus audit.

The published CE+ starting price would apply, subject to confirming the technical scope.

You need both certifications

If you have not yet achieved Cyber Essentials, we can arrange the Cyber Essentials assessment and Cyber Essentials Plus audit as part of the same overall engagement.

The Cyber Essentials assessment fee will be added separately to the CE+ audit price.

Your existing certificate is too old

If your Cyber Essentials certificate falls outside the permitted period for completing the Plus audit, a new Cyber Essentials assessment will be required.

We can confirm what is needed when reviewing your existing certificate and proposed audit dates.

What determines the final price?

Several factors can affect the amount of work required to complete a Cyber Essentials Plus audit.

Number of devices

A larger device estate can require more planning, evidence collection and testing.

Although representative sampling is used for parts of the audit, the whole in-scope estate must comply with the Cyber Essentials requirements.

Variety of device types

Testing a group of devices built and managed in the same way is usually more straightforward than assessing an environment containing:

  • Windows computers
  • macOS computers
  • Linux workstations
  • Physical servers
  • Virtual servers
  • Mobile devices
  • Thin clients
  • Employee-owned equipment

Each distinct device type or configuration may need to be represented in the audit sample.

Internet-facing systems

The audit includes checks of the organisation’s internet-facing infrastructure.

This can include:

  • Public IP addresses
  • Firewalls and routers
  • VPN gateways
  • Remote-access services
  • Web servers
  • Email gateways
  • Cloud-hosted systems
  • Other externally accessible services

An organisation with a single internet connection and standard firewall will normally be simpler to assess than one operating several networks and public services.

Cloud platforms

Cloud services that store or process organisational data can form part of the certification scope.

These may include:

  • Microsoft 365
  • Google Workspace
  • Microsoft Azure
  • Amazon Web Services
  • Google Cloud
  • Cloud-based business applications
  • Identity and access-management platforms

Using a cloud provider does not automatically transfer every Cyber Essentials responsibility to that provider. Your organisation must still secure the accounts, permissions and configurations it controls.

Locations and remote workers

The scope may include:

  • One or more offices
  • Home workers
  • International locations
  • Separate networks
  • Remote-access arrangements
  • On-site or remote audit activity

Most audits can be conducted remotely, depending on the environment. If on-site attendance or significant travel is required, this will be discussed during scoping.

Technical readiness

An organisation that already meets the Cyber Essentials requirements is likely to progress through the audit more smoothly.

Issues that commonly cause delays include:

  • Unsupported operating systems
  • Missing security updates
  • Unpatched applications
  • Inactive endpoint protection
  • Missing multi-factor authentication
  • Excessive administrator privileges
  • Unmanaged devices
  • Incorrect firewall configurations
  • Incomplete asset records
  • Inconsistent security settings

Addressing these problems before the audit reduces the risk of failed tests, delays and additional work.

What does the Cyber Essentials Plus audit include?

The precise audit activities depend on the confirmed scope, but the assessment normally includes:

  • Confirmation of the certification scope
  • External vulnerability assessment
  • Authenticated internal vulnerability checks
  • Testing of representative user devices and servers
  • Verification of security update management
  • Malware-protection checks
  • Email and web-based malware tests
  • Cloud-service and MFA checks where applicable
  • Review of administrative account separation
  • Collection and assessment of audit evidence
  • Reporting and certification processing

Cyber Essentials Plus is a defined technical audit against the five Cyber Essentials controls. It should not be confused with a penetration test, which investigates a broader and separately agreed range of vulnerabilities and attack paths.

What should you check when comparing prices?

Not every quotation necessarily includes the same level of support.

When comparing Cyber Essentials Plus providers, check whether the price includes:

  • The Cyber Essentials assessment
  • Support with the self-assessment questionnaire
  • Scope confirmation
  • The complete CE+ technical audit
  • Remote or on-site testing
  • Travel expenses
  • Remediation guidance
  • Retesting
  • Certification processing
  • Support during the engagement
  • VAT

An apparently cheaper quotation may exclude preparation support, retesting or other elements you expected to be included.

A clear quotation should explain what is covered, what assumptions have been made and whether any circumstances could change the price.

Is the cheapest Cyber Essentials Plus provider the best?

Every authorised Certification Body assesses organisations against the same Cyber Essentials requirements. However, the service surrounding the audit can vary.

Consider whether you will receive:

  • Direct access to the assessor
  • Clear preparation guidance
  • Help understanding failed checks
  • Practical remediation advice
  • Flexible scheduling
  • Plain-English communication
  • Retesting after remediation
  • A clear fixed price

A higher price does not automatically mean a better service. Equally, the lowest headline price may not represent the lowest overall cost if important elements are charged separately.

The best comparison is based on the complete service rather than the audit price alone.

How can you reduce the cost and disruption?

Good preparation makes the audit easier to scope and complete.

Before the assessment:

  • Maintain an accurate inventory of devices and software.
  • Remove or replace unsupported systems.
  • Apply outstanding security updates.
  • Confirm that MFA is enabled where required.
  • Review user and administrator accounts.
  • Standardise device configurations.
  • Check that endpoint protection is active.
  • Identify every internet-facing service.
  • Resolve known vulnerabilities.
  • Make appropriate users and devices available for testing.

These controls should be maintained throughout the year, not introduced only for the audit.

Frequently asked questions

How much does Cyber Essentials Plus cost for a micro organisation?

Cyber Essentials Plus starts from £900 plus VAT for a micro organisation with 1 to 9 employees.

The final price depends on the number and variety of devices, locations, systems and services within scope.

How much does Cyber Essentials Plus cost for a small organisation?

Cyber Essentials Plus starts from £1,000 plus VAT for a small organisation with 10 to 49 employees.

How much does Cyber Essentials Plus cost for a medium organisation?

Cyber Essentials Plus starts from £1,100 plus VAT for a medium organisation with 50 to 249 employees.

How much does Cyber Essentials Plus cost for a large organisation?

Cyber Essentials Plus starts from £1,200 plus VAT for a large organisation with 250 or more employees.

The final quotation will reflect the scale and complexity of the environment.

Do I need Cyber Essentials first?

Yes. Your organisation must achieve Cyber Essentials before completing Cyber Essentials Plus.

If you need both certifications, Plainsight Security can arrange the complete route and provide a combined quotation.

Does every device get tested?

The whole in-scope estate must comply, but representative sampling is used for parts of the technical audit.

The number of devices selected for testing depends on the size and variety of the estate.

Can the audit be conducted remotely?

Most Cyber Essentials Plus audits can be completed remotely, depending on the organisation’s systems and testing arrangements.

On-site testing can be discussed where it is necessary or preferred.

What happens if a test fails?

The assessor will explain which requirement was not met. The organisation may have an opportunity to correct the issue and complete further testing within the scheme’s permitted remediation process.

Is Cyber Essentials Plus a penetration test?

No. Cyber Essentials Plus is a prescribed technical audit of the five Cyber Essentials controls.

A penetration test has a separately agreed scope and investigates a broader range of exploitable vulnerabilities and real-world attack paths.

Get a fixed Cyber Essentials Plus price

Our Cyber Essentials Plus prices start from:

  • Micro organisations: £900 plus VAT
  • Small organisations: £1,000 plus VAT
  • Medium organisations: £1,100 plus VAT
  • Large organisations: £1,200 plus VAT

Tell Plainsight Security a little about your users, devices, locations and technical environment. We will confirm the scope and provide a clear, fixed-price quotation before any work begins.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights