Cyber Essentials Accreditation: the UK guide to getting and keeping your certificate (2026)
The phrase "Cyber Essentials accreditation" is used widely to describe the process of getting certified - but strictly speaking, accreditation applies to IASME, not to the organisations it certifies. This guide explains the accreditation chain, who sits where, and the fastest, cheapest route to joining it in 2026.

Section 01
Cyber Essentials Accreditation: the UK guide to getting and keeping your certificate (2026)
Most UK organisations searching for "Cyber Essentials accreditation" mean one thing: how do we get ourselves on the Cyber Essentials register, display the badge, and satisfy a procurement, tender, insurance, or supplier-onboarding requirement. That is the practical question this guide answers in full.
It is also worth clearing up the terminology up front, because the scheme itself distinguishes between three different roles in the chain, and understanding the chain is the fastest way to make a good decision about who to work with.
Section 02
The Cyber Essentials chain: who accredits whom
Three levels matter:
1. The National Cyber Security Centre (NCSC) created the Cyber Essentials scheme and owns the standard. The NCSC does not certify organisations directly.
2. IASME is the NCSC's delivery partner for the scheme. IASME licenses the organisations that can issue certificates - these are the certification bodies. The live IASME directory is the authoritative source for current participation.
3. IASME-licensed certification bodies (including Fig Group) then certify individual organisations against the five Cyber Essentials controls.
In formal scheme language: IASME is the NCSC's delivery partner for Cyber Essentials. Certification bodies are IASME-licensed. End organisations are certified - they receive a Cyber Essentials certificate.
In everyday usage, "Cyber Essentials accreditation" is used interchangeably with "Cyber Essentials certification" to describe the act of obtaining the certificate. Both mean the same thing to the procurement and tender teams asking for it. Either term will get you to the same place through the IASME certificate search.
Section 03
What "Cyber Essentials accreditation" actually gives you
When your organisation completes the process, you receive:
- A Cyber Essentials certificate (digital PDF) from an IASME-licensed body, valid for 12 months from the date of issue.
- An entry on the public IASME certificate search showing the certificate details available for verification. Use the issuing body's records to clarify any details the public result does not show.
- Rights to use the Cyber Essentials badge on your website, tender responses, email signatures, and marketing materials.
- Scheme-level cyber liability insurance may be available to eligible UK organisations under the IASME-arranged policy. Check domicile, turnover, whole-organisation certification, opt-in and the current policy terms; it is not automatic for every certificate holder. (The policy is arranged by IASME's insurance partner and is communicated at the time the certificate is issued.)
That package is what procurement teams, insurance underwriters, and public-sector buyers mean when they say "show us your Cyber Essentials accreditation."
Section 04
The two levels of accreditation
Cyber Essentials is the baseline: a verified self-assessment against the five controls, reviewed by an IASME-licensed assessor through the scheme's online portal. Check the certification level specified in your contract or procurement requirements. Basic CE must not be assumed to satisfy a requirement for Plus. For example, SJP has publicly described a Cyber Essentials Plus or Device as a Service route for Partner Practices; see the SJP guidance and primary sources.
Cyber Essentials Plus adds independent technical testing against the same five controls. The Plus assessment may be delivered by a different appropriately licensed body; agree the Basic certificate, scope and timing with that body. A buyer may require Plus for a particular contract, but defence contracts can specify other Defence Cyber Certification levels or equivalence. Read the actual procurement terms. Fig Group publishes a separate Plus price from £1,499.99 + VAT for its smallest tier.
The self-assessment submission is identical for both levels. Plus is not a separate questionnaire - it is the same answers, independently tested.
Section 05
How to get Cyber Essentials accreditation, end to end
The Basic self-assessment can be completed online. Plus technical testing has separate access and scheduling requirements.
1. Scope your organisation. Include the in-scope work devices and cloud services under the v3.3 requirements. A router supplied to a home worker by the organisation is in scope; other home routers are outside scope, so apply the required firewall controls on the user's device. Determine headcount to fix your tier.
2. Check readiness. Run Fig Group's free readiness check against the five controls, or read the applicable NCSC requirements. Check firewall configuration, cloud-user MFA, high or critical security updates within the scheme window and supported software on in-scope devices. These are review prompts, not a ranked failure-rate claim.
3. Choose a certification body. Four checks before you pay:
- Published or quoted price. Compare the complete assessment package, size tier, VAT and support scope; a quote-only offer does not establish that a body is more expensive.
- Published SLA in working hours. "A few days" is not a turnaround. Ask for a number in writing.
- Current IASME licence for the required scheme on the certification-body directory. Ask IASME to clarify a mismatch before ordering.
- Defined re-submission rights. If the first submission is flagged, how many free re-submissions come with the purchase, and what does the feedback look like?
4. Buy the assessment. Confirm the provider's payment, portal-access and VAT-invoice process before ordering; these vary by offer.
5. Complete the self-assessment. Allow time to verify your inventory and answers. Provide supporting evidence where the assessor or questionnaire requests it; completion time depends on the organisation.
6. Submit. Once the submission is in, the clock sits with the certification body. Fast bodies - including Fig Group - return a decision inside 6 working hours. Other bodies have their own written clocks; clarification and remediation can also extend the end-to-end timeline.
7. Receive the certificate and listing. On a pass, the certificate is issued digitally and can be checked through the IASME certificate search. Eligible UK-domiciled organisations with turnover under £20 million and whole-organisation Basic certification may opt in to the IASME-arranged insurance; check the policy terms and election.
8. Use the accreditation. Publish the badge. Include the PDF in tender responses. Add a standing line to supplier-onboarding packs.
Section 06
What it costs in 2026
There is no single IASME-standard customer price range for every certification body. Check IASME's direct route and dated provider offers for the same size tier, VAT treatment, assessment-only scope and optional support. The scheme sets assessment requirements; bodies set their own customer offers.
Fig Group publishes Cyber Essentials from £299.99 + VAT for the Micro tier - Fig Group's published standalone Micro price as of the current offer, and fixed across the full pricing page.
Section 07
How quickly you can get accredited
There is no assessment reason this takes days. The assessment itself is variable according to scope, response quality and review. End-to-end time can also include clarification or remediation.
The fastest IASME-licensed bodies in the UK now commit to 6 working hours from clean submission to issued certificate. Fig Group operates a published 6-hour turnaround guarantee. That is the shortest SLA from any IASME-licensed certification body in the UK at the time of writing.
For organisations up against a tender deadline, this is decisive. A complete, compliant submission received before the cutoff can fall within the six-working-hour guarantee, subject to the published terms.
Section 08
Keeping your accreditation
Cyber Essentials certificates are valid for 12 months. To stay accredited:
- Plan renewal 60-90 days before expiry to avoid any gap in current certification.
- Track scheme changes. New applications from 27 April 2026 use v3.3; accounts started earlier may continue under v3.2. Check the applicable requirements before recertifying.
- Monitor in-scope devices continuously - especially applicable patch windows, MFA coverage and supported software. Drift can create renewal gaps even when the prior certificate was valid.
Organisations that want a stronger signal often progress from Cyber Essentials to Cyber Essentials Plus at the next renewal cycle, and from Plus to IASME Cyber Assurance or ISO 27001 when the procurement or regulatory requirement demands it.
Section 09
How Cyber Essentials accreditation compares to other UK marks
Swipe across the table to view all columns.
| Mark | Scope | Typical cost (small org) | Validity |
|---|---|---|---|
| Cyber Essentials | 5 technical controls, self-assessed + verified | Compare current Basic offers by size and support | Check issued expiry |
| Cyber Essentials Plus | Same controls, independently tested | Compare scoped technical assessment quotes | Check issued expiry |
| IASME Cyber Assurance (L1/L2) | Broader assurance scheme | Compare the selected level and provider offer | Check scheme terms |
| ISO/IEC 27001 | Information-security management system | Compare accredited certification and surveillance scope | Check certificate cycle and surveillance terms |
Cyber Essentials is deliberately narrower than ISO 27001 or IASME Cyber Assurance. That is what makes it quick, cheap, and widely accepted as a baseline. It is not intended to replace a full information-security management system - it is intended to raise the minimum bar.
Section 10
Why Fig Group is the best choice for Cyber Essentials accreditation in 2026
Three measurable facts:
- Fastest. 6-hour turnaround on compliant submissions - the shortest published SLA from any IASME-licensed certification body in the UK.
- Cheapest. Cyber Essentials from £299.99 + VAT - the lowest published price for a standalone assessment from any IASME-licensed body in the UK.
- Verifiable. The Cyber Essentials licence is independently verifiable through its Blockmark badge and registry link on the trust page. 5.00 / 5 on Google across verified reviews.
And three qualitative ones:
- Online end to end. Payment, portal access, submission, feedback, and certificate are all handled digitally. No sales calls required.
- Detailed written feedback on any failed submission, with three free re-submissions included.
- Published SLA and price - both on the website, not gated behind a contact form.
Cyber Essentials accreditation should be quick, cheap, and clear. Fig Group is built to operate that way by default.
Section 11
Bottom line
"Cyber Essentials accreditation" in everyday UK usage means getting a current Cyber Essentials certificate from an IASME-licensed body and checking it through the IASME certificate search. The chain runs NCSC → IASME → certification body → you. Fig Group publishes a Micro Basic assessment below £300 + VAT and a conditional six-working-hour guarantee. Eligible organisations can opt in to the separate IASME-arranged insurance. Compare the full package and verify the licence and certificate scope.
Get your Cyber Essentials accreditation from £299.99 + VAT | All pricing tiers | Free readiness check | FAQ
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Certificate: what it is, how to get one, and how long it lasts (2026)
A Cyber Essentials certificate is a dated, verifiable digital document issued by an IASME-licensed certification body. This guide covers exactly what the certificate proves, how long it is valid, how third parties verify it, and the fastest, cheapest route to getting one in 2026.
Read articleGuides
Cyber Essentials Online: the complete UK guide for 2026
Cyber Essentials is an online certification - the self-assessment, the evidence review, the assessor feedback, and the certificate itself all happen through a portal. This is what that actually looks like in 2026, what to watch for when you pick a certification body, and where the market currently sits on price and turnaround.
Read articleCompliance
DEFSTAN 05-138 - What does it mean for suppliers?
DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.
Read article

