Skip to content
Compliance

Cyber Essentials Certification Body Pricing Compared (2026)

We compare published pricing from IASME-licensed certification bodies across all organisation sizes. The differences are larger than you might expect.

office desk with smartphone and financial cha

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

Cyber Essentials Certification Body Pricing Compared (2026)

Compare Cyber Essentials and Cyber Essentials Plus prices by organisation size, without confusing a one-off certification fee with a technology subscription. This guide separates the self-assessment certificate, the Plus technical audit, support and recurring commitments so you can compare the total purchase you actually need.

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Standalone certification starts at £299.99 + VAT, with three rounds of assessor feedback and our six-working-hour commitment for compliant submissions. Read the published price evidence and turnaround terms. The six-working-hour commitment applies to Cyber Essentials assessment, not preparation or a Cyber Essentials Plus audit.

Read the complete UK Cyber Essentials cost guide for scheme fees, or the CE versus CE Plus cost guide for the difference between certification levels.

Read our latest September 2026 provider review for the current shortlist, optional platform and switching offers.

The six-working-hour Basic guarantee starts on receipt of a complete compliant submission before midday UK time on a UK business day; purchase alone does not qualify. Clarification, remediation and customer response time are separate. Plus has a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation; one formal retest within 30 days is included under its terms, and issuance requires a successful assessment.

Comparison scope: Fastest and cheapest are Fig Group’s publisher positioning for the stated Basic commitment and comparable named standalone Micro prices. Quote-only entries do not prove a complete UK market survey, and Basic-only pricing is not a combined annual software total.

Section 02

How to compare certification prices

Start with the legal organisation being certified and the number of staff. Then confirm whether the requirement is Cyber Essentials, Cyber Essentials Plus or both. A price that includes consultancy, an annual platform subscription or a combined package cannot be compared directly with a certification-only fee without accounting for those differences.

All Fig Group figures below are in GBP and exclude VAT. Select the correct organisation size before buying. Competitor prices and package terms can change: a dated figure is evidence of the published offer checked on that date, not a binding quote for your organisation. Where a current size-specific quote has not been verified, the table says to request one rather than filling the gap with an old price.

Section 03

Cyber Essentials provider pricing by organisation size

Swipe across the table to view all columns.

ProviderMicro: 1-9 staffSmall: 10-49Medium: 50-249Large: 250+
Fig Group£299.99 + VAT£399.99 + VAT£449.99 + VAT£549.99 + VAT
IASME direct published benchmark£320.00 + VAT£440.00 + VAT£500.00 + VAT£600.00 + VAT
WorkNest, formerly BulletproofRequest quoteRequest quoteRequest quoteRequest quote
Pentest PeopleRequest current quoteRequest current quoteRequest current quoteRequest current quote
GRC Solutions, formerly IT Governance£420 + VAT, checked 7 September 2026Confirm selected bandConfirm selected bandConfirm selected band
LRQARequest quoteRequest quoteRequest quoteRequest quote
CyberSmart, outside our shortlistCurrent selected-package quoteCurrent selected-package quoteCurrent selected-package quoteCurrent selected-package quote

Fig Group's current prices come from our certification catalogue. The IASME benchmark was checked on 7 September 2026. GRC Solutions' dated Micro price comes from its published certification package; check the renewal commitment and the selected size band. The IASME benchmark is shown separately from the provider shortlist, not as a recommendation for a particular engagement.

For the remaining providers, use WorkNest, Pentest People, LRQA and CyberSmart's plans to request a scoped offer. CyberSmart’s current plans present certification and software offerings separately, while its FAQ retains subscription-only and from-£675 language. Confirm the selected plan, software requirement, minimum commitment and staff-band quote; neither the FAQ figure nor a historic £999 headline establishes the current certification-only price.

Section 04

Cyber Essentials Plus provider pricing by organisation size

Cyber Essentials Plus adds independent technical verification. Confirm the existing Cyber Essentials certificate and scope before scheduling the audit. Fig Group's Plus-only fees below assume that the required Cyber Essentials certification is purchased separately or already held. The technical audit must be sequenced within the scheme's required three-month window after CE certification.

Swipe across the table to view all columns.

ProviderMicro: 1-9 staffSmall: 10-49Medium: 50-249Large: 250+
Fig Group, Plus audit only£1,499.99 + VAT£1,999.99 + VAT£2,799.99 + VAT£4,499.99 + VAT
Fig Group, CE and Plus package£1,649.99 + VAT£2,199.99 + VAT£3,024.99 + VAT£4,774.99 + VAT
WorkNestScoped audit quoteScoped audit quoteScoped audit quoteScoped audit quote
Pentest PeopleScoped audit quoteScoped audit quoteScoped audit quoteScoped audit quote
GRC SolutionsScoped audit quoteScoped audit quoteScoped audit quoteScoped audit quote
LRQAScoped audit quoteScoped audit quoteScoped audit quoteScoped audit quote
CyberSmart, outside our shortlistConfirm subscription and audit scopeConfirm subscription and audit scopeConfirm subscription and audit scopeConfirm subscription and audit scope

The Fig Group package row is a separately priced combined offer, not the sum of two standalone purchases. Compare the current package inclusions and VAT totals. The Plus audit scope, device sample, sites and remediation can affect another provider's quote. Do not assume that a price published for basic CE includes the Plus audit, or that an annual subscription includes every service you will need.

Section 05

What is included in the price?

Fig Group

Standalone Cyber Essentials includes three rounds of assessor feedback and the published six-working-hour assessment commitment for compliant submissions under the stated terms. There is no compulsory Fig Group technology subscription. Optional security and compliance tooling includes the Cyber Essentials corporate platform from £27 + VAT per month equivalent, billed annually at £324 + VAT for 1-9 corporate staff, with a one-year commitment and certification purchased separately, with 300+ integrations and support for 65+ frameworks across the platform, subject to the selected package.

CE customers receive the approved one-month platform trial offer; existing CyberSmart customers receive the three-month trial offer. Monthly payment options for technology subscribers and deferred-start two-year contracts are subject to the agreed offer terms. Certification, software and payment arrangements should each be clear before purchase.

Other providers

Request the same written breakdown from every provider: certification fee, included assessor feedback, preparation support, Plus audit, technology subscription, VAT and renewal terms. WorkNest and LRQA offer broader service engagements; scope and fees should be confirmed in their quotes. GRC Solutions describes an annually renewing certification package. CyberSmart’s FAQ advertises support and resubmissions within its described package; confirm the actual selected plan and allowance. Those are different offers, so compare the services you need and the full commitment rather than only the first displayed number.

Section 06

The cost of hidden extras

Resubmission fees. Ask how many assessment attempts or feedback rounds are included, what the time window is and what happens after the allowance. Three feedback rounds do not mean unlimited certification attempts or a guarantee of passing an unremediated submission.

Preparation support. Establish whether the provider reviews implemented controls, supplies consultancy to fix gaps, or both. Your own IT provider's remediation effort is separate from the certification fee unless expressly included.

Express fees. Compare the normal review commitment, any optional faster service and the point at which the clock starts. Read the compliant-submission and working-hours conditions before planning around a deadline.

Platform and renewal costs. Confirm whether technology is optional, the minimum subscription period, cancellation notice and renewal price. A monthly instalment can still be part of a longer contractual commitment.

Plus retesting. Ask how failed tests, remediation and repeat visits are handled. Compare the audit sample and scope instead of assuming every Plus quote buys the same work.

Section 07

Which provider offers the best value?

For buyers who want the cheapest Cyber Essentials certification and the fastest published assessment commitment, Fig Group combines transparent four-band pricing, three rounds of feedback and optional technology. Our best-provider comparison explains the wider buying criteria.

CyberSmart is outside our shortlist for buyers who prioritise standalone certification and flexible purchasing; confirm CyberSmart’s current certification-only or software package rather than assuming a universal compulsory subscription. Read the full CyberSmart comparison, trial offers and switching options. Compare package scope and terms before choosing; this article is published by Fig Group, a competing provider.

Choose your Fig Group certification and organisation size or discuss a CE/Plus scope with our team.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group