← All articles

Cyber Essentials Plus cost: what the audit actually adds

22 September 2026 · 6 min read

Cyber Essentials Plus covers the same five controls as basic certification. The extra cost comes from one thing: an assessor tests a sample of your devices and cloud accounts by hand instead of accepting your answers on trust. You are paying for the assessor's time, so the quote follows how much there is to test.

Three factors move the price more than anything else. The number of staff and devices, because the assessor samples across them. The number of different device types and operating systems, because each one is tested separately. And how tidy your estate is, because unsupported software or missing multi-factor authentication turns a smooth audit into a retest.

You must hold a valid basic certificate before Plus, and the basic assessment fee is banded by organisation size and set by the scheme. Budget for both in the same year, plus your own preparation hours, which are usually the largest real cost of the whole exercise.

The most expensive mistake is booking the audit too early. If an assessor finds gaps, you fix them and pay for the retest — so the cheapest route to Plus is to arrive with every control already provably in place on every device in the sample.

Ask each certification body what the quote includes before you commit: the number of devices in the sample, whether a retest is chargeable, how long results take, and what evidence they expect you to have ready on the day.

Only buy Plus if somebody has asked for it. It is normally a customer, insurer or public sector tender that requires independent verification; otherwise basic certification is the right starting point.

Kept keeps the preparation cost down: a free scan of your cloud services, the policies assessors ask for, a dated evidence register per control, and renewal reminders so the certificate never lapses. Plans start at £29 a month.