Cheap Cyber Essentials › Hidden costs
The assessment fee is the number everybody compares, because it is the only number anybody publishes. For an organisation whose controls already meet the standard, it is also the entire cost, and that is a genuinely common outcome. For everyone else it is the smallest line on the bill.
The awkward part is that the other lines are invisible until you start. You cannot see the cost of replacing an out-of-support firewall until somebody checks the firmware version, and by then you have already bought the assessment. This article is about seeing those lines in advance, so the decision to certify is made with the real figure rather than the advertised one.
The fee is the part you can already see
The assessment fee here follows IASME's staff bands: £320 + VAT at micro size, meaning one to nine people; £440 at small, which runs to forty-nine; £500 at medium, which runs to two hundred and forty-nine; and £600 at large, meaning anything above that. Each of those is the IASME tier price, and each is fixed by headcount rather than by how complicated your estate turns out to be.
That is worth noticing, because it means the fee carries none of the information you actually need. A twelve-person architecture practice with everything on Microsoft 365 and a thirty-person manufacturer with two unsupported machine controllers, a shared administrator account and no device inventory pay exactly the same £440. Their total costs are not remotely comparable.
Staff time, which is the largest line for most organisations
Nobody invoices you for this and it is real money all the same. Three distinct pieces of work, and they land on different people.
Building the inventory
Every device organisational data passes through, each cloud service in use, every operating system version and every piece of software facing the internet. Most organisations think they have this list and discover they have a partial one. If you have a device management platform and everyone is enrolled in it, this is an afternoon. If you have a spreadsheet last edited in 2023, three people who use their own laptops and a marketing team that signed up to four services without telling anyone, budget two to three days of somebody's attention spread across a fortnight, because the gaps only surface when you start asking.
Answering the questions
The self-assessment runs to a few dozen questions across the five controls. Answering them when you already know the answers takes a few hours. Answering them when each one triggers a small investigation takes considerably longer, and it is the investigations rather than the typing that consume the week.
Chasing people outside your organisation
This is the line that ruins timelines. If your IT is outsourced, several answers are not yours to give, and you are waiting on a supplier who has their own queue. Same for a landlord who controls the office internet connection, a software vendor who has to confirm a support status, or a parent company whose network you sit on. Each of these is a short email and a long wait. Start them on day one rather than day nine.
Replacing what has gone out of support
Unsupported software and firmware is one of the most reliable causes of a first-time failure, and it is the only cost line that can run into thousands. It is also the one people are most surprised by, because the kit still works perfectly well.
The usual offenders are not desktops. They are the things nobody has looked at in five years: a router or firewall the internet provider installed and never updated, a network attached storage box, a wireless access point, an old handset still receiving mail, a Windows Server edition that quietly reached end of life, or a line-of-business application that only runs on a version of something that no longer gets patches.
There are three ways out and only one of them costs nothing. Update it, if a supported firmware or version exists. Replace it, which is the cost. Or remove it from scope entirely, which is legitimate where the device genuinely does not touch organisational data and can be properly segregated, and is not legitimate as a way of pretending a problem is not there.
Licence upgrades to get multi-factor authentication
Multi-factor authentication is required on cloud services for every user, and on some plans it is not available without moving up a tier or adding a paid component. This is a per-user, per-month cost that continues for as long as you keep the service, which makes it structurally different from a one-off purchase and easy to under-count.
Check it per service rather than in general. Organisations with a well licensed main platform routinely have a second or third service, an accounting package or a customer database, where the multi-factor option is not on the plan they bought. Multiply the monthly difference by the number of users and by twelve before you decide whether to upgrade the plan or change the service.
Tidying up administrator rights
Day-to-day accounts should not hold local administrator rights, and administrative accounts should be separate and used only for administrative work. Removing those rights is free. Dealing with what breaks afterwards is not.
The cost here is entirely in the software that was installed on the assumption of administrator access, and in the people who have to stop doing something the way they have always done it. Expect a short period of tickets. Budget a day of IT time for a small organisation and rather more if you have specialist applications that were installed once, years ago, by somebody who no longer works there.
The lines people forget
| Line | Typical size | When it applies |
|---|---|---|
| Personal devices brought into scope | Either a device purchase or the time to separate work data properly | Anywhere staff use their own phones or laptops for work |
| A device management platform | Per user, per month, ongoing | Where you cannot otherwise demonstrate what is on each device |
| Supplier assistance | Whatever your IT contract charges for out-of-scope work | Almost always, if IT is outsourced and the contract is a fixed-scope one |
| Password manager rollout | Modest per user, plus the time to migrate | Where shared credentials are currently in a spreadsheet |
| Decommissioning something properly | A day, sometimes two | Where the answer to an end-of-life device is to retire it rather than replace it |
| A second attempt | The tier fee again, plus the delay | Where a submission fails outside the free resubmission window |
How to estimate yours before you commit
Half a day, no purchase required, and it will get you within a reasonable margin.
- List everything in scope, including the network equipment and the things nobody thinks of as computers. The list itself is the single most useful artefact in the whole exercise.
- Check the vendor support status of every operating system, firmware version and internet-facing application on that list. Anything already out of support, or falling out within six months, is a cost line with a number attached.
- Check multi-factor authentication availability on each cloud service against the plan you actually hold, not the plan the vendor's marketing page describes.
- Count the accounts with administrator rights and identify which applications depend on them.
- Add up the staff days at whatever your organisation costs per day, and include the supplier's chargeable time if IT is outsourced.
Add the assessment fee at the end. For a well run estate the total is the fee and a couple of days of somebody's time. For an inherited estate with unmanaged devices it can be several thousand pounds, most of which is replacement hardware and licence uplifts you were going to have to deal with eventually anyway.
The case for doing the estimate even if you do not certify
That list of costs is not a Cyber Essentials cost. It is a list of things in your organisation that are unsupported, unmanaged or unprotected, priced. If a client or insurer has asked for the certificate, you are going to spend it. If nobody has asked yet, the estimate is still the most useful half day you will spend this quarter, because it tells you what you are carrying.
Is the assessment fee ever the whole cost?
Often, yes. An organisation where every device is managed, everything is in support, multi-factor authentication is on across every cloud service and nobody works from an administrator account has nothing to fix, so the fee plus a few hours of someone answering questions is the total. That is a realistic outcome, not a marketing line.
Does the price change if our estate is complicated?
No. The tier price is set by staff headcount, so a straightforward twenty-person estate and a messy one both pay £440 + VAT. Complexity changes how long you spend getting ready and what you have to fix, not the assessment fee.
We outsource our IT. Will they charge us for this?
Check the contract before you start. Many fixed-scope support agreements treat compliance work as chargeable, and several of the questionnaire answers are only obtainable from them. Ask for an estimate in writing at the same time as you ask for the answers, so it is not a surprise on the invoice.
Can we spread the remediation over more than one year?
Not if it affects the five controls, because the assessment is pass or fail against them as they stand on the day you submit. What you can do is sequence the work: fix what the controls require now, and plan the wider improvements the exercise exposed over a longer period.
Want the total before you commit?
Tell us what your setup looks like and we will tell you which of these lines apply to you and which do not, including when the honest answer is that the fee is the whole cost.