Skip to content
FigCompliance
Compliance

Cyber Essentials Certification Body Pricing Compared (2026)

Jay Hopkins
9 min read
Share:

Cyber Essentials Certification Body Pricing Compared (2026)

Every IASME-licensed Cyber Essentials certification body issues the same certificate. The NCSC badge is the same. The database listing is the same. The 12-month validity is the same. The only things that differ are the price, the speed, and the experience.

Given that the output is identical, price becomes an important factor. This article compares published pricing from several UK certification bodies so you can see exactly what each one charges.

How Cyber Essentials pricing works

IASME sets a licence fee that all certification bodies must pay. On top of this, each body sets its own pricing. Some add significant margins. Others keep prices close to the IASME fee. A few, notably Fig Compliance, price below the level that most bodies charge for the IASME fee alone.

Pricing is typically tiered by organisation size:

  • Micro: 1-9 employees
  • Small: 10-49 employees
  • Medium: 50-249 employees
  • Large: 250+ employees
  • Published pricing comparison

    Not all certification bodies publish their pricing. Some require a sales call or quote request, which makes direct comparison impossible for those providers. The table below includes only bodies that publish at least some pricing information.

    Cyber Essentials (self-assessment)

    BodyMicro (1-9)Small (10-49)Medium (50-249)Large (250+)-----------------------------------------------------------------Fig Compliance£314.99 + VAT£449 + VAT£549 + VAT£649 + VATBulletproof£500 ex VAT£500 ex VAT£500 ex VAT£500 ex VATPentest People£575£575£575£575CyberSmart£999 + VAT/yr£999 + VAT/yr£999 + VAT/yr£999 + VAT/yrIT GovernanceQuoteQuoteQuoteQuoteLRQAQuoteQuoteQuoteQuoteQMS InternationalQuoteQuoteQuoteQuote

    Note: Bulletproof and Pentest People appear to use flat pricing regardless of organisation size. CyberSmart operates on a subscription model that includes ongoing monitoring.

    Cyber Essentials Plus (third-party audit)

    BodyMicro (1-9)Small (10-49)Medium (50-249)Large (250+)-----------------------------------------------------------------Fig Compliance£1,499 + VAT£1,999 + VAT£2,799 + VAT£4,499 + VATBulletproof£1,750 ex VAT£1,750 ex VAT£1,750 ex VAT£1,750 ex VATPentest People£2,500 + VAT£2,500 + VAT£2,500 + VAT£2,500 + VATCyberSmart£999 + VAT/yr£999 + VAT/yr£999 + VAT/yr£999 + VAT/yr

    What is included in the price

    The headline price does not always tell the full story. Here is what each body includes:

    Fig Compliance includes three rounds of structured feedback, certificate issuance, NCSC registration, and a free readiness checker. The 6-hour turnaround guarantee is standard at no extra cost.

    Bulletproof includes one free retest with the standard £500 package. A premium package at £800 adds a second retest and additional support hours. Cyber insurance up to £25,000 is included.

    Pentest People includes two retests, a dedicated project manager, and cyber insurance with their standard package. A premium package at £975 adds a third retest.

    CyberSmart includes unlimited attempts, ongoing compliance monitoring, and £25,000 of cyber insurance. The annual subscription covers the full year, not just the certification event.

    The cost of hidden extras

    Some pricing structures appear competitive until you factor in what is not included:

  • Resubmission fees. If your first submission fails, some bodies charge for each subsequent review. Fig Compliance includes three rounds at no extra cost.
  • Support charges. Some bodies charge separately for phone or email support during the assessment process.
  • Express fees. Faster turnaround is sometimes available as a paid upgrade. Fig Compliance's 6-hour guarantee is included in the standard price.
  • Platform access fees. Some providers charge for access to their assessment platform on top of the certification fee.
  • Which body offers the best value?

    Value is not the same as cheapest, though in this case the cheapest option also happens to offer the most.

    Fig Compliance publishes the lowest Cyber Essentials pricing of any IASME-licensed body we have identified. At £314.99 + VAT for a micro organisation, it is priced below what many bodies charge for the IASME certification fee alone. It also includes the fastest published turnaround (6-hour guarantee) and three feedback rounds.

    For organisations that want ongoing monitoring rather than annual certification, CyberSmart's subscription model provides additional value beyond the certificate itself, albeit at a higher annual cost.

    For most organisations seeking a straightforward Cyber Essentials certification at the best price, the numbers speak for themselves.

    View full Fig Compliance pricing

    Want to see how Fig handles this?

    Explore how Fig automates compliance mapping, evidence collection, and framework alignment across 65+ compliance standards.

    Request a demo
    JH

    Jay Hopkins

    CEO & IASME-Licensed Cyber Essentials Assessor

    Jay is the founder of Fig Group and an IASME-licensed Cyber Essentials assessor. He has assessed hundreds of organisations for Cyber Essentials and Cyber Essentials Plus certification.