
Budget for the Cyber Essentials assessment separately from the work needed to get ready. Before requesting a quote, establish which devices and services are in scope, check their condition and decide who will resolve any gaps. Ask for a written breakdown rather than treating one headline price as the whole project.
IASME separates self-led preparation using free resources from paid support, and prices the basic assessment by organisation size.[5] Your first decision is therefore how much help you need, not which package looks cheapest. Prepare a short readiness brief, then ask suppliers to price the same work so you can compare their answers fairly.
Establish what the assessment will cover
Start with a record of the equipment and services people use for work. Include remote staff and personally owned devices rather than counting only the laptops in the office. IASME’s scope guidance includes devices used to access organisational data or services, including personal phones used for work email.[1] Ask your assessor about uncertain cases before setting the budget.
Record each device’s owner, operating system and support status. Add cloud services and identify who administers them. Have someone check the list against actual working arrangements: a director’s old tablet or a contractor’s access should not depend on somebody remembering it during the assessment. Keep passwords and customer records out of this planning document.
Separate the assessment from preparation help
Ask the supplier to identify the assessment fee and any optional preparation charge as separate items. Find out whether preparation means explaining questions, reviewing your answers or making technical changes. Name the person who will gather information internally. Even with outside help, assign somebody in the business to check that the answers describe how you actually work.
Download the questions before paying. IASME recommends preparing answers in advance and makes the question set available free of charge.[2] Mark anything you cannot answer confidently and ask for help with those specific areas. Avoid buying a broad consultancy package before you know whether the problem is missing information, unclear responsibility or work that needs doing.
Price the gaps before replacing equipment
Ask your IT provider to check the support position of the systems in scope. IASME states that unsupported software within the assessment scope prevents certification.[2] For each affected item, request a proposed remedy and its cost. Do not assume every older laptop needs replacing, or that paying for an assessment will resolve a software problem.
Separate configuration work from purchases. Ask whether a supported upgrade is available, whether the existing hardware can run it and what testing is needed for business applications. Where replacement is proposed, request costs for setup, data migration and secure disposal as well as the device itself. Give each change an owner and an agreed maintenance window.
Check what a Plus quote includes
If a customer asks for Cyber Essentials Plus, confirm that requirement before accepting a quote for the basic assessment. IASME says Plus adds a technical audit, with the price quoted individually according to the size and complexity of the network.[2] Ask the certification body to confirm the scope and required preparation rather than assuming a standard package fits.
Request written details of the audit arrangements, your team’s expected involvement and any follow-up charges. Ask what happens if a device is unavailable or a finding needs remedial work. Distinguish fixing a problem from checking it again. Keep the customer’s deadline visible, but do not agree a completion date until the assessor and technical team have reviewed the work.
Allow for keeping the controls in place
Treat the preparation project and ongoing service as separate budget decisions. For each new tool or support arrangement, ask whether the charge is one-off or recurring, who owns the subscription and how cancellation works. Check your existing IT agreement before buying overlapping services. Request an explanation of any additional licence rather than accepting an unexplained bundle.
Cyber Essentials certificates expire after 12 months, and IASME says you must enter the information again when recertifying.[2] Put a review date in the diary before renewal. Keep the device record and answers available to the next person responsible, then agree who checks changes when staff join, equipment is replaced or a new cloud service is introduced.
Bring a readiness brief to the conversation
Write a brief containing your intended scope, known gaps, required certification level and deadline. Ask for a quote that separates assessment, preparation, remedial work and ongoing charges. Include assumptions and exclusions. Where a supplier cannot price something yet, ask what investigation is needed and whether that investigation is chargeable before authorising it.
If you need help reviewing the technical work, bring that brief to BMT and discuss your small-business cyber security setup. Start with what needs checking, then agree who will carry out each task. Confirm separately who will assess the application and what their fee includes before committing to the full project.
Sources
[1] https://iasme.co.uk/articles/scope
[2] https://iasme.co.uk/cyber-essentials/frequently-asked-questions
[5] https://iasme.co.uk/cyber-essentials/cyber-essentials-apply-now
