Cyber security audit cost UK searches almost always end in confusion, and the reason is simple: the phrase does not describe one product. Ask five UK providers to quote for a cyber security audit and you will get five documents describing five genuinely different pieces of work, priced between roughly £400 and £25,000, all using the same two words on the cover.
One is a questionnaire you fill in yourself. One is an engineer plugging a laptop into your network. One is a three-year certification programme with an accredited certification body attached to it. They are not variants of the same thing, and choosing between them on price alone is how small firms end up paying five figures for assurance nobody asked them to hold.
This guide prices every version of the work honestly. It starts by separating the five products that get sold under one name, then gives 2026 UK price bands for each, explains the day-rate arithmetic underneath every quote, and shows exactly which scope decisions move the number. If you want the offensive-testing side of the market in detail, our companion guide to penetration testing cost UK covers day rates, test types and CREST accreditation, and our breakdown of ISO 27001 certification cost covers the certification route end to end. This article is the layer above both: how to work out which one you actually need before anyone quotes you.
Every figure here is either a published price, a government statistic, or arithmetic performed on numbers stated in this article. Where the market quotes a range rather than a price, the range is given as a range. Prices exclude VAT unless stated, and reflect the UK market as it stands in 2026.
Table of contents
- What a cyber security audit actually is
- Cyber security audit cost UK: the 2026 price table
- The day-rate arithmetic behind every cyber security audit quote
- What sets the cyber security audit scope, and therefore the quote
- Cyber Essentials: the cheapest cyber security audit a UK SME can buy
- Cyber Essentials Plus: what a hands-on cyber security audit adds
- ISO 27001: the most expensive cyber security audit route
- The security posture review: the flexible middle of the cyber security audit market
- Scanning, testing and a cyber security audit are three different purchases
- Internal or external: who should run the cyber security audit
- What the cyber security audit quote does not include
- When a cyber security audit stops being optional
- A worked cyber security audit cost example
- What the UK market actually spends on assurance
- How to compare two cyber security audit quotes
- The annual cyber security audit budget a UK SME needs
- Fourteen cyber security audit questions to ask before you sign
- Common cyber security audit buying mistakes
- How to get a fair cyber security audit quote
- Frequently asked questions
- References
What a cyber security audit actually is
A cyber security audit is a structured, independent examination of how an organisation protects its information, resulting in a written opinion. That definition matters commercially, because the two load-bearing words are independent and opinion. You are not buying a fix. You are buying somebody’s documented judgement about a defined scope at a defined moment.
The three things every cyber security audit has in common
Whatever it is called, a genuine cyber security audit has a defined scope, a defined standard to measure against, and a deliverable that somebody puts their name to. Remove any one of those and you have something else: a scan, a workshop, or a sales exercise.
What a cyber security audit is not
A cyber security audit is not remediation. The report tells you what is wrong; fixing it is a separate line of spend, and on most engagements it is the larger one. A cyber security audit is also not a live measure of your cybersecurity capability — it is a snapshot, and the National Cyber Security Centre is explicit that assurance activities validate known issues only at the time they are carried out.
Why the same phrase covers five products
The UK market has never settled on one meaning. Certification bodies use the phrase cyber security audit to mean the formal assessment stage of a certification cycle. Consultancies use it to mean a posture review against a framework. Managed service providers use it to mean a health check of the estate they already run. Testers use it to mean a vulnerability assessment. All four are legitimate. None of them is interchangeable with the others, and the price gap between the cheapest and the dearest is more than twenty times.
The five products, in one place
| What gets sold as an audit | What it examines | Who signs it off | Typical UK price |
|---|---|---|---|
| Cyber Essentials self-assessment | Five technical control areas, answered by you | An IASME certification body assessor | £320–£600 +VAT |
| Cyber Essentials Plus | The same five areas, tested hands-on by an assessor | An IASME certification body assessor | £1,399–£3,499 +VAT |
| Security posture review | Controls, governance and configuration against a framework | A consultancy, unaccredited | £3,000–£10,000 |
| Vulnerability assessment | Reachable technical weaknesses on named systems | A testing provider | £2,000–£3,500 |
| ISO 27001 certification audit | A management system, in two formal stages | An accredited certification body | £6,000–£15,000 |
The rest of this guide takes each of those five in turn, prices it properly, and then puts them back together into a decision.
Cyber security audit cost UK: the 2026 price table
Here are the price bands a UK small or medium business should expect to see in 2026. These are market ranges, not quotes, and every one of them moves with scope.
The headline cyber security audit bands
Across the whole market, a cyber security audit engagement for a UK SME lands between £2,000 and £15,000. The bottom of that band buys a scoped technical assessment of a small estate. The top of it buys a two-stage certification audit against an international standard. Below £2,000 you are almost always buying a self-assessment scheme or an automated scan with a report wrapped around it, which is a legitimate purchase but a different one.
Prices by product
| Engagement | 2026 UK price | Elapsed time | Consultant days |
|---|---|---|---|
| Cyber Essentials, self-serve | £300–£500 | 1–2 weeks | 0 |
| Cyber Essentials with support | £800–£1,500 | 1–3 weeks | 1–2 |
| Cyber Essentials Plus | £1,500–£3,500 | 2–4 weeks | 1–3 |
| Vulnerability assessment, 20-person office | £2,000–£3,500 | 1–2 weeks | 2–3 |
| Full security posture assessment | £3,000–£10,000 | 4–8 weeks | 4–8 |
| External test added on top | £3,000–£10,000 | 2–3 weeks | 3–8 |
| ISO 27001 Stage 1 and Stage 2 | £6,000–£15,000 | 3–6 months | 3–9 |
Where the cyber security audit money actually goes
On most engagements the fieldwork is short and the reporting is not. A typical cyber security audit runs two to four weeks from scoping call to final report, of which only two to five days are consultant time on your systems. You are paying for the evidence review, the write-up and the readout as much as for the visit, which is why a two-day engagement rarely costs two days of anybody’s rate.
The cyber security audit price ladder, drawn
Ranked against the top of the ladder, the spread between the cheapest and dearest cyber security audit route is the single most important fact in this article.
The day-rate arithmetic behind every cyber security audit quote
Almost every cyber security audit quote in the UK is built the same way underneath, however it is presented on the front page. Somebody has estimated a number of days and multiplied it by a rate. Once you can see both halves, a quote stops being a mystery and becomes a negotiation about scope.
Every cyber security audit is days multiplied by rate
A consultancy cyber security audit is days times rate. A certification engagement is days times rate plus a scheme fee that goes to the certification body rather than the auditor. A self-assessment scheme is the scheme fee on its own, with optional days bolted on if you want help answering the questions. Those three shapes cover the entire market.
UK day rates in 2026
Rates vary far more than people expect, and the variation is not mostly about quality. Independent implementation consultants sit at £700–£1,200 a day. UK certification bodies commonly charge £900–£1,500 per auditor-day, with the larger international names at the top of that band. Offensive testers run £800–£2,500, with £1,200 a published rate for a CREST-accredited consultant. Below roughly £500 a day nobody is doing manual work; you are buying automated scanning with a template report.
What a cyber security audit day actually buys
A consultant day is not eight hours on your systems. On a typical cyber security audit, scoping, evidence review, write-up, quality review and the readout call all come out of the same pot. Ask any provider to split the quoted days between fieldwork and reporting — the answer tells you more about the engagement than the total does.
The rate ladder, scaled
Ranked against the top of the market, the spread of UK day rates is wide enough that two providers can quote the same number of days and differ by a factor of three.
Where a cyber security audit rate is negotiable and where it is not
On a certification audit the day count is barely negotiable, because it is derived from a mandatory international table rather than invented. The rate sometimes is. On a consultancy cyber security audit both are negotiable, but the honest lever is scope: fewer sites, fewer systems, more remote work. Getting three quotes against one tightly written scope statement remains the single most effective procurement move available to a small business.
What sets the cyber security audit scope, and therefore the quote
Every provider counts your organisation before they price the cyber security audit. The units differ by product, and knowing which unit applies is what lets you predict the number before it arrives.
The unit each cyber security audit product counts
| Engagement | The unit that drives the price | What does not change the price |
|---|---|---|
| Cyber Essentials | Headcount band | Number of devices, number of sites |
| Cyber Essentials Plus | Headcount band, plus network complexity | Turnover, sector |
| Security posture review | Systems in scope and framework depth | Headcount, mostly |
| Vulnerability assessment | Live hosts and external addresses | Staff numbers |
| ISO 27001 certification | Effective personnel in scope, plus sites | Device count |
Headcount is the unit more often than you think
Two of the five products price on people, not technology. That surprises firms with a small team and a large estate, and it is good news for them: a twelve-person business running four servers and ninety devices pays a micro-organisation certification fee. It is bad news the other way round, which is why a headcount-heavy, technology-light business should always price a technical assessment before a certification one.
Sites multiply, systems add
The shape of your IT infrastructure is what a scoping call is really trying to establish. Adding a second office to a certification scope usually adds audit days. Adding a second system to a posture review usually adds hours. The distinction matters when you are drawing the boundary: consolidating two sites into one scope statement can save more than trimming three systems out of it.
Remote work has quietly cut the cyber security audit number
A large share of evidence review is now done remotely, which has taken real money out of the typical cyber security audit for a distributed business. Ask explicitly what proportion of the work is remote and whether travel is charged at cost or as a fixed uplift; a two-auditor site visit to a regional office can add several hundred pounds nobody budgeted for.
The scope drivers that move a cyber security audit quote most
| Driver | Effect on the cyber security audit price | Can you control it? |
|---|---|---|
| Number of physical sites | Adds audit days and travel | Yes, via scope wording |
| In-house software development | Adds days on a certification audit | Rarely |
| Regulated or special category data | Adds depth and evidence volume | No |
| Number of cloud tenants | Adds configuration review hours | Sometimes, by consolidating |
| Bring-your-own-device | Adds sampling on hands-on testing | Yes, by policy |
| Deadline pressure | Adds a premium or removes discounts | Yes, by starting earlier |
Cyber Essentials: the cheapest cyber security audit a UK SME can buy
For most small businesses the first genuine cyber security audit they ever hold is Cyber Essentials, and it is the best-value assurance product on the UK market by a distance.
What the cheapest cyber security audit costs
Certification starts at £320 +VAT and is priced according to the size of your organisation, running to roughly £600 +VAT at the top of the small-business bands. Add optional consultant support and the all-in figure lands between £800 and £1,500. Done entirely in-house it is £300–£500. That is the whole cost.
What you get for it
This cyber security audit covers five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. You answer a question set about your estate, and an assessor at an IASME-appointed certification body reviews your answers. The NCSC describes the base scheme as a combination of self-assessment and independent audit — the independence is real, but the evidence is your own.
What changes on 27 April 2026
The scheme moves to Requirements for IT Infrastructure v3.3 on 27 April 2026. Multi-factor authentication becomes a mandatory requirement for all cloud services where it is available, so a missing MFA rollout is now an automatic fail rather than a note. A cloud service is newly defined as “an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet”, passkeys and passwordless login are explicitly recognised, and excluding infrastructure from your scope now requires a documented justification to your assessor. Budget a remediation window before you book.
Who is actually holding it
Take-up is rising fast but remains low. Five per cent of UK businesses held Cyber Essentials certification in 2025/26, up from three per cent the year before. Among large businesses the figure jumped from 21 per cent to 35 per cent, and among small businesses from five per cent to twelve per cent. Meanwhile only 24 per cent of businesses meet all five of the scheme’s technical control areas, certified or not — which tells you the certificate is measuring something real.
Certification uptake, plotted
Set against the highest figure in the series, the growth is concentrated at the larger end of the market — and the gap between large and small is the commercial signal for any firm that sells to bigger customers.
The honest cyber security audit limitation
A Cyber Essentials cyber security audit proves five controls are in place across a declared scope. It does not examine your governance, your suppliers, your incident response capability or your backups. Treating it as a full cyber security audit is the most common category error in UK small-business security, and it is the reason so many firms are surprised by what a real assessment finds afterwards.
Cyber Essentials Plus: what a hands-on cyber security audit adds
Cyber Essentials Plus is the same five control areas as the base scheme, verified by somebody else instead of asserted by you. The jump in price is real, and so is the jump in what the certificate means.
The published fee bands
The IASME certification fee is banded by organisation size: from £1,399 +VAT for micro organisations of nought to nine people, £1,699 +VAT for small organisations of ten to 49, £2,399 +VAT for medium organisations of 50 to 249, and £3,499 +VAT for large organisations of 250 or more. Individual certification bodies may add a premium on top of the scheme fee. Most UK organisations end up paying between £1,500 and £3,000 +VAT.
Fee bands in one table
| Organisation size | Headcount | Cyber Essentials Plus, from | Base certification |
|---|---|---|---|
| Micro | 0–9 | £1,399 +VAT | from £320 +VAT |
| Small | 10–49 | £1,699 +VAT | priced by size |
| Medium | 50–249 | £2,399 +VAT | priced by size |
| Large | 250+ | £3,499 +VAT | priced by size |
What the assessor actually does
An assessor performs more rigorous, independent technical testing rather than reading your answers. In practice that means a sample of your end-user devices is checked for patch levels and configuration, an external scan is run against your internet-facing addresses, and a set of malicious files and links is fired at a sampled workstation and mailbox to see whether your controls stop them. The sample size, not your total device count, is what drives the effort.
Why firms fail the hands-on cyber security audit
The failure modes are boringly consistent: a laptop two months behind on browser updates, a local administrator account somebody kept for convenience, an unsupported operating system on one machine in the corner, and cloud services without MFA. None of those cost money to fix. They cost time, and the time has to happen before the assessment, not during it.
Budget the remediation, not just the cyber security audit
The commonest budgeting mistake at this cyber security audit level is funding the certificate and not the work. If you have never been assessed, assume one to three consultant days of preparation on top of the fee — a pre-assessment gap analysis from a specialist typically runs £750–£1,500 for a small business. Firms that skip it frequently pay the assessment fee twice.
ISO 27001: the most expensive cyber security audit route
At the top of the market sits the certification audit against ISO/IEC 27001. It is a genuinely different cyber security audit: you are certifying a management system, not a set of controls, and the audit is only the visible end of a much larger programme.
The two-stage cyber security audit structure
Initial certification is a two-stage audit. Stage 1 is a readiness review in which the auditor checks that your documentation, scope, risk assessment and Statement of Applicability exist and hang together. Stage 2, usually four to eight weeks later, tests whether you are actually doing what you documented. Stage 1 is short, often a single day. Stage 2 carries most of the days and most of the fee.
What the cyber security audit itself costs
UK certification bodies commonly charge between £900 and £1,500 per auditor-day. A small business needing three to five total days for initial certification is therefore looking at roughly £3,000–£7,000 of audit fee before travel and the annual certificate maintenance charge. Across the market, a Stage 1 plus Stage 2 engagement is quoted at £6,000–£15,000, and first certification takes three to six months from a standing start.
Why the day count is not invented
Audit days are derived from a mandatory international table published by the International Accreditation Forum, based on the number of effective personnel in scope, then adjusted for complexity, risk, site count and how much can be done remotely. Two auditors quoting the same scope should land within a day of each other. If they do not, one of them has misunderstood your scope — which is a useful thing to discover during procurement rather than during Stage 2.
The three-year cycle nobody budgets for
A certificate is valid for three years, but you are audited every year. Each surveillance audit is a partial re-examination, typically around a third of the initial audit days, so expect roughly 30–40 per cent of the year-one audit fee annually. Recertification at the end of the cycle usually takes around two-thirds of the original audit days. For a thirty-person UK business a realistic three-year total lands at roughly £30,000–£55,000 rather than the year-one number.
The three-year shape, drawn
Taking the top of the small-business band — five days at £1,500, or £7,500 of year-one audit fee — the cycle scales as follows using the percentages above.
Everything that is not the cyber security audit fee
The cyber security audit itself is the cheap part. A professional gap analysis by a consultant runs £2,500–£5,000. Implementation support carries UK day rates of £700–£1,200, and fixed-price small-business packages commonly land between £8,000 and £20,000. Year-one totals for a UK SME therefore sit at £6,000–£15,000 where the internal team does the work and considerably more where it does not. Our full ISO 27001 certification cost breakdown splits that figure line by line.
The security posture review: the flexible middle of the cyber security audit market
Between the certification schemes and the technical tests sits the cyber security audit product most consultancies actually mean: a posture review measured against a recognised framework, with no certificate at the end.
What this cyber security audit costs and how long it takes
A full security posture assessment runs £3,000–£10,000 and takes four to eight weeks end to end, of which four to eight days are consultant time. It is the most common first purchase for a business that has outgrown Cyber Essentials but has no contractual reason to certify.
What it examines
A competent posture-review cyber security audit covers endpoint protection, email security, network security, identity and access controls, backup and recovery readiness, incident response capability and policy documentation. Good ones map every finding to a named framework control so the report can be reused rather than re-commissioned.
Which framework to ask for
Ask for the framework by name, because it changes the depth and the price. The NCSC’s ten-step guidance is the lightest and most readable for a UK small business. The Cyber Assessment Framework is the right choice if you supply the public sector. The CIS Controls give the most directly actionable output for a technical team. NIST’s framework travels best if your customers are American.
Framework choice, compared
| Framework | Best when | Relative depth | Certificate? |
|---|---|---|---|
| NCSC 10 Steps | First formal review, UK SME | Light | No |
| CIS Controls | Technical team wants a work queue | Medium | No |
| NIST Cyber Security Framework | US customers or investors | Medium | No |
| Cyber Assessment Framework | Public sector supply chain | Deep | No |
| ISO/IEC 27001 | A customer contractually requires it | Deep | Yes |
The one cyber security audit clause to insist on
A posture review does not include threat intelligence, continuous monitoring or offensive penetration testing, and a good provider will say so at the scoping call. Insist that the cyber security audit report ranks findings by risk with an owner and an effort estimate against each one, not merely a red-amber-green grid. A posture review whose output cannot be turned into a costed plan on the day it lands has failed at the only job that justified its price.
Scanning, testing and a cyber security audit are three different purchases
The single most expensive confusion in the cyber security audit market is between an automated scan, a manual test and an audit. They answer different questions, and buying the wrong one is how firms end up with a document that satisfies nobody.
The question each cyber security audit answers
A vulnerability scan answers “what known weaknesses can a tool see from here?”. A penetration test answers “what could a skilled attacker actually do with them?”. A cyber security audit answers “does this organisation manage security in a way somebody independent will vouch for?”. Only the third produces an opinion, and only the third is what a customer questionnaire or an insurer is usually asking for.
Prices side by side
| Purchase | Question answered | UK price | Repeatable? |
|---|---|---|---|
| Automated vulnerability scan | What known weaknesses are visible? | Under £500 a day equivalent | Continuously |
| Vulnerability assessment with a report | Which of those actually matter here? | £2,000–£3,500 | Quarterly |
| External test, manual | What could an attacker chain together? | £3,000–£10,000 | Annually |
| Security posture review | Are the right controls designed and running? | £3,000–£10,000 | Annually |
| Certification audit | Will somebody accredited vouch for us? | £6,000–£15,000 | Three-year cycle |
What the NCSC actually says about testing
The National Cyber Security Centre defines this kind of assurance work as gaining confidence by attempting to breach systems using the same tools and techniques an adversary might. It is explicit that the exercise is not a magic bullet, that findings are valid only at the time of the test, and that risk assessment and decisions on applying fixes remain your responsibility. That last point is the commercial one: nobody you pay takes the risk off you.
Why the accreditation question is different here
For offensive testing, accreditation genuinely narrows the field, and CREST membership or the Cyber Scheme is the usual shortlist filter. Note that the NCSC’s CHECK scheme is mandatory only for central government systems at OFFICIAL and above; if your organisation is not public sector, testing does not need to be conducted by a CHECK service provider. Our penetration testing cost UK guide sets out how much accreditation actually adds to a quote.
The cyber security audit sequencing that saves money
Run the cheap cyber security audit first. A vulnerability assessment before a posture review means the obvious technical findings are already fixed, so you are not paying a senior consultant to write down that a server needs patching. A posture review before a certification audit means Stage 1 does not turn into an expensive gap analysis. Reversing that order is the most reliable way to pay twice.
Internal or external: who should run the cyber security audit
Not every review needs to be bought. The choice between an internal cyber security audit and an external one is a question about what the output has to survive, not about capability.
What the UK market actually does
Among businesses that carried out a vulnerability audit in the last year, 39 per cent used external auditors only. Charities split differently, with 45 per cent internal only and 25 per cent external only — a reasonable proxy for what happens when budget rather than requirement drives the decision.
When an internal cyber security audit is genuinely enough
An internal cyber security audit is fine when the audience is your own management team, the purpose is to build a work queue, and nobody outside the business will ever read it. An internal cyber security audit is free apart from time, it can be repeated quarterly, and it builds knowledge that stays in the building.
When it is not
The moment the output has to persuade a customer, an insurer, a regulator or a board that is not taking your word for it, internal work stops being sufficient. Independence is the product. An assessment signed by the person responsible for the controls it examines carries no weight in a supplier questionnaire, however competent that person is.
The middle option people forget
A structured self-assessment against a published framework, reviewed by an external consultant for one day, costs a fraction of a full engagement and catches most of the obvious problems. For a business that is two years away from needing certification, it is usually the correct answer.
Internal versus external, compared
| Factor | Internal review | External engagement |
|---|---|---|
| Cash cost | Staff time only | £2,000–£15,000 |
| Credibility with a customer | Low | High |
| Frequency achievable | Quarterly or better | Annual |
| Blind spots | Whatever the team already assumes | Whatever falls outside scope |
| Knowledge retained | Stays in the business | Leaves with the consultant |
| Useful for insurance or tender | Rarely | Usually |
What the cyber security audit quote does not include
Read the cyber security audit exclusions before the total. On most engagements the excluded items are worth more than the negotiating room in the price.
Remediation
The report is the deliverable. Fixing what it finds is separate work at a separate rate, and on a first assessment it is routinely two to five times the assessment fee. Ask for an indicative remediation range at scoping, before anybody has looked at anything, and treat a provider who refuses to give one as a warning.
Retesting
Confirming a finding is closed usually costs extra unless the contract says otherwise. A single retest day is cheap insurance and is worth negotiating into the original engagement rather than buying afterwards.
Evidence gathering by your own team
Somebody in your business will spend real hours pulling policies, screenshots, asset lists and configuration exports. On a certification route that internal time is frequently the largest single line in the cyber security audit in the true cost and it never appears on any invoice.
Ongoing tooling
If the assessment recommends multi-factor authentication everywhere, a managed detection service or a proper backup platform, those are recurring costs that start after the engagement ends. A cyber security audit that changes nothing has no ongoing cost; a useful one always does.
Scheme and certificate fees
On certification routes there is an annual certificate maintenance charge distinct from the audit fee, and on Cyber Essentials the scheme fee sits alongside anything a consultant charges you. Ask which line goes to the assessor and which goes to the scheme.
In and out of a cyber security audit, at a glance
| Item | Usually in the quote | Usually extra |
|---|---|---|
| Scoping call and scope statement | Yes | — |
| Fieldwork and evidence review | Yes | — |
| Written report and readout call | Yes | — |
| Remediation work | — | Yes |
| Retest after fixes | Sometimes | Often |
| Travel to additional sites | Sometimes | Often |
| Board or customer presentation | — | Yes |
| Annual certificate maintenance | — | Yes |
When a cyber security audit stops being optional
Most SMEs do not buy a cyber security audit because they want it. They buy it because somebody made it a condition of doing business, and the identity of that somebody determines which product you need.
The four things that force a cyber security audit
Customer contracts are the biggest driver in the UK small-business market: a tender or a supplier questionnaire asks for a certificate and the sale depends on it. Insurers are second, increasingly asking for evidence of specific controls before quoting. Regulators are third. Investors and acquirers are fourth, and their diligence questions are usually the most detailed of the four.
Regulated sectors and their cadence
| Driver | What it requires | Cadence | Who it applies to |
|---|---|---|---|
| Card payment rules | Internal and external testing, plus scanning | At least every 12 months | Anyone handling card data |
| Card payment rules, segmentation | Segmentation testing | Annual for merchants, six-monthly for service providers | Segmented environments |
| EU financial resilience regime | Threat-led testing of live systems | At least every three years | Identified financial entities |
| UK data protection law | Appropriate technical and organisational measures | Continuous | Every controller and processor |
| Public sector supply chain | Framework-based assessment | Contract dependent | Suppliers to government |
| Customer tender | Usually a named certificate | Annual renewal | Anyone selling B2B |
Read the requirement before you buy a cyber security audit
The wording of the clause matters more than the category. “Cyber Essentials or equivalent” and “ISO 27001 certified” are separated by roughly £15,000 in year one. A surprising number of firms buy the expensive one because nobody read the sentence carefully, and an equally surprising number buy the cheap one and then fail the tender.
Insurance is a growing driver
Forty-seven per cent of UK businesses hold some form of cyber insurance, rising to 55 per cent of small businesses and 61 per cent of medium ones — but only ten per cent hold a specific cyber policy, rising to 24 per cent of medium and 32 per cent of large businesses. As underwriters tighten their control questions, that gap is exactly where the cyber security audit starts paying for itself in premium terms rather than risk terms.
Data protection law does not name a product
UK data protection law requires appropriate technical and organisational measures without naming a scheme, so no certificate discharges the duty. What an assessment gives you is documented evidence that you considered the question and acted on the answer, which is the thing regulators look for when something has gone wrong.
A worked cyber security audit cost example
Abstract ranges are hard to budget against, so here is one firm’s cyber security audit costed five ways. Every figure below uses rates and fees already stated in this article.
The business
A 40-person UK professional services firm across two offices. Sixty-two endpoints, four servers, one Microsoft 365 tenant, two line-of-business SaaS platforms, one public-facing website and one on-premises file server. No in-house software development, no card data, no special category data beyond ordinary HR records. It sits in the small organisation band of ten to 49 people.
Route A: Cyber Essentials only
Consultant support at £1,200 plus a certification fee of £400 gives £1,600. Elapsed time is one to three weeks. This is the right answer if a customer contract says “Cyber Essentials or equivalent” and nothing else in the business is pushing.
Route B: Cyber Essentials Plus
The base certificate at £400, plus the small-organisation Plus fee of £1,699, plus one day of remediation support at £950, gives £3,049. Elapsed time is two to four weeks. This is the right answer when a customer specifically names Plus, which is increasingly common in public sector supply chains.
Route C: security posture review
Five consultant days at £950 gives £4,750, with the report and readout included. Elapsed time is four to eight weeks. This is the right answer when the board has asked “how exposed are we?” and no certificate is required.
Route D: posture review plus an external test
Route C at £4,750 plus three testing days at £1,200, or £3,600, gives £8,350. This is the right answer when the firm has a public-facing application and wants both the governance view and the technical one.
Route E: ISO 27001, year one
A gap analysis at £3,500, implementation support at £9,000, and a five-day Stage 1 and Stage 2 audit at £1,200 a day, or £6,000, gives £18,500. Elapsed time is three to six months. This is the right answer only when a contract requires the certificate.
The five routes, side by side
| Route | Line items | Total | Elapsed |
|---|---|---|---|
| A — Cyber Essentials | £1,200 support + £400 fee | £1,600 | 1–3 weeks |
| B — Cyber Essentials Plus | £400 + £1,699 + £950 | £3,049 | 2–4 weeks |
| C — Posture review | 5 days at £950 | £4,750 | 4–8 weeks |
| D — Posture review + test | £4,750 + 3 days at £1,200 | £8,350 | 6–10 weeks |
| E — ISO 27001 year one | £3,500 + £9,000 + £6,000 | £18,500 | 3–6 months |
The same five routes, plotted
Scaled against the dearest route, the shape of the decision is clear: the first three routes together cost half of the fifth.
Trimming the cyber security audit number without losing the point
Route D drops to £5,950 if the external test is cut from three days to one, because the day rate does not move. Route C drops to £2,850 if the review covers three consultant days instead of five, which is realistic when a vulnerability assessment has already cleared the technical noise. The lever is always days, never rate.
What the UK market actually spends on assurance
Before you decide your own number, it helps to know what everyone else is doing — and the government’s own survey shows a cyber security audit market that is far thinner than the marketing suggests.
How many businesses are being attacked
Just over four in ten UK businesses, 43 per cent, identified a breach or attack in the last twelve months, which is roughly 612,000 organisations. Around three in ten charities, 28 per cent, said the same, about 57,000. By size the figures are 42 per cent of micro businesses, 46 per cent of small, 65 per cent of medium and 69 per cent of large.
How few businesses commission a cyber security audit
Thirty per cent of businesses carried out a risk assessment covering security in the last year. Thirty-two per cent used security monitoring tools, 22 per cent ran mock phishing exercises, 18 per cent carried out a vulnerability audit, 13 per cent commissioned testing and 11 per cent used threat intelligence. In other words, more than four in five UK businesses did not commission any form of external technical examination at all.
Assurance activity, plotted
Scaled against the most common activity in the series, the drop-off from monitoring to testing is steep.
Why the reported cost of a breach is misleading
The median perceived cost of the most disruptive breach was £0 for businesses overall and £30 for medium and large ones, with an interquartile range of £0 to £200. That is not evidence that incidents are cheap. It is evidence that most identified incidents are low-grade phishing that got stopped, and that firms without an assurance programme have no mechanism for counting the cost of the ones that were not.
Governance is the real gap
Board-level responsibility for security sat at 31 per cent of businesses, rising from 29 per cent of micro firms to 37 per cent of small, 52 per cent of medium and 68 per cent of large. Formal incident response plans were rarer still at 25 per cent overall, 21 per cent of micro businesses, 57 per cent of medium and 76 per cent of large. A governance-focused cyber security audit is aimed squarely at that gap, and it is the cheapest of the three deep products.
What this means for your cyber security audit budget
If your business commissions any external assessment at all, you are already in the top fifth of UK organisations by assurance activity. That is worth knowing when a provider implies you are behind. You may simply be being sold to.
How to compare two cyber security audit quotes
Two cyber security audit quotes for the same words can differ by a factor of five and both be honest. Comparing them fairly takes about twenty minutes and one table.
Normalise the scope first
Write your own scope statement before you approach anybody, and send the same one to every provider. Name the sites, the systems, the cloud tenants, the headcount and the framework. Any provider who quotes against a scope they wrote themselves is quoting a different job from the others.
Then normalise the days
Ask every provider for days and rate separately, split between fieldwork and reporting. A £9,000 quote at six days and £1,500 and a £9,000 quote at twelve days and £750 are very different engagements, and only one of them has senior people on it.
Read the cyber security audit deliverable clause
Ask to see a redacted sample report before you sign. The difference between a useful cyber security audit and an expensive one is almost entirely in the report: whether findings carry risk ratings, named owners, effort estimates and framework references, or whether they carry adjectives.
The comparison table to use
| What to compare | Weak answer | Strong answer |
|---|---|---|
| Scope statement | “Your IT environment” | Named sites, systems, tenants and exclusions |
| Days and rate | A single total | Days split fieldwork versus reporting, rate shown |
| Framework | “Industry best practice” | A named standard and version |
| Who does the work | Unnamed team | Named consultant and qualifications |
| Sample report | Not available | Redacted example provided |
| Retest | Silent | Included or priced explicitly |
| Remediation | Bundled without a figure | Separately priced or explicitly excluded |
| Conflict of interest | The auditor also sells the fix | Declared, with an option to decline |
The conflict question is not theoretical
A provider who assesses you and then sells you the remediation is not automatically wrong — for a small business it is often the practical choice, and our own IT security and compliance work is frequently bought that way. But the conflict should be on the table in writing, with a clear route to take the report elsewhere. A firm that will not say so unprompted has answered a different question.
The cheapest cyber security audit is sometimes correct
If two providers quote the same days against the same scope with the same framework and comparable people, take the cheaper one. Assurance is a professional service, not a luxury good, and paying a premium for a logo buys nothing a customer questionnaire will ever ask about.
The annual cyber security audit budget a UK SME needs
A cyber security audit is a recurring cost, not a project. Budgeting it annually rather than reactively is what stops the number ambushing a board meeting.
A realistic annual cyber security audit figure by size
| Business size | Minimum sensible annual spend | Typical | What that buys |
|---|---|---|---|
| Under 10 people | £400 | £1,500–£2,000 | Certification, renewed annually |
| 10–49 people | £1,600 | £3,000–£5,000 | Hands-on certification, or a review |
| 50–249 people | £3,000 | £8,000–£15,000 | Review plus testing, renewed |
| Certified to ISO 27001 | £2,625 | £3,000–£8,000 | Surveillance audit and maintenance |
Alternate the deep work
Very few small businesses need every cyber security audit product every year. A workable three-year rhythm is certification renewed annually, a technical assessment in year one, a governance review in year two and testing again in year three. That keeps the annual line predictable and still refreshes every view of the estate inside a single cycle.
Fund remediation separately
Set aside a remediation budget alongside the assessment budget, at roughly one to two times the assessment fee for a first engagement and considerably less thereafter. An organisation that funds the assessment but not the fixes has bought a document, and a document that sits in a shared drive is the most expensive form of assurance there is.
The two-year effect
A second-year cyber security audit is cheaper in real terms because the evidence already exists. The policies, asset register, access reviews and supplier list are built once. Firms that let all of that lapse and rebuild it before each assessment pay the build cost repeatedly, which is the single most avoidable overspend in this market.
Fourteen cyber security audit questions to ask before you sign
Send these to every provider in writing. The answers will separate the shortlist faster than any price comparison.
On scope
What exactly is in scope, expressed as named sites, systems and cloud tenants? What is explicitly out of scope? What happens to the fee if we discover an additional system mid-engagement?
On effort and people
How many days, split between fieldwork and reporting? What is the day rate? Who specifically will do the work, and what qualifications do they hold? Will any of it be subcontracted?
Cyber security audit questions on the deliverable
Can we see a redacted sample report? Will findings carry risk ratings, named owners and effort estimates? Will each finding map to a named framework control? Is a management summary suitable for a board included?
On what happens next
Is a retest included, and if not, what does one cost? Do you also sell remediation, and if so how is that conflict managed? What does the same engagement cost next year?
The cyber security audit questions in a list
| # | Question | What a good answer looks like |
|---|---|---|
| 1 | What is in scope? | A written list, not a category |
| 2 | What is out of scope? | Explicit exclusions, in writing |
| 3 | How many days? | A number, split by activity |
| 4 | What is the day rate? | A figure, not “it varies” |
| 5 | Who does the work? | A named person with credentials |
| 6 | Which framework? | A named standard and version |
| 7 | Can we see a sample report? | Yes, redacted, before signature |
| 8 | How are findings rated? | A published, consistent scale |
| 9 | Is remediation included? | No, and priced separately |
| 10 | Is a retest included? | Yes, or a stated price |
| 11 | How much is done remotely? | A percentage and a travel policy |
| 12 | What internal time do we need? | Hours, by role |
| 13 | What does year two cost? | A figure, given up front |
| 14 | Who owns the report? | You do, with no reuse restriction |
Common cyber security audit buying mistakes
Every one of these has been made by a competent business with a sensible budget. They are procurement failures, not technical ones.
Buying assurance nobody asked for
The most expensive cyber security audit mistake is buying certification when the requirement said “or equivalent”. Read the clause, then buy to the clause. If nobody has asked at all, a posture review is almost always the better first purchase because it tells you which certificate you would pass.
Confusing a scan report with an opinion
A 200-page tool export with a logo on the cover is not a cyber security audit, and a customer questionnaire will not accept it as one. If the deliverable has no named human judgement in it, you have bought a scan.
Letting the provider write the cyber security audit scope
The provider who writes your scope also decides your price and, more importantly, decides what does not get looked at. Write it yourself, even badly, then let them improve it.
Timing it against a deadline
Deadline pressure removes every negotiating lever you have and adds a premium on top. Certification takes three to six months from a standing start; hands-on assessment takes two to four weeks plus remediation. Start when the tender appears, not when it closes.
Treating the certificate as the outcome
The certificate is evidence of the outcome. The outcome is the set of controls the cyber security audit made you build. Firms that optimise for passing rather than for improving get both, badly, and pay for the privilege twice — see our cyber security checklist for accountancy firms for what the control set actually looks like in practice.
Not budgeting the internal hours
Somebody has to gather the evidence, answer the questions and chase the fixes. On a certification route that is frequently three to five days of one person’s month for several months. It is the largest invisible line in the whole exercise.
Buying once
A cyber security audit is a snapshot. The NCSC is explicit that findings hold good only at the time of the exercise, and gaps between exercises are often a year or more. A one-off purchase in year one that is never repeated leaves you with a certificate that is technically valid and evidentially stale.
How to get a fair cyber security audit quote
Procurement does more for the final number than negotiation does. These five moves cost nothing and reliably move the price.
Write the cyber security audit scope statement yourself
One page. Named sites, named systems, named cloud tenants, headcount, the framework you want, and an explicit exclusions list. Send the identical document to three providers. This alone routinely produces a 30 per cent spread you can act on, because it exposes which provider was quietly quoting for less work.
Ask for the day count before the price
A provider who will give you days and rate separately is easy to compare and easy to trust. One who will only give a total is asking you to buy on brand. On certification routes you can sanity-check the day count against the published international duration table before you negotiate anything.
Fix the free findings first
Enable multi-factor authentication everywhere, patch the estate, remove local administrator rights, and turn on the logging you already pay for. Every one of those is free, all four are checked by every cyber security audit product on the market, and clearing them shortens the engagement and shrinks the remediation bill behind it.
Book the cyber security audit outside the rush
Demand is seasonal, driven by financial year ends and tender cycles. Booking six to eight weeks out, rather than into a deadline, keeps the discount available and gets you a named consultant instead of whoever is free.
Buy the cyber security audit cycle, not the event
If you know you will run a cyber security audit annually, say so and ask for two- or three-year pricing. Providers discount predictable revenue, and you get rate certainty for the board. This is the single easiest saving available on any recurring cyber security audit programme.
Frequently asked questions
How much does a cyber security audit cost in the UK?
For a UK SME in 2026, expect a cyber security audit to cost £2,000 to £15,000 externally. Cyber Essentials certification starts at £320 +VAT, Cyber Essentials Plus runs £1,399–£3,499 +VAT by size, a full posture assessment is £3,000–£10,000, and an ISO 27001 Stage 1 and Stage 2 audit is £6,000–£15,000.
Is Cyber Essentials a real cyber security audit?
Yes, but a narrow one. The base scheme combines self-assessment with independent review by an appointed certification body, covering five technical control areas. It does not examine governance, suppliers, backups or incident response, so it should not be presented as a full assessment of the business.
How long does a cyber security audit take?
Two to four weeks from scoping call to final report for most engagements, of which two to five days are consultant time. A full posture assessment takes four to eight weeks. First-time ISO 27001 certification takes three to six months.
How often should we run a cyber security audit?
Annually is the working answer for anything certificate-bearing, because certificates renew annually. For technical assessment, at least once a year and after any significant change, which is also the cadence the card payment rules require of anyone handling card data.
Can we do a cyber security audit ourselves?
You can run a cyber security audit yourself, and for a first pass you probably should. An internal cyber security audit against a published framework costs nothing but time and finds most of the obvious problems. It stops being sufficient the moment somebody outside the business has to believe the result.
What is the difference between an audit and a penetration test?
An audit forms an independent opinion on whether security is managed properly across a defined scope. A test attempts to break in and reports what worked. The first satisfies questionnaires, insurers and regulators; the second finds the specific technical holes the first will never see.
Does a cyber security audit make us secure?
No. A cyber security audit tells you where you stand. The NCSC is explicit that assurance exercises are not a magic bullet, that findings hold only at the time of the exercise, and that risk decisions and remediation remain your responsibility.
Will our insurer accept the report?
Sometimes, and increasingly. Underwriters typically want evidence of specific controls rather than a cyber security audit report as such, so an assessment that maps findings to named controls is far more useful to an insurer than one that grades you out of ten.
What does it cost in year two?
Less. A surveillance cyber security audit on a certification route is roughly 30 to 40 per cent of the year-one audit fee, and repeat consultancy engagements are cheaper because the evidence already exists. Budget one to two times the assessment fee for remediation in year one, and considerably less thereafter.
Which cyber security audit should we buy first?
If a contract names a certificate, buy that certificate. If nothing external is driving it, buy a posture review, because it tells you which certificate you would pass and what it would take to pass the next one up.
References
NCSC — Cyber Essentials Overview
IASME — Upcoming Changes to the Cyber Essentials Scheme, April 2026 Update
Cyber Security Breaches Survey 2025/2026
Cyber Security Breaches Survey Collection
Cyber Governance Code of Practice
NCSC — Cyber Security Board Toolkit
NCSC — 10 Steps to Cyber Security
NCSC — Risk Management Guidance
NCSC — Cyber Assessment Framework
NCSC — Penetration Testing Guidance
NCSC — CHECK Scheme Introduction
NCSC — CHECK Information for Buyers
NCSC — Vulnerability Management
NCSC — Vulnerability Scanning Tools and Services
NCSC — Device Security Guidance
NCSC — Multi-Factor Authentication for Online Services
NCSC — Supply Chain Security
ICO — A Guide to Data Security
ICO — Data Protection Impact Assessments
ISO27001security.com — ISO/IEC 27001 Reference
International Accreditation Forum
NIST SP 800-115 — Technical Guide to Information Security Testing and Assessment
NIST SP 800-30 — Guide for Conducting Risk Assessments
CIS Critical Security Controls
OWASP Web Security Testing Guide
FIRST — Common Vulnerability Scoring System
National Vulnerability Database
PCI Security Standards Council
PCI Security Standards Document Library
FCA — Operational Resilience