Cyber security audit cost UK searches almost always end in confusion, and the reason is simple: the phrase does not describe one product. Ask five UK providers to quote for a cyber security audit and you will get five documents describing five genuinely different pieces of work, priced between roughly £400 and £25,000, all using the same two words on the cover.

One is a questionnaire you fill in yourself. One is an engineer plugging a laptop into your network. One is a three-year certification programme with an accredited certification body attached to it. They are not variants of the same thing, and choosing between them on price alone is how small firms end up paying five figures for assurance nobody asked them to hold.

This guide prices every version of the work honestly. It starts by separating the five products that get sold under one name, then gives 2026 UK price bands for each, explains the day-rate arithmetic underneath every quote, and shows exactly which scope decisions move the number. If you want the offensive-testing side of the market in detail, our companion guide to penetration testing cost UK covers day rates, test types and CREST accreditation, and our breakdown of ISO 27001 certification cost covers the certification route end to end. This article is the layer above both: how to work out which one you actually need before anyone quotes you.

Every figure here is either a published price, a government statistic, or arithmetic performed on numbers stated in this article. Where the market quotes a range rather than a price, the range is given as a range. Prices exclude VAT unless stated, and reflect the UK market as it stands in 2026.

What a cyber security audit actually is

cyber security audit cost uk what smes pay b caliper fixed sliding jaws

A cyber security audit is a structured, independent examination of how an organisation protects its information, resulting in a written opinion. That definition matters commercially, because the two load-bearing words are independent and opinion. You are not buying a fix. You are buying somebody’s documented judgement about a defined scope at a defined moment.

The three things every cyber security audit has in common

Whatever it is called, a genuine cyber security audit has a defined scope, a defined standard to measure against, and a deliverable that somebody puts their name to. Remove any one of those and you have something else: a scan, a workshop, or a sales exercise.

What a cyber security audit is not

A cyber security audit is not remediation. The report tells you what is wrong; fixing it is a separate line of spend, and on most engagements it is the larger one. A cyber security audit is also not a live measure of your cybersecurity capability — it is a snapshot, and the National Cyber Security Centre is explicit that assurance activities validate known issues only at the time they are carried out.

Why the same phrase covers five products

The UK market has never settled on one meaning. Certification bodies use the phrase cyber security audit to mean the formal assessment stage of a certification cycle. Consultancies use it to mean a posture review against a framework. Managed service providers use it to mean a health check of the estate they already run. Testers use it to mean a vulnerability assessment. All four are legitimate. None of them is interchangeable with the others, and the price gap between the cheapest and the dearest is more than twenty times.

The five products, in one place

What gets sold as an auditWhat it examinesWho signs it offTypical UK price
Cyber Essentials self-assessmentFive technical control areas, answered by youAn IASME certification body assessor£320–£600 +VAT
Cyber Essentials PlusThe same five areas, tested hands-on by an assessorAn IASME certification body assessor£1,399–£3,499 +VAT
Security posture reviewControls, governance and configuration against a frameworkA consultancy, unaccredited£3,000–£10,000
Vulnerability assessmentReachable technical weaknesses on named systemsA testing provider£2,000–£3,500
ISO 27001 certification auditA management system, in two formal stagesAn accredited certification body£6,000–£15,000

The rest of this guide takes each of those five in turn, prices it properly, and then puts them back together into a decision.

Cyber security audit cost UK: the 2026 price table

cyber security audit cost uk what smes pay c2 stapler closed wedge body

Here are the price bands a UK small or medium business should expect to see in 2026. These are market ranges, not quotes, and every one of them moves with scope.

The headline cyber security audit bands

Across the whole market, a cyber security audit engagement for a UK SME lands between £2,000 and £15,000. The bottom of that band buys a scoped technical assessment of a small estate. The top of it buys a two-stage certification audit against an international standard. Below £2,000 you are almost always buying a self-assessment scheme or an automated scan with a report wrapped around it, which is a legitimate purchase but a different one.

Prices by product

Engagement2026 UK priceElapsed timeConsultant days
Cyber Essentials, self-serve£300–£5001–2 weeks0
Cyber Essentials with support£800–£1,5001–3 weeks1–2
Cyber Essentials Plus£1,500–£3,5002–4 weeks1–3
Vulnerability assessment, 20-person office£2,000–£3,5001–2 weeks2–3
Full security posture assessment£3,000–£10,0004–8 weeks4–8
External test added on top£3,000–£10,0002–3 weeks3–8
ISO 27001 Stage 1 and Stage 2£6,000–£15,0003–6 months3–9

Where the cyber security audit money actually goes

On most engagements the fieldwork is short and the reporting is not. A typical cyber security audit runs two to four weeks from scoping call to final report, of which only two to five days are consultant time on your systems. You are paying for the evidence review, the write-up and the readout as much as for the visit, which is why a two-day engagement rarely costs two days of anybody’s rate.

The cyber security audit price ladder, drawn

Ranked against the top of the ladder, the spread between the cheapest and dearest cyber security audit route is the single most important fact in this article.

UK audit engagements, top of each published band, scaled against the dearest
ISO 27001 Stage 1 and 2 £15,000
Full posture assessment £10,000
Cyber Essentials Plus £3,500
Vulnerability scan and report £3,500
Cyber Essentials with support £1,500

The day-rate arithmetic behind every cyber security audit quote

cyber security audit cost uk what smes pay d hard hat domed brim

Almost every cyber security audit quote in the UK is built the same way underneath, however it is presented on the front page. Somebody has estimated a number of days and multiplied it by a rate. Once you can see both halves, a quote stops being a mystery and becomes a negotiation about scope.

Every cyber security audit is days multiplied by rate

A consultancy cyber security audit is days times rate. A certification engagement is days times rate plus a scheme fee that goes to the certification body rather than the auditor. A self-assessment scheme is the scheme fee on its own, with optional days bolted on if you want help answering the questions. Those three shapes cover the entire market.

UK day rates in 2026

Rates vary far more than people expect, and the variation is not mostly about quality. Independent implementation consultants sit at £700–£1,200 a day. UK certification bodies commonly charge £900–£1,500 per auditor-day, with the larger international names at the top of that band. Offensive testers run £800–£2,500, with £1,200 a published rate for a CREST-accredited consultant. Below roughly £500 a day nobody is doing manual work; you are buying automated scanning with a template report.

What a cyber security audit day actually buys

A consultant day is not eight hours on your systems. On a typical cyber security audit, scoping, evidence review, write-up, quality review and the readout call all come out of the same pot. Ask any provider to split the quoted days between fieldwork and reporting — the answer tells you more about the engagement than the total does.

The rate ladder, scaled

Ranked against the top of the market, the spread of UK day rates is wide enough that two providers can quote the same number of days and differ by a factor of three.

UK assurance day rates 2026, scaled against the top of the range
Offensive tester, top of range £2,500
Certification body, top of range £1,500
CREST-accredited published rate £1,200
Certification body, floor £900
Independent consultant, floor £700

Where a cyber security audit rate is negotiable and where it is not

On a certification audit the day count is barely negotiable, because it is derived from a mandatory international table rather than invented. The rate sometimes is. On a consultancy cyber security audit both are negotiable, but the honest lever is scope: fewer sites, fewer systems, more remote work. Getting three quotes against one tightly written scope statement remains the single most effective procurement move available to a small business.

What sets the cyber security audit scope, and therefore the quote

cyber security audit cost uk what smes pay e trophy cup two side handles

Every provider counts your organisation before they price the cyber security audit. The units differ by product, and knowing which unit applies is what lets you predict the number before it arrives.

The unit each cyber security audit product counts

EngagementThe unit that drives the priceWhat does not change the price
Cyber EssentialsHeadcount bandNumber of devices, number of sites
Cyber Essentials PlusHeadcount band, plus network complexityTurnover, sector
Security posture reviewSystems in scope and framework depthHeadcount, mostly
Vulnerability assessmentLive hosts and external addressesStaff numbers
ISO 27001 certificationEffective personnel in scope, plus sitesDevice count

Headcount is the unit more often than you think

Two of the five products price on people, not technology. That surprises firms with a small team and a large estate, and it is good news for them: a twelve-person business running four servers and ninety devices pays a micro-organisation certification fee. It is bad news the other way round, which is why a headcount-heavy, technology-light business should always price a technical assessment before a certification one.

Sites multiply, systems add

The shape of your IT infrastructure is what a scoping call is really trying to establish. Adding a second office to a certification scope usually adds audit days. Adding a second system to a posture review usually adds hours. The distinction matters when you are drawing the boundary: consolidating two sites into one scope statement can save more than trimming three systems out of it.

Remote work has quietly cut the cyber security audit number

A large share of evidence review is now done remotely, which has taken real money out of the typical cyber security audit for a distributed business. Ask explicitly what proportion of the work is remote and whether travel is charged at cost or as a fixed uplift; a two-auditor site visit to a regional office can add several hundred pounds nobody budgeted for.

The scope drivers that move a cyber security audit quote most

DriverEffect on the cyber security audit priceCan you control it?
Number of physical sitesAdds audit days and travelYes, via scope wording
In-house software developmentAdds days on a certification auditRarely
Regulated or special category dataAdds depth and evidence volumeNo
Number of cloud tenantsAdds configuration review hoursSometimes, by consolidating
Bring-your-own-deviceAdds sampling on hands-on testingYes, by policy
Deadline pressureAdds a premium or removes discountsYes, by starting earlier

Cyber Essentials: the cheapest cyber security audit a UK SME can buy

cyber security audit cost uk what smes pay f warehouse pitched roof shutter

For most small businesses the first genuine cyber security audit they ever hold is Cyber Essentials, and it is the best-value assurance product on the UK market by a distance.

What the cheapest cyber security audit costs

Certification starts at £320 +VAT and is priced according to the size of your organisation, running to roughly £600 +VAT at the top of the small-business bands. Add optional consultant support and the all-in figure lands between £800 and £1,500. Done entirely in-house it is £300–£500. That is the whole cost.

What you get for it

This cyber security audit covers five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. You answer a question set about your estate, and an assessor at an IASME-appointed certification body reviews your answers. The NCSC describes the base scheme as a combination of self-assessment and independent audit — the independence is real, but the evidence is your own.

What changes on 27 April 2026

The scheme moves to Requirements for IT Infrastructure v3.3 on 27 April 2026. Multi-factor authentication becomes a mandatory requirement for all cloud services where it is available, so a missing MFA rollout is now an automatic fail rather than a note. A cloud service is newly defined as “an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet”, passkeys and passwordless login are explicitly recognised, and excluding infrastructure from your scope now requires a documented justification to your assessor. Budget a remediation window before you book.

Who is actually holding it

Take-up is rising fast but remains low. Five per cent of UK businesses held Cyber Essentials certification in 2025/26, up from three per cent the year before. Among large businesses the figure jumped from 21 per cent to 35 per cent, and among small businesses from five per cent to twelve per cent. Meanwhile only 24 per cent of businesses meet all five of the scheme’s technical control areas, certified or not — which tells you the certificate is measuring something real.

Certification uptake, plotted

Set against the highest figure in the series, the growth is concentrated at the larger end of the market — and the gap between large and small is the commercial signal for any firm that sells to bigger customers.

Cyber Essentials certification held, 2024/25 versus 2025/26, scaled to the highest figure (35%)
Large businesses, 2025/26 35%
Large businesses, 2024/25 21%
Small businesses, 2025/26 12%
Small businesses, 2024/25 5%
All businesses, 2025/26 5%

The honest cyber security audit limitation

A Cyber Essentials cyber security audit proves five controls are in place across a declared scope. It does not examine your governance, your suppliers, your incident response capability or your backups. Treating it as a full cyber security audit is the most common category error in UK small-business security, and it is the reason so many firms are surprised by what a real assessment finds afterwards.

Cyber Essentials Plus: what a hands-on cyber security audit adds

Cyber Essentials Plus is the same five control areas as the base scheme, verified by somebody else instead of asserted by you. The jump in price is real, and so is the jump in what the certificate means.

The published fee bands

The IASME certification fee is banded by organisation size: from £1,399 +VAT for micro organisations of nought to nine people, £1,699 +VAT for small organisations of ten to 49, £2,399 +VAT for medium organisations of 50 to 249, and £3,499 +VAT for large organisations of 250 or more. Individual certification bodies may add a premium on top of the scheme fee. Most UK organisations end up paying between £1,500 and £3,000 +VAT.

Fee bands in one table

Organisation sizeHeadcountCyber Essentials Plus, fromBase certification
Micro0–9£1,399 +VATfrom £320 +VAT
Small10–49£1,699 +VATpriced by size
Medium50–249£2,399 +VATpriced by size
Large250+£3,499 +VATpriced by size

What the assessor actually does

An assessor performs more rigorous, independent technical testing rather than reading your answers. In practice that means a sample of your end-user devices is checked for patch levels and configuration, an external scan is run against your internet-facing addresses, and a set of malicious files and links is fired at a sampled workstation and mailbox to see whether your controls stop them. The sample size, not your total device count, is what drives the effort.

Why firms fail the hands-on cyber security audit

The failure modes are boringly consistent: a laptop two months behind on browser updates, a local administrator account somebody kept for convenience, an unsupported operating system on one machine in the corner, and cloud services without MFA. None of those cost money to fix. They cost time, and the time has to happen before the assessment, not during it.

Budget the remediation, not just the cyber security audit

The commonest budgeting mistake at this cyber security audit level is funding the certificate and not the work. If you have never been assessed, assume one to three consultant days of preparation on top of the fee — a pre-assessment gap analysis from a specialist typically runs £750–£1,500 for a small business. Firms that skip it frequently pay the assessment fee twice.

ISO 27001: the most expensive cyber security audit route

At the top of the market sits the certification audit against ISO/IEC 27001. It is a genuinely different cyber security audit: you are certifying a management system, not a set of controls, and the audit is only the visible end of a much larger programme.

The two-stage cyber security audit structure

Initial certification is a two-stage audit. Stage 1 is a readiness review in which the auditor checks that your documentation, scope, risk assessment and Statement of Applicability exist and hang together. Stage 2, usually four to eight weeks later, tests whether you are actually doing what you documented. Stage 1 is short, often a single day. Stage 2 carries most of the days and most of the fee.

What the cyber security audit itself costs

UK certification bodies commonly charge between £900 and £1,500 per auditor-day. A small business needing three to five total days for initial certification is therefore looking at roughly £3,000–£7,000 of audit fee before travel and the annual certificate maintenance charge. Across the market, a Stage 1 plus Stage 2 engagement is quoted at £6,000–£15,000, and first certification takes three to six months from a standing start.

Why the day count is not invented

Audit days are derived from a mandatory international table published by the International Accreditation Forum, based on the number of effective personnel in scope, then adjusted for complexity, risk, site count and how much can be done remotely. Two auditors quoting the same scope should land within a day of each other. If they do not, one of them has misunderstood your scope — which is a useful thing to discover during procurement rather than during Stage 2.

The three-year cycle nobody budgets for

A certificate is valid for three years, but you are audited every year. Each surveillance audit is a partial re-examination, typically around a third of the initial audit days, so expect roughly 30–40 per cent of the year-one audit fee annually. Recertification at the end of the cycle usually takes around two-thirds of the original audit days. For a thirty-person UK business a realistic three-year total lands at roughly £30,000–£55,000 rather than the year-one number.

The three-year shape, drawn

Taking the top of the small-business band — five days at £1,500, or £7,500 of year-one audit fee — the cycle scales as follows using the percentages above.

Certification audit fee across a three-year cycle, scaled against year one
Year one, Stage 1 and Stage 2 £7,500
Year three, recertification at two-thirds £5,000
Year two, surveillance at 35 per cent £2,625

Everything that is not the cyber security audit fee

The cyber security audit itself is the cheap part. A professional gap analysis by a consultant runs £2,500–£5,000. Implementation support carries UK day rates of £700–£1,200, and fixed-price small-business packages commonly land between £8,000 and £20,000. Year-one totals for a UK SME therefore sit at £6,000–£15,000 where the internal team does the work and considerably more where it does not. Our full ISO 27001 certification cost breakdown splits that figure line by line.

The security posture review: the flexible middle of the cyber security audit market

Between the certification schemes and the technical tests sits the cyber security audit product most consultancies actually mean: a posture review measured against a recognised framework, with no certificate at the end.

What this cyber security audit costs and how long it takes

A full security posture assessment runs £3,000–£10,000 and takes four to eight weeks end to end, of which four to eight days are consultant time. It is the most common first purchase for a business that has outgrown Cyber Essentials but has no contractual reason to certify.

What it examines

A competent posture-review cyber security audit covers endpoint protection, email security, network security, identity and access controls, backup and recovery readiness, incident response capability and policy documentation. Good ones map every finding to a named framework control so the report can be reused rather than re-commissioned.

Which framework to ask for

Ask for the framework by name, because it changes the depth and the price. The NCSC’s ten-step guidance is the lightest and most readable for a UK small business. The Cyber Assessment Framework is the right choice if you supply the public sector. The CIS Controls give the most directly actionable output for a technical team. NIST’s framework travels best if your customers are American.

Framework choice, compared

FrameworkBest whenRelative depthCertificate?
NCSC 10 StepsFirst formal review, UK SMELightNo
CIS ControlsTechnical team wants a work queueMediumNo
NIST Cyber Security FrameworkUS customers or investorsMediumNo
Cyber Assessment FrameworkPublic sector supply chainDeepNo
ISO/IEC 27001A customer contractually requires itDeepYes

The one cyber security audit clause to insist on

A posture review does not include threat intelligence, continuous monitoring or offensive penetration testing, and a good provider will say so at the scoping call. Insist that the cyber security audit report ranks findings by risk with an owner and an effort estimate against each one, not merely a red-amber-green grid. A posture review whose output cannot be turned into a costed plan on the day it lands has failed at the only job that justified its price.

Scanning, testing and a cyber security audit are three different purchases

The single most expensive confusion in the cyber security audit market is between an automated scan, a manual test and an audit. They answer different questions, and buying the wrong one is how firms end up with a document that satisfies nobody.

The question each cyber security audit answers

A vulnerability scan answers “what known weaknesses can a tool see from here?”. A penetration test answers “what could a skilled attacker actually do with them?”. A cyber security audit answers “does this organisation manage security in a way somebody independent will vouch for?”. Only the third produces an opinion, and only the third is what a customer questionnaire or an insurer is usually asking for.

Prices side by side

PurchaseQuestion answeredUK priceRepeatable?
Automated vulnerability scanWhat known weaknesses are visible?Under £500 a day equivalentContinuously
Vulnerability assessment with a reportWhich of those actually matter here?£2,000–£3,500Quarterly
External test, manualWhat could an attacker chain together?£3,000–£10,000Annually
Security posture reviewAre the right controls designed and running?£3,000–£10,000Annually
Certification auditWill somebody accredited vouch for us?£6,000–£15,000Three-year cycle

What the NCSC actually says about testing

The National Cyber Security Centre defines this kind of assurance work as gaining confidence by attempting to breach systems using the same tools and techniques an adversary might. It is explicit that the exercise is not a magic bullet, that findings are valid only at the time of the test, and that risk assessment and decisions on applying fixes remain your responsibility. That last point is the commercial one: nobody you pay takes the risk off you.

Why the accreditation question is different here

For offensive testing, accreditation genuinely narrows the field, and CREST membership or the Cyber Scheme is the usual shortlist filter. Note that the NCSC’s CHECK scheme is mandatory only for central government systems at OFFICIAL and above; if your organisation is not public sector, testing does not need to be conducted by a CHECK service provider. Our penetration testing cost UK guide sets out how much accreditation actually adds to a quote.

The cyber security audit sequencing that saves money

Run the cheap cyber security audit first. A vulnerability assessment before a posture review means the obvious technical findings are already fixed, so you are not paying a senior consultant to write down that a server needs patching. A posture review before a certification audit means Stage 1 does not turn into an expensive gap analysis. Reversing that order is the most reliable way to pay twice.

Internal or external: who should run the cyber security audit

Not every review needs to be bought. The choice between an internal cyber security audit and an external one is a question about what the output has to survive, not about capability.

What the UK market actually does

Among businesses that carried out a vulnerability audit in the last year, 39 per cent used external auditors only. Charities split differently, with 45 per cent internal only and 25 per cent external only — a reasonable proxy for what happens when budget rather than requirement drives the decision.

When an internal cyber security audit is genuinely enough

An internal cyber security audit is fine when the audience is your own management team, the purpose is to build a work queue, and nobody outside the business will ever read it. An internal cyber security audit is free apart from time, it can be repeated quarterly, and it builds knowledge that stays in the building.

When it is not

The moment the output has to persuade a customer, an insurer, a regulator or a board that is not taking your word for it, internal work stops being sufficient. Independence is the product. An assessment signed by the person responsible for the controls it examines carries no weight in a supplier questionnaire, however competent that person is.

The middle option people forget

A structured self-assessment against a published framework, reviewed by an external consultant for one day, costs a fraction of a full engagement and catches most of the obvious problems. For a business that is two years away from needing certification, it is usually the correct answer.

Internal versus external, compared

FactorInternal reviewExternal engagement
Cash costStaff time only£2,000–£15,000
Credibility with a customerLowHigh
Frequency achievableQuarterly or betterAnnual
Blind spotsWhatever the team already assumesWhatever falls outside scope
Knowledge retainedStays in the businessLeaves with the consultant
Useful for insurance or tenderRarelyUsually

What the cyber security audit quote does not include

Read the cyber security audit exclusions before the total. On most engagements the excluded items are worth more than the negotiating room in the price.

Remediation

The report is the deliverable. Fixing what it finds is separate work at a separate rate, and on a first assessment it is routinely two to five times the assessment fee. Ask for an indicative remediation range at scoping, before anybody has looked at anything, and treat a provider who refuses to give one as a warning.

Retesting

Confirming a finding is closed usually costs extra unless the contract says otherwise. A single retest day is cheap insurance and is worth negotiating into the original engagement rather than buying afterwards.

Evidence gathering by your own team

Somebody in your business will spend real hours pulling policies, screenshots, asset lists and configuration exports. On a certification route that internal time is frequently the largest single line in the cyber security audit in the true cost and it never appears on any invoice.

Ongoing tooling

If the assessment recommends multi-factor authentication everywhere, a managed detection service or a proper backup platform, those are recurring costs that start after the engagement ends. A cyber security audit that changes nothing has no ongoing cost; a useful one always does.

Scheme and certificate fees

On certification routes there is an annual certificate maintenance charge distinct from the audit fee, and on Cyber Essentials the scheme fee sits alongside anything a consultant charges you. Ask which line goes to the assessor and which goes to the scheme.

In and out of a cyber security audit, at a glance

ItemUsually in the quoteUsually extra
Scoping call and scope statementYes—
Fieldwork and evidence reviewYes—
Written report and readout callYes—
Remediation work—Yes
Retest after fixesSometimesOften
Travel to additional sitesSometimesOften
Board or customer presentation—Yes
Annual certificate maintenance—Yes

When a cyber security audit stops being optional

Most SMEs do not buy a cyber security audit because they want it. They buy it because somebody made it a condition of doing business, and the identity of that somebody determines which product you need.

The four things that force a cyber security audit

Customer contracts are the biggest driver in the UK small-business market: a tender or a supplier questionnaire asks for a certificate and the sale depends on it. Insurers are second, increasingly asking for evidence of specific controls before quoting. Regulators are third. Investors and acquirers are fourth, and their diligence questions are usually the most detailed of the four.

Regulated sectors and their cadence

DriverWhat it requiresCadenceWho it applies to
Card payment rulesInternal and external testing, plus scanningAt least every 12 monthsAnyone handling card data
Card payment rules, segmentationSegmentation testingAnnual for merchants, six-monthly for service providersSegmented environments
EU financial resilience regimeThreat-led testing of live systemsAt least every three yearsIdentified financial entities
UK data protection lawAppropriate technical and organisational measuresContinuousEvery controller and processor
Public sector supply chainFramework-based assessmentContract dependentSuppliers to government
Customer tenderUsually a named certificateAnnual renewalAnyone selling B2B

Read the requirement before you buy a cyber security audit

The wording of the clause matters more than the category. “Cyber Essentials or equivalent” and “ISO 27001 certified” are separated by roughly £15,000 in year one. A surprising number of firms buy the expensive one because nobody read the sentence carefully, and an equally surprising number buy the cheap one and then fail the tender.

Insurance is a growing driver

Forty-seven per cent of UK businesses hold some form of cyber insurance, rising to 55 per cent of small businesses and 61 per cent of medium ones — but only ten per cent hold a specific cyber policy, rising to 24 per cent of medium and 32 per cent of large businesses. As underwriters tighten their control questions, that gap is exactly where the cyber security audit starts paying for itself in premium terms rather than risk terms.

Data protection law does not name a product

UK data protection law requires appropriate technical and organisational measures without naming a scheme, so no certificate discharges the duty. What an assessment gives you is documented evidence that you considered the question and acted on the answer, which is the thing regulators look for when something has gone wrong.

A worked cyber security audit cost example

Abstract ranges are hard to budget against, so here is one firm’s cyber security audit costed five ways. Every figure below uses rates and fees already stated in this article.

The business

A 40-person UK professional services firm across two offices. Sixty-two endpoints, four servers, one Microsoft 365 tenant, two line-of-business SaaS platforms, one public-facing website and one on-premises file server. No in-house software development, no card data, no special category data beyond ordinary HR records. It sits in the small organisation band of ten to 49 people.

Route A: Cyber Essentials only

Consultant support at £1,200 plus a certification fee of £400 gives £1,600. Elapsed time is one to three weeks. This is the right answer if a customer contract says “Cyber Essentials or equivalent” and nothing else in the business is pushing.

Route B: Cyber Essentials Plus

The base certificate at £400, plus the small-organisation Plus fee of £1,699, plus one day of remediation support at £950, gives £3,049. Elapsed time is two to four weeks. This is the right answer when a customer specifically names Plus, which is increasingly common in public sector supply chains.

Route C: security posture review

Five consultant days at £950 gives £4,750, with the report and readout included. Elapsed time is four to eight weeks. This is the right answer when the board has asked “how exposed are we?” and no certificate is required.

Route D: posture review plus an external test

Route C at £4,750 plus three testing days at £1,200, or £3,600, gives £8,350. This is the right answer when the firm has a public-facing application and wants both the governance view and the technical one.

Route E: ISO 27001, year one

A gap analysis at £3,500, implementation support at £9,000, and a five-day Stage 1 and Stage 2 audit at £1,200 a day, or £6,000, gives £18,500. Elapsed time is three to six months. This is the right answer only when a contract requires the certificate.

The five routes, side by side

RouteLine itemsTotalElapsed
A — Cyber Essentials£1,200 support + £400 fee£1,6001–3 weeks
B — Cyber Essentials Plus£400 + £1,699 + £950£3,0492–4 weeks
C — Posture review5 days at £950£4,7504–8 weeks
D — Posture review + test£4,750 + 3 days at £1,200£8,3506–10 weeks
E — ISO 27001 year one£3,500 + £9,000 + £6,000£18,5003–6 months

The same five routes, plotted

Scaled against the dearest route, the shape of the decision is clear: the first three routes together cost half of the fifth.

Five routes for one 40-person firm, scaled against the dearest
Route E, certification year one £18,500
Route D, posture review and test £8,350
Route C, posture review £4,750
Route B, hands-on certification £3,049
Route A, self-assessed certification £1,600

Trimming the cyber security audit number without losing the point

Route D drops to £5,950 if the external test is cut from three days to one, because the day rate does not move. Route C drops to £2,850 if the review covers three consultant days instead of five, which is realistic when a vulnerability assessment has already cleared the technical noise. The lever is always days, never rate.

What the UK market actually spends on assurance

Before you decide your own number, it helps to know what everyone else is doing — and the government’s own survey shows a cyber security audit market that is far thinner than the marketing suggests.

How many businesses are being attacked

Just over four in ten UK businesses, 43 per cent, identified a breach or attack in the last twelve months, which is roughly 612,000 organisations. Around three in ten charities, 28 per cent, said the same, about 57,000. By size the figures are 42 per cent of micro businesses, 46 per cent of small, 65 per cent of medium and 69 per cent of large.

How few businesses commission a cyber security audit

Thirty per cent of businesses carried out a risk assessment covering security in the last year. Thirty-two per cent used security monitoring tools, 22 per cent ran mock phishing exercises, 18 per cent carried out a vulnerability audit, 13 per cent commissioned testing and 11 per cent used threat intelligence. In other words, more than four in five UK businesses did not commission any form of external technical examination at all.

Assurance activity, plotted

Scaled against the most common activity in the series, the drop-off from monitoring to testing is steep.

UK businesses undertaking each assurance activity in the last 12 months, scaled to the highest (32%)
Security monitoring tools 32%
Risk assessment covering security 30%
Mock phishing exercises 22%
Vulnerability audit 18%
Commissioned technical testing 13%
Threat feeds and intelligence 11%

Why the reported cost of a breach is misleading

The median perceived cost of the most disruptive breach was £0 for businesses overall and £30 for medium and large ones, with an interquartile range of £0 to £200. That is not evidence that incidents are cheap. It is evidence that most identified incidents are low-grade phishing that got stopped, and that firms without an assurance programme have no mechanism for counting the cost of the ones that were not.

Governance is the real gap

Board-level responsibility for security sat at 31 per cent of businesses, rising from 29 per cent of micro firms to 37 per cent of small, 52 per cent of medium and 68 per cent of large. Formal incident response plans were rarer still at 25 per cent overall, 21 per cent of micro businesses, 57 per cent of medium and 76 per cent of large. A governance-focused cyber security audit is aimed squarely at that gap, and it is the cheapest of the three deep products.

What this means for your cyber security audit budget

If your business commissions any external assessment at all, you are already in the top fifth of UK organisations by assurance activity. That is worth knowing when a provider implies you are behind. You may simply be being sold to.

How to compare two cyber security audit quotes

Two cyber security audit quotes for the same words can differ by a factor of five and both be honest. Comparing them fairly takes about twenty minutes and one table.

Normalise the scope first

Write your own scope statement before you approach anybody, and send the same one to every provider. Name the sites, the systems, the cloud tenants, the headcount and the framework. Any provider who quotes against a scope they wrote themselves is quoting a different job from the others.

Then normalise the days

Ask every provider for days and rate separately, split between fieldwork and reporting. A £9,000 quote at six days and £1,500 and a £9,000 quote at twelve days and £750 are very different engagements, and only one of them has senior people on it.

Read the cyber security audit deliverable clause

Ask to see a redacted sample report before you sign. The difference between a useful cyber security audit and an expensive one is almost entirely in the report: whether findings carry risk ratings, named owners, effort estimates and framework references, or whether they carry adjectives.

The comparison table to use

What to compareWeak answerStrong answer
Scope statement“Your IT environment”Named sites, systems, tenants and exclusions
Days and rateA single totalDays split fieldwork versus reporting, rate shown
Framework“Industry best practice”A named standard and version
Who does the workUnnamed teamNamed consultant and qualifications
Sample reportNot availableRedacted example provided
RetestSilentIncluded or priced explicitly
RemediationBundled without a figureSeparately priced or explicitly excluded
Conflict of interestThe auditor also sells the fixDeclared, with an option to decline

The conflict question is not theoretical

A provider who assesses you and then sells you the remediation is not automatically wrong — for a small business it is often the practical choice, and our own IT security and compliance work is frequently bought that way. But the conflict should be on the table in writing, with a clear route to take the report elsewhere. A firm that will not say so unprompted has answered a different question.

The cheapest cyber security audit is sometimes correct

If two providers quote the same days against the same scope with the same framework and comparable people, take the cheaper one. Assurance is a professional service, not a luxury good, and paying a premium for a logo buys nothing a customer questionnaire will ever ask about.

The annual cyber security audit budget a UK SME needs

A cyber security audit is a recurring cost, not a project. Budgeting it annually rather than reactively is what stops the number ambushing a board meeting.

A realistic annual cyber security audit figure by size

Business sizeMinimum sensible annual spendTypicalWhat that buys
Under 10 people£400£1,500–£2,000Certification, renewed annually
10–49 people£1,600£3,000–£5,000Hands-on certification, or a review
50–249 people£3,000£8,000–£15,000Review plus testing, renewed
Certified to ISO 27001£2,625£3,000–£8,000Surveillance audit and maintenance

Alternate the deep work

Very few small businesses need every cyber security audit product every year. A workable three-year rhythm is certification renewed annually, a technical assessment in year one, a governance review in year two and testing again in year three. That keeps the annual line predictable and still refreshes every view of the estate inside a single cycle.

Fund remediation separately

Set aside a remediation budget alongside the assessment budget, at roughly one to two times the assessment fee for a first engagement and considerably less thereafter. An organisation that funds the assessment but not the fixes has bought a document, and a document that sits in a shared drive is the most expensive form of assurance there is.

The two-year effect

A second-year cyber security audit is cheaper in real terms because the evidence already exists. The policies, asset register, access reviews and supplier list are built once. Firms that let all of that lapse and rebuild it before each assessment pay the build cost repeatedly, which is the single most avoidable overspend in this market.

Fourteen cyber security audit questions to ask before you sign

Send these to every provider in writing. The answers will separate the shortlist faster than any price comparison.

On scope

What exactly is in scope, expressed as named sites, systems and cloud tenants? What is explicitly out of scope? What happens to the fee if we discover an additional system mid-engagement?

On effort and people

How many days, split between fieldwork and reporting? What is the day rate? Who specifically will do the work, and what qualifications do they hold? Will any of it be subcontracted?

Cyber security audit questions on the deliverable

Can we see a redacted sample report? Will findings carry risk ratings, named owners and effort estimates? Will each finding map to a named framework control? Is a management summary suitable for a board included?

On what happens next

Is a retest included, and if not, what does one cost? Do you also sell remediation, and if so how is that conflict managed? What does the same engagement cost next year?

The cyber security audit questions in a list

#QuestionWhat a good answer looks like
1What is in scope?A written list, not a category
2What is out of scope?Explicit exclusions, in writing
3How many days?A number, split by activity
4What is the day rate?A figure, not “it varies”
5Who does the work?A named person with credentials
6Which framework?A named standard and version
7Can we see a sample report?Yes, redacted, before signature
8How are findings rated?A published, consistent scale
9Is remediation included?No, and priced separately
10Is a retest included?Yes, or a stated price
11How much is done remotely?A percentage and a travel policy
12What internal time do we need?Hours, by role
13What does year two cost?A figure, given up front
14Who owns the report?You do, with no reuse restriction

Common cyber security audit buying mistakes

Every one of these has been made by a competent business with a sensible budget. They are procurement failures, not technical ones.

Buying assurance nobody asked for

The most expensive cyber security audit mistake is buying certification when the requirement said “or equivalent”. Read the clause, then buy to the clause. If nobody has asked at all, a posture review is almost always the better first purchase because it tells you which certificate you would pass.

Confusing a scan report with an opinion

A 200-page tool export with a logo on the cover is not a cyber security audit, and a customer questionnaire will not accept it as one. If the deliverable has no named human judgement in it, you have bought a scan.

Letting the provider write the cyber security audit scope

The provider who writes your scope also decides your price and, more importantly, decides what does not get looked at. Write it yourself, even badly, then let them improve it.

Timing it against a deadline

Deadline pressure removes every negotiating lever you have and adds a premium on top. Certification takes three to six months from a standing start; hands-on assessment takes two to four weeks plus remediation. Start when the tender appears, not when it closes.

Treating the certificate as the outcome

The certificate is evidence of the outcome. The outcome is the set of controls the cyber security audit made you build. Firms that optimise for passing rather than for improving get both, badly, and pay for the privilege twice — see our cyber security checklist for accountancy firms for what the control set actually looks like in practice.

Not budgeting the internal hours

Somebody has to gather the evidence, answer the questions and chase the fixes. On a certification route that is frequently three to five days of one person’s month for several months. It is the largest invisible line in the whole exercise.

Buying once

A cyber security audit is a snapshot. The NCSC is explicit that findings hold good only at the time of the exercise, and gaps between exercises are often a year or more. A one-off purchase in year one that is never repeated leaves you with a certificate that is technically valid and evidentially stale.

How to get a fair cyber security audit quote

Procurement does more for the final number than negotiation does. These five moves cost nothing and reliably move the price.

Write the cyber security audit scope statement yourself

One page. Named sites, named systems, named cloud tenants, headcount, the framework you want, and an explicit exclusions list. Send the identical document to three providers. This alone routinely produces a 30 per cent spread you can act on, because it exposes which provider was quietly quoting for less work.

Ask for the day count before the price

A provider who will give you days and rate separately is easy to compare and easy to trust. One who will only give a total is asking you to buy on brand. On certification routes you can sanity-check the day count against the published international duration table before you negotiate anything.

Fix the free findings first

Enable multi-factor authentication everywhere, patch the estate, remove local administrator rights, and turn on the logging you already pay for. Every one of those is free, all four are checked by every cyber security audit product on the market, and clearing them shortens the engagement and shrinks the remediation bill behind it.

Book the cyber security audit outside the rush

Demand is seasonal, driven by financial year ends and tender cycles. Booking six to eight weeks out, rather than into a deadline, keeps the discount available and gets you a named consultant instead of whoever is free.

Buy the cyber security audit cycle, not the event

If you know you will run a cyber security audit annually, say so and ask for two- or three-year pricing. Providers discount predictable revenue, and you get rate certainty for the board. This is the single easiest saving available on any recurring cyber security audit programme.

Frequently asked questions

How much does a cyber security audit cost in the UK?

For a UK SME in 2026, expect a cyber security audit to cost £2,000 to £15,000 externally. Cyber Essentials certification starts at £320 +VAT, Cyber Essentials Plus runs £1,399–£3,499 +VAT by size, a full posture assessment is £3,000–£10,000, and an ISO 27001 Stage 1 and Stage 2 audit is £6,000–£15,000.

Is Cyber Essentials a real cyber security audit?

Yes, but a narrow one. The base scheme combines self-assessment with independent review by an appointed certification body, covering five technical control areas. It does not examine governance, suppliers, backups or incident response, so it should not be presented as a full assessment of the business.

How long does a cyber security audit take?

Two to four weeks from scoping call to final report for most engagements, of which two to five days are consultant time. A full posture assessment takes four to eight weeks. First-time ISO 27001 certification takes three to six months.

How often should we run a cyber security audit?

Annually is the working answer for anything certificate-bearing, because certificates renew annually. For technical assessment, at least once a year and after any significant change, which is also the cadence the card payment rules require of anyone handling card data.

Can we do a cyber security audit ourselves?

You can run a cyber security audit yourself, and for a first pass you probably should. An internal cyber security audit against a published framework costs nothing but time and finds most of the obvious problems. It stops being sufficient the moment somebody outside the business has to believe the result.

What is the difference between an audit and a penetration test?

An audit forms an independent opinion on whether security is managed properly across a defined scope. A test attempts to break in and reports what worked. The first satisfies questionnaires, insurers and regulators; the second finds the specific technical holes the first will never see.

Does a cyber security audit make us secure?

No. A cyber security audit tells you where you stand. The NCSC is explicit that assurance exercises are not a magic bullet, that findings hold only at the time of the exercise, and that risk decisions and remediation remain your responsibility.

Will our insurer accept the report?

Sometimes, and increasingly. Underwriters typically want evidence of specific controls rather than a cyber security audit report as such, so an assessment that maps findings to named controls is far more useful to an insurer than one that grades you out of ten.

What does it cost in year two?

Less. A surveillance cyber security audit on a certification route is roughly 30 to 40 per cent of the year-one audit fee, and repeat consultancy engagements are cheaper because the evidence already exists. Budget one to two times the assessment fee for remediation in year one, and considerably less thereafter.

Which cyber security audit should we buy first?

If a contract names a certificate, buy that certificate. If nothing external is driving it, buy a posture review, because it tells you which certificate you would pass and what it would take to pass the next one up.

References

NCSC — Cyber Essentials Overview

IASME — Cyber Essentials

IASME — Upcoming Changes to the Cyber Essentials Scheme, April 2026 Update

IASME Consortium

Cyber Security Breaches Survey 2025/2026

Cyber Security Breaches Survey Collection

Cyber Governance Code of Practice

NCSC — Cyber Security Board Toolkit

NCSC — 10 Steps to Cyber Security

NCSC — Risk Management Guidance

NCSC — Cyber Assessment Framework

NCSC — Penetration Testing Guidance

NCSC — CHECK Scheme Introduction

NCSC — CHECK Information for Buyers

NCSC — Vulnerability Management

NCSC — Vulnerability Scanning Tools and Services

NCSC — Device Security Guidance

NCSC — Multi-Factor Authentication for Online Services

NCSC — Incident Management

NCSC — Exercise in a Box

NCSC — Supply Chain Security

ICO — A Guide to Data Security

ICO — Data Protection Impact Assessments

ICO — Enforcement Action

Data Protection Act 2018

ISO27001security.com — ISO/IEC 27001 Reference

International Accreditation Forum

CREST

CREST Membership

The Cyber Scheme

UK Cyber Security Council

NIST Cybersecurity Framework

NIST SP 800-115 — Technical Guide to Information Security Testing and Assessment

NIST SP 800-53 Revision 5

NIST SP 800-30 — Guide for Conducting Risk Assessments

CIS Critical Security Controls

OWASP Top Ten

OWASP Web Security Testing Guide

MITRE ATT&CK

FIRST — Common Vulnerability Scoring System

National Vulnerability Database

PCI Security Standards Council

PCI Security Standards Document Library

FCA — Operational Resilience

Bank of England — Financial Stability

EIOPA — Digital Operational Resilience Act