Skip to main content
Precursor Security
2026 Comparison Guide

The Best Cyber Essentials Providers UK

The best UK Cyber Essentials providers in 2026 are IASME-accredited certification bodies with transparent pricing, a documented gap-analysis process, and a clear re-test policy. This guide compares 7 providers: Precursor Security, CyberSmart, GRC Solutions (formerly IT Governance), LRQA, WorkNest Secure (formerly Bulletproof), Indelible Data, and Cyber Tec Security, on criteria any buyer can check independently against the IASME certification body directory.

Seven IASME-accredited UK Cyber Essentials certification bodies compared on the criteria that actually matter to buyers: accreditation you can verify in the IASME directory, pricing you can see before a sales call, gap-analysis support, and free re-testing.

Updated August 2026
Every claim verifiable
Criteria published in full
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Read This First

We are Precursor Security, and we have ranked ourselves first on this list.

Rather than pretend otherwise, we publish the selection criteria in full, describe every other provider fairly, and link the official IASME certification body directory so you can check our working. The firms below are genuinely capable certification bodies. The differences are in pricing transparency, gap-analysis support, and what happens if you do not pass first time.

At a Glance

Seven certification bodies, side by side

ProviderIASME-accreditedPricing publishedFrom
1. Precursor SecurityYesYesFrom £1,500
2. CyberSmartYesYesPublished online (subscription)
3. GRC Solutions (formerly IT Governance)YesNoOn application
4. LRQAYesNoOn application
5. WorkNest Secure (formerly Bulletproof)YesNoOn application
6. Indelible DataYesNoOn application
7. Cyber Tec SecurityYesYesFrom £320 + VAT

Verified against each provider's public website and the IASME certification body directory, August 2026. "No" under pricing published means we could not find a package price publicly stated; it does not mean the firm lacks a fair rate.

The 7 best UK Cyber Essentials
providers in 2026

1. Precursor Security

Best for: Mid-market and first-time certifiers who want fixed pricing and a real first-time pass

Precursor is an IASME-accredited Cyber Essentials assessor delivering both Cyber Essentials and Cyber Essentials Plus. Pricing is published on the website: Cyber Essentials from £1,500, Cyber Essentials Plus from £3,000, and a pre-assessment gap analysis from £500 for organisations that want to maximise their first-time pass rate. The IASME certification fee is included in every quote, a re-test is free if you do not pass first time, and fixed-price quotes follow a 20-minute scoping call, not an open-ended day rate. Because Precursor also delivers CREST-accredited penetration testing, Cyber Essentials Plus findings feed into a wider remediation picture rather than a standalone tick-box exercise.

Trade-off: A mid-market specialist rather than a high-volume certificate factory, and the youngest firm on this list.

2. CyberSmart

Best for: SMEs that want certification bundled with ongoing compliance monitoring

CyberSmart has been an IASME Consortium-licensed Cyber Essentials certification body since March 2020 and describes itself as the UK's leading Cyber Essentials certification body by volume. The distinguishing feature is the delivery model: certification is sold through a subscription platform that layers continuous device and configuration monitoring on top of the annual assessment, rather than a one-off engagement. Plan pricing is published online, though it is structured as recurring platform fees rather than a single fixed project quote.

Trade-off: A platform and subscription model rather than a fixed-price consultancy engagement; the annual cost includes ongoing tooling, not just the certificate.

3. GRC Solutions (formerly IT Governance)

Best for: Organisations that want Cyber Essentials folded into a wider GRC and ISO 27001 programme

IT Governance rebranded to GRC Solutions and remains one of the founding Cyber Essentials certification bodies, IASME-licensed and reporting more than 12,000 certificates issued since the scheme launched in 2014. Headquartered in Ely, Cambridgeshire, the firm sits inside a broader information security consultancy and publishing business, which suits buyers who want Cyber Essentials handled alongside ISO 27001, GDPR, or wider governance work under one supplier.

Trade-off: Package pricing is not published; you request a quote rather than seeing a rate card upfront.

4. LRQA

Best for: Large enterprises that want Cyber Essentials issued by a global assurance body they already use

LRQA is an official IASME Cyber Essentials and Cyber Essentials Plus certification body, operating as part of a global assurance and management-systems certifier with UK registered offices in Birmingham. For organisations that already hold ISO certifications through LRQA, or that need a globally recognised certifier for multinational procurement, the existing relationship is the draw.

Trade-off: Enterprise-scale assurance provider rather than an SME-focused specialist; pricing is quote-only and the engagement model is built for larger procurement processes.

5. WorkNest Secure (formerly Bulletproof)

Best for: Organisations that want Cyber Essentials alongside penetration testing and employment-law-adjacent compliance support

Bulletproof, previously a well-known standalone UK Cyber Essentials and penetration testing brand, was absorbed in May 2026 into WorkNest Secure, a new division combining Bulletproof and Pentest People under the wider WorkNest group. WorkNest Secure is an IASME-licensed Cyber Essentials certification body offering Core and Premium packages for both Cyber Essentials and Cyber Essentials Plus, with NCSC-certified assessors. Worth knowing if you were expecting to deal with "Bulletproof" directly: the brand and team now sit inside a larger, recently merged organisation.

Trade-off: Pricing is not published, quotes follow a booked consultation, and the business has just been through a brand and structural change buyers should ask about directly.

6. Indelible Data

Best for: Organisations that want a long-standing, independently owned specialist certification body

Indelible Data is an IASME-licensed Cyber Essentials certification body based in Maryport, Cumbria, offering both Cyber Essentials and Cyber Essentials Plus assessments and reporting more than 2,500 organisations certified since the scheme launched in 2014. It has stayed an independent, specialist certification body rather than expanding into a broader security platform, which appeals to buyers who want a certifier and nothing else.

Trade-off: Pricing is quote-only rather than published, and the firm is smaller than the enterprise-scale names on this list.

7. Cyber Tec Security

Best for: International or offshore-structured organisations that also need the IASME Cyber Baseline equivalent

Cyber Tec Security is an IASME Certification Body for Cyber Essentials and Cyber Essentials Plus, registered in Jersey with additional UK and Bermuda offices. Alongside standard UK Cyber Essentials, the firm also delivers IASME Cyber Baseline and IASME Cyber Assurance, the international equivalents of Cyber Essentials and Cyber Essentials Plus, which suits groups with entities outside the UK. Pricing is published in named packages starting from £320 + VAT.

Trade-off: A Channel Islands-registered structure will not suit every UK procurement team's supplier-vetting requirements, even though the certification itself is fully valid.

Methodology

How we ranked them

Six criteria, each something a buyer should care about and can verify without taking anyone's word for it. Weighting is ours; the underlying facts are checkable.

Verifiable IASME accreditation

Listed in the official IASME certification body directory, not just claimed on a website. Only an IASME-accredited body can verify a self-assessment and issue a Cyber Essentials certificate.

Cyber Essentials vs Cyber Essentials Plus scope fit

Whether the provider correctly scopes which level you actually need, rather than upselling Cyber Essentials Plus to every enquiry regardless of what your contract or framework requires.

Pricing transparency

Whether you can see a rate before a sales call. Many certification bodies price on application, which costs buyers time and makes comparison hard.

Gap-analysis and first-time pass support

Whether the provider offers a pre-assessment gap analysis so common failure points, unpatched devices, incomplete MFA, BYOD gaps, are caught before the formal assessment rather than after a failed one.

Free re-test policy

Whether verification of your fixes after a failed assessment is included or sold back to you as a second, separately priced engagement.

Penetration testing depth behind Cyber Essentials Plus

Whether the assessor also delivers penetration testing, so Cyber Essentials Plus findings, the external vulnerability scan and device sampling results, feed into real remediation rather than a certificate and nothing else.

Buyer Beware

Red flags when choosing
a Cyber Essentials assessor

Whichever provider you choose, including us, walk away if you see these.

Not actually IASME-accredited

Verify every accreditation claim against the official IASME certification body directory. If a provider claims to certify Cyber Essentials but does not appear there, they cannot legally issue a valid certificate.

Cyber Essentials Plus quoted with no device sample scoping

Cyber Essentials Plus pricing depends on how many devices and users are sampled for testing. A flat quote given before any scoping conversation is a guess, not a price.

Opaque pricing with no rate guidance

A provider that cannot give you a starting price before a discovery call is optimising for deal-size discovery, not your budget. The underlying IASME fee bands are public; anyone refusing to anchor near them is hiding something.

No pre-assessment gap analysis offered

Failing your first formal assessment costs you a re-assessment fee and a delayed certificate. A provider with no gap-analysis stage is optimised for booking assessments, not for you passing them.

Re-test billed separately

If you fail and the re-test is a fresh, separately priced engagement, your path to a valid certificate costs more than the original quote suggested. Ask about re-test policy before you sign anything.

A certificate mill with no technical depth

For Cyber Essentials Plus in particular, ask who performs the hands-on testing and what their background is. A rubber-stamp assessment that never meaningfully tests your devices defeats the purpose of paying for Plus over Basic.

What It Costs

UK Cyber Essentials prices in 2026

Across the market, the underlying IASME assessment fee runs from £320 to £600 plus VAT depending on organisation size, before a certification body\'s own support and consultancy fee is added. At Precursor\'s published rates, all inclusive of the IASME fee: pre-assessment gap analysis from £500, Cyber Essentials from £1,500, Cyber Essentials Plus (micro to SME) from £3,000, and Cyber Essentials Plus (mid-market, 250+ staff) from £4,500.

Full pricing and process breakdown
Pre-assessment gap analysisFrom £500
Cyber EssentialsFrom £1,500
Cyber Essentials Plus (SME)From £3,000
Cyber Essentials Plus (250+ staff)From £4,500
Make It a Fair Fight

Compare us against anyone on this list.

Fixed pricing published before you call. A gap analysis to catch failure points early. A free re-test if you need one.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team
FAQs

Choosing a Cyber Essentials assessor

The questions buyers ask most when comparing UK certification bodies.

Pricing varies by provider and organisation size. The underlying IASME assessment fee alone runs from around £320 for a micro-organisation to £600 for a large organisation, plus VAT, but most certification bodies bundle this into a package price that includes guidance and support. Across the market, published packages for Cyber Essentials start from roughly £320 to £1,500, and Cyber Essentials Plus, which adds a hands-on technical audit, typically starts from £3,000 given the extra device sampling and vulnerability scanning involved. Precursor publishes fixed pricing: Cyber Essentials from £1,500, Cyber Essentials Plus from £3,000, and a pre-assessment gap analysis from £500, all including the IASME certification fee.

Cyber Essentials is a Verified Self Assessment: you complete a questionnaire against five technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) and an IASME-accredited assessor verifies your answers. Cyber Essentials Plus adds independent, hands-on technical verification: assessors confirm the Cyber Essentials Plus scope matches your self-assessment, then run external vulnerability scanning, device sampling, and configuration review to confirm the controls are actually implemented and effective, not just declared. Cyber Essentials Plus is typically required by MOD supply chain, NHS, and enterprise procurement teams; standard Basic certification is usually sufficient for general government contracts and everyday cyber hygiene.

Only an IASME-accredited certification body can issue Cyber Essentials or Cyber Essentials Plus certification. IASME is the National Cyber Security Centre's sole delivery partner for the scheme and licenses a network of certification bodies across the UK and Crown Dependencies to verify assessments and issue certificates. Fully self-certified, DIY completion of the scheme is not possible: you can complete the self-assessment questionnaire yourself, but an accredited assessor must review and verify it before a certificate is issued. You can check any provider's status using the official IASME certification body directory.

Yes. Since 2014, Cyber Essentials certification has been mandatory for UK Government contracts that involve handling sensitive or personal information. Standard Cyber Essentials (Basic) is usually sufficient for general government contracts, while MOD supply chain and defence sector contracts typically require Cyber Essentials Plus. An increasing number of private sector supply chains, NHS trusts, and cyber insurers now apply the same requirement outside of direct government procurement.

Leading IASME-accredited Cyber Essentials certification bodies in the UK include Precursor Security, CyberSmart, GRC Solutions (formerly IT Governance), LRQA, WorkNest Secure (formerly Bulletproof), Indelible Data, and Cyber Tec Security. Each is licensed by IASME to issue Cyber Essentials and Cyber Essentials Plus certificates, but they differ on pricing transparency, delivery model, and whether gap analysis and re-testing are included or sold separately, which is why comparing more than accreditation status matters.