How to choose a Cyber Essentials and DCC Level 0 Certifying Body?

Key Takeaways

  • Cyber Essentials pricing is fixed. IASME sets the fee, so every certifying body charges the same. The difference is in the value and support you receive.
  • Compare Cyber Essentials Plus quotes. Prices vary, so check exactly what each quote includes.
  • Check your assessor’s credentials. Ask who will assess you and what qualifications they hold. CE Plus Lead Assessors must have a penetration testing qualification.
  • Scope comes first. A good certifying body will discuss your scope before you start the question set.
  • Defence contractors need the right expertise. Choose a body that can certify both Cyber Essentials and DCC Level 0.

Introduction

Choosing a Cyber Essentials certifying body may seem like a straightforward administrative decision. With more than 300 IASME licence holders and the basic certification fee set at the same level, it can be tempting to choose on price alone.

But your choice can have a much bigger impact. The certifying body you select can help determine how your scope is defined, see how prepared you are for the new automatic-fail questions, and whether the work you do today can be carried forward to Cyber Essentials Plus and DCC Level 0 or whether you have to start again.

I oversee audits regularly and see these differences first-hand. Here are the key things to check, before you choose your certifying body.

Read more: How to Choose the Right Cybersecurity Consultant: 5 Things to Consider

What does a Cyber Essentials Certification Body do? 

IASME is the NCSC’s official Cyber Essentials Delivery Partner and all certifying bodies operate under its licence. You have two options: register directly with IASME and complete the verified self-assessment yourself, or work directly with a certifying body for additional guidance and support.

Assessors must meet qualification requirements too. IASME requires assessors to have at least three years’ IT or security experience, plus a recognised qualification such as CISSP, CISM or ISO 27001 Lead Auditor or to have passed IASME’s own assessor exam. For Cyber Essentials Plus, lead assessors must also hold a recognised penetration testing qualification, such as CREST or OSCP.

These requirements provide a baseline for every certifying body. The real differences come in the level of service, expertise and value they provide, starting with cost.

Cyber Essentials cost is fixed, the value is not

Basic Cyber Essentials is priced by IASME, not by the individual certifying body. According to IASME’s own FAQ, fees start at £320 + VAT for micro-organisations and rise to £600 + VAT for organisations with 250 or more employees.

Cyber Essentials Plus is different. IASME says CE Plus “has to be quoted for individually”, as the cost depends on the size and complexity of your network. IASME can put you in touch with three certifying bodies, to obtain quotes.

When comparing quotes, look beyond the headline price. Check how devices will be sampled, whether the assessment is remote or on site, and how any retests are handled. A low CE Plus quote that excludes retesting or scoping support may not be the cheapest option overall.

So, what should you check before choosing a certifying body?

Five things to check before you commit

1. Who will assess you?
Ask for the assessor’s name and qualifications. If you are going for CE Plus, check that they hold the recognised testing credentials for their role. If they are a Lead Assessor, make sure they are a qualified penetration tester (Ethical hacker|).

2. Do they discuss scope first?

Scope is where many applications go wrong. Since the April 2026 changes, your scope must identify the legal entity and document any areas that are out of scope. A good certifying body will ask about your entities, cloud services and remote workers before you start the question set.

Read more: Cyber Essentials Scoping: The Decision That Determines Whether You Pass or Fail

3. Do they know the new question set? 

Assessments from 26 April 2026 use the Requirements for IT Infrastructure v3.3. MFA must now be enabled on every cloud service where it is available, and critical updates must be applied within 14 days. Both can result in an automatic fail, so ask how your certifying body will help you prepare.

4. What is their plan for CE Plus?

Complete CE Plus within 90 days of your CE certification otherwise you will need to repeat the self-assessment questions with the associated costs. Your certifying body should already be planning your CE Plus audit date during your CE basic assessment to manage the time frame. Since April 2026, you also cannot amend your answers after your CE Plus testing begins, making preparation more important than ever.

Read more: Inside a Cyber Essentials Plus Audit: What Really Happens

5. Can they take you further?

For defence contractors, this may be the most important question. Look for a certifying body that can support you beyond Cyber Essentials and help you meet the requirements of DCC Level 0.

But before you choose, there are also some things to watch out for.

Warning signs to walk away from

  • A guaranteed pass – No legitimate certifying body can promise you will pass.
  • No discussion of scope before payment – If nobody asks what is in scope, nobody is checking whether your scope is correct.
  • Unclear answers about the assessor or retests – You should know who will assess you, how the testing works and what happens if you need a retest before you sign up.

Choosing a DCC Level 0 Certifying Body for Defence Industry

The MOD expects every supplier to hold DCC Level 0, by 31 December 2026, and Level 0 requires Cyber Essentials across the business systems within scope. A recent Defence Digital article describes aligning your Cyber Essentials scope with your DCC scope as “the single biggest challenge for applicants.”

The same article notes that DCC “relies on suppliers receiving the same outcome regardless of which Certifying Body conducts the assessment.” The standard is consistent. The support you receive in meeting it is not.

That is why I would choose a certifying body that is licensed to deliver both. Get the scope right once, with DCC in mind, rather than having to revisit and rebuild it later.

Pera Prometheus is an IASME approved certifying body for Cyber Essentials and Cyber Essentials Plus, as well as a certifying body for DCC Level 0. That means we can address the alignment, between the two, from the outset.

Read more: Cyber Essentials: The Foundation of DCC Level 0

Conclusion

You are not simply buying a certificate. You are choosing who will challenge your assumptions about your own network, year after year, for as long as you hold contracts that depend on certification.

Choose a certifying body that asks the difficult questions early. The alternative is discovering the gaps during assessment when there is less time to fix them and more pressure to get it right. 

Ready to take the Next Step?

With a DCC deadline approaching, this is one more decision on a full list. If you would like to talk through your scope, or your route from Cyber Essentials to Plus and DCC Level 0, get in touch with our team.

Frequently Asked Questions

Q: Does it matter which Cyber Essentials certifying body I use? 

A: Yes. The certification standard is the same, but the level of scoping support, assessor experience and preparation for Cyber Essentials Plus can vary between certifying bodies.

Q: Does the price of Cyber Essentials vary between certifying bodies?

A: The basic Cyber Essentials fee is set by IASME and varies by organisation size, starting at £320 + VAT. Cyber Essentials Plus is quoted individually, so this is where prices differ.

Q: Can the same certifying body help me prepare and then assess me?

A: Yes. IASME allows certifying bodies to provide consultancy to help you understand the questions and how they apply to your organisation.

Q: How soon after Cyber Essentials should I complete Cyber Essentials Plus?

A: Within three months if you want to avoid repeating the self-assessment questions.

Q: Can my Cyber Essentials certifying body also certify DCC Level 0?

A: Only if it is licensed to deliver DCC Level 0 and its assessors have completed the required DCC training. Check this before you commit.

Stay Safe, Stay Secure