Skip to main content
    NixInfinity-AI
    UK Legislation

    CSR Bill vs Cyber Essentials vs Cyber Assurance: How They Stack

    Published 9 July 2026

    Quick comparison

    CSR BillCyber EssentialsCyber Assurance
    TypeUK lawUK technical certificationUK governance certification
    Mandatory?Yes, for in-scope entitiesNo, but procurement-mandatoryNo, but increasingly required
    ScopeOperators, MSPs, data centres + supply chainAll UK organisationsUK SMEs and mid-market
    CostIndirect (compliance + breach risk)£320 + VATL1 £320 + VAT, L2 quote-based
    Free insuranceNoYes – £25k for eligible UK orgsInherits CE insurance

    How they fit together

    1. CSR Bill sets the legal expectation: incident reporting, supplier assurance, technical baseline.
    2. Cyber Essentials evidences the technical baseline – the five controls.
    3. Cyber Assurance evidences governance: risk management, business continuity, supplier oversight, the 14 themes.

    What most SMEs should do

    • Hold current Cyber Essentials.
    • Add Cyber Assurance Level 1 if you handle regulated data or sell to regulated buyers.
    • Step to Level 2 when buyers ask, or when you handle critical operational data.
    • Keep an incident response plan that meets the 24/72-hour reporting expectation.

    When ISO 27001 makes more sense

    ISO 27001 is heavier and more expensive but internationally recognised. Pick it when you sell internationally to enterprise buyers who specifically require ISO. For UK SMEs in the UK supply chain, CE + Cyber Assurance is usually faster, cheaper and accepted.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions