UK Legislation
CSR Bill vs Cyber Essentials vs Cyber Assurance: How They Stack
Published 9 July 2026
Quick comparison
| CSR Bill | Cyber Essentials | Cyber Assurance | |
|---|---|---|---|
| Type | UK law | UK technical certification | UK governance certification |
| Mandatory? | Yes, for in-scope entities | No, but procurement-mandatory | No, but increasingly required |
| Scope | Operators, MSPs, data centres + supply chain | All UK organisations | UK SMEs and mid-market |
| Cost | Indirect (compliance + breach risk) | £320 + VAT | L1 £320 + VAT, L2 quote-based |
| Free insurance | No | Yes – £25k for eligible UK orgs | Inherits CE insurance |
How they fit together
- CSR Bill sets the legal expectation: incident reporting, supplier assurance, technical baseline.
- Cyber Essentials evidences the technical baseline – the five controls.
- Cyber Assurance evidences governance: risk management, business continuity, supplier oversight, the 14 themes.
What most SMEs should do
- Hold current Cyber Essentials.
- Add Cyber Assurance Level 1 if you handle regulated data or sell to regulated buyers.
- Step to Level 2 when buyers ask, or when you handle critical operational data.
- Keep an incident response plan that meets the 24/72-hour reporting expectation.
When ISO 27001 makes more sense
ISO 27001 is heavier and more expensive but internationally recognised. Pick it when you sell internationally to enterprise buyers who specifically require ISO. For UK SMEs in the UK supply chain, CE + Cyber Assurance is usually faster, cheaper and accepted.
