If a tender asks for a Cyber Essentials certificate, you need to know how long it will take to get one. This guide sets out the realistic timeline.
How long does Cyber Essentials take? The questionnaire takes about an hour to fill in, and most assessors return a result within three working days. Most of the time goes on getting your IT ready before you start the questionnaire.
Cyber Essentials is a verified self-assessment. Once your answers are ready, the questionnaire takes about an hour, and assessors aim to return results within three days. When organisations miss a deadline, the delay is usually fixing their IT, not the paperwork.
How Long Does Cyber Essentials Take From Start to Certificate?
If your business already patches quickly and has multi-factor authentication switched on, Cyber Essentials can take one to two weeks. If it doesn’t, four to eight weeks is more realistic. The difference is the time spent fixing your systems, and that’s usually the part Transputec is asked to help with.
Many businesses budget for the assessment and then find they have a bigger project on their hands.
Why Does Preparation Take Longer Than the Assessment?
Because the assessment only checks whether the controls are already in place. It doesn’t give you time to put them there. So when someone asks how long does Cyber Essentials take, the answer depends on how far their IT is from meeting the five controls.
IASME lets you download the question set for free before you apply. Reading it early is the best way to shorten the cyber essentials timeline, because you find out what’s missing while there’s still time to fix it.
If you pay first and read the questions later, the six-month deadline to submit starts straight away.
Working to a Tender Deadline?
Transputec's cyber security services cover the patching, device configuration, access control and malware protection that Cyber Essentials checks. Talk to our team about the work behind your certification.
Get a Strategic ConsultationWhat Are the Cyber Essentials Application Process Steps?
The cyber essentials process has five steps: read the question set, fix what fails, apply and pay, complete the verified self-assessment, and receive the certificate. Only two of those involve IASME. The other three happen inside your business, so two organisations that buy on the same day can certify months apart.
This is where the time goes:
| Stage | Realistic Time |
|---|---|
| Reading the question set and scoping the estate | 1 to 3 weeks |
| Remediation: patching, MFA, removing unsupported software | 2 to 6 weeks |
| Completing the self-assessment | About 1 hour |
| Assessor marking the submission | Within 3 working days |
| Fixing and resubmitting a failed assessment | 2 working days |
| Certificate issued after a pass | Same day |
So how long does Cyber Essentials take in practice? Mostly it depends on the remediation row. Everything else takes hours or days.
How Long Does Cyber Essentials Take to Be Marked?
Most assessors aim to return your result within three days of submission. If your answers are compliant, you get the certificate straight away. If the assessor can’t mark a question because there isn’t enough detail, they send it back and ask for more, which adds a few days. Write full answers the first time.
A failed submission doesn’t end the attempt. IASME gives you two working days to read the assessor’s feedback, fix simple issues with your network and policies, update your answers and resubmit, at no extra cost. The assessor then aims to remark within three days. You also get a full report showing every answer and the assessor’s comments on anything non-compliant.
If you miss the two-day window, you have to reapply and pay the assessment fee again. So how long does Cyber Essentials take to recover from a fail? Two working days, or you start again.
What Is the Deadline Everyone Forgets?
You have six months from the date of application to complete and submit. After that, your account may be closed and IASME won’t issue a refund. If you apply early and then leave the work, you can lose the fee. Our guide to Cyber Essentials cost lists that fee for each organisation size.
There’s a second deadline in 2026. The Danzell question set, published on 13 February 2026, took effect on 26 April 2026 alongside Requirements for IT Infrastructure v3.3. Organisations whose assessment account was created before that date were given six months to certify under the old requirements. That period ends in late October 2026, so if you registered earlier in the year and haven’t certified yet, you have weeks left, not months.
Two questions are now automatic fails, whatever your other answers. A6.4 and A6.5 require high-risk and critical security updates to be installed within 14 days of release for operating systems, router and firewall firmware, and applications. Using unsupported software anywhere in scope is also an automatic fail.
If you registered early in 2026 and stalled, the question isn’t how long does Cyber Essentials take. It’s how long you have left.
You can’t argue your way around patching at assessment time. Either the updates were installed or they weren’t. That’s the work Transputec’s managed IT services and vulnerability management teams do every day.
How Quickly Can You Get Cyber Essentials Certified?
How long does Cyber Essentials take at its fastest? About a week from application to certificate, but only if you’re prepared. That means MFA is already on for cloud services, critical updates are installed within 14 days, there are no unsupported operating systems in scope, and you know which devices belong to the business.
If all four are true, apply now. If not, fix them first. Otherwise you start the six-month deadline while you’re still doing the work.
How Long Does Cyber Essentials Plus Take on Top?
Cyber Essentials Plus adds a technical audit to the same five controls, and it must be completed within three months of your Cyber Essentials certification. The controls are the same, but the assurance is higher: an assessor independently tests a sample of your devices, all internet gateways and internet-facing servers, and runs internal and external vulnerability scans.
If your basic certification is less than three months old, you don’t repeat the self-assessment. If more than three months have passed, you do. Our guide to Cyber Essentials Plus covers the audit in more detail.
Your Cyber Essentials Timeline Checklist
- Download the question set and read it before you spend anything.
- List everything in scope: devices, cloud services and software.
- Remove or replace unsupported software. It’s an automatic fail, and often the longest job.
- Enforce multi-factor authentication on all cloud services.
- Make sure you can show critical updates are installed within 14 days. A6.4 and A6.5 are now automatic fails.
- Apply and pay once all of the above is done, then complete the self-assessment, which takes about an hour.
- Write full answers so the assessor doesn’t have to send questions back.
- Keep two working days free after you submit in case you need to fix a fail. It’s the shortest deadline in the scheme.
- Put renewal in the diary at eleven months. Certificates expire after twelve.
Conclusion
How long does Cyber Essentials take? Days if your IT is ready, weeks if it isn’t. The assessment itself is quick. Getting ready for it is the real work, so plan that part properly. If you already have good patching, MFA switched on and no unsupported software, you can be certified in days. If you need to sort all three, allow a month or two, and start by reading the question set before you pay for an assessment.
Transputec holds Cyber Essentials Plus, ISO/IEC 27001 and ISO 9001, so we’ve been through this ourselves as well as with our clients. We don’t sell the certificate. We do the IT work that decides whether you pass: patching, device configuration, access control and malware protection, delivered through our cyber security services.
If you’re working to a contract deadline, work back from that date and talk to our UK team about what needs doing.
FAQs
How Long Does Cyber Essentials Take for a Small Business?
A small business with MFA enabled and up-to-date software can certify in one to two weeks, and the self-assessment itself takes about an hour. If you find unsupported operating systems or patching gaps, expect four to eight weeks. The state of your IT matters more than your size.
How Long Does Cyber Essentials Take to Be Assessed Once Submitted?
Most assessors aim to return a result within three working days. If you pass, you get the certificate straight away. If the assessor needs more detail, they send the answer back to you, which adds a few days to the cyber essentials process.
What Happens if I Fail the Cyber Essentials Assessment?
You get a report of every answer, with the assessor’s comments on anything non-compliant. You then have two working days to fix simple issues and resubmit at no extra charge, and the assessor aims to remark within three days. If you’re still non-compliant after those two days, you have to reapply and pay again.
How Long Does Cyber Essentials Plus Take After Basic Certification?
The Cyber Essentials Plus audit must be completed within three months of your Cyber Essentials certificate. Book it early. It’s an independent technical audit with internal and external vulnerability scans and device sampling, so it has to be scheduled with an assessor. Transputec can get your IT ready before then, but you book the audit itself with your certification body.
How Long Is a Cyber Essentials Certificate Valid?
Twelve months from the date the certificate is issued, for both Cyber Essentials and Cyber Essentials Plus. IASME emails a reminder about a month before renewal is due, and organisations that don’t recertify are removed from the certified organisations list. Put it in the diary at eleven months so there’s time to do the work.
This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.



