Enquiries: +44 (0) 20 8584 1400

CONTACT

How Long Does Cyber Essentials Take to Get

how long does cyber essentials take

The tender closes in three weeks. The buyer wants a Cyber Essentials certificate number on the submission. And someone has just worked out that nobody in the building has started.

How long does Cyber Essentials take? The questionnaire itself takes about an hour to fill in, and most assessors return a result within three working days. The weeks go on everything that happens before you log in.

Cyber Essentials is a verified self-assessment. Once your answers are ready, the questionnaire takes roughly an hour and assessors aim to return results within three days. Organisations that miss a deadline are almost never held up by the paperwork. They are held up by fixing the estate underneath it.

How Long Does Cyber Essentials Take From Start to Certificate?

For a business that already patches quickly and has multi-factor authentication switched on, Cyber Essentials can be done in one to two weeks. For a business that does not, four to eight weeks is realistic. The gap between those two numbers is remediation, not administration.

That is the part most people get wrong. They budget for an assessment and discover a project.

Why Does Preparation Take Longer Than the Assessment?

Because the assessment only asks whether the controls are already in place. It gives you no time to put them there. When someone asks how long does Cyber Essentials take, the real answer depends on how far their estate already sits from the five controls. IASME lets you download the question set for free before you apply, and reading it early is the single biggest thing you can do to shorten the cyber essentials timeline. You find out what you are missing while you still have room to fix it.

Buy first and read later, and the clock is already running.

Working to a Tender Deadline?

Tell us what your estate looks like today and we will tell you what stands between it and a pass. Straight answer, no sales theatre.

Get a Strategic Consultation

What Are the Cyber Essentials Application Process Steps?

The cyber essentials process runs in five steps: read the question set, fix what fails, apply and pay, complete the verified self-assessment, and receive the certificate. Only two of those five involve IASME. The other three happen inside your business, which is why two organisations buying on the same day can certify months apart.

Here is where the time genuinely goes.

StageRealistic Time
Reading the question set and scoping the estate1 to 3 weeks
Remediation: patching, MFA, removing unsupported software2 to 6 weeks
Completing the self-assessmentAbout 1 hour
Assessor marking the submissionWithin 3 working days
Fixing and resubmitting a failed assessment2 working days
Certificate issued after a passSame day

So how long does Cyber Essentials take in practice? Read the middle row. Everything else on that list is measured in hours and days.

How Long Does Cyber Essentials Take to Be Marked?

Most assessors aim to return your result within three days of submission. If your answers are compliant, the certificate follows straight away. If the assessor cannot mark a question because you have not given enough detail, they send it back and ask for more, and that round trip adds a few days. So write full answers the first time. Thin answers are not a fail, but they cost you a week you may not have.

A failed submission does not end the attempt either. IASME allows two working days to read the assessor’s feedback, correct simple issues with your network and policies, update your answers and resubmit, at no extra cost. The assessor then aims to remark within three days. You also get a full report showing every answer and the assessor’s comments against anything non-compliant, so you know exactly what to fix.

Miss that two-day window and it gets expensive, because you have to reapply and pay the assessment fee again. So how long does Cyber Essentials take to recover from a fail? Two days, or you start over.

What Is the Deadline Everyone Forgets?

You have six months from the date of application to complete and submit. After that your account may be closed, and IASME does not issue a refund. Applying early to feel organised, then leaving the work, is how businesses lose the fee entirely.

There is a second clock running in 2026. The Danzell question set, published on 13 February 2026, took effect on 26 April 2026 alongside Requirements for IT Infrastructure v3.3. Any organisation whose assessment account was created before that date was given six months to certify under the old requirements, which puts the end of that window in late October 2026. If you registered earlier in the year and have not certified yet, you have weeks, not months.

Two questions are now automatic fails regardless of how well you do elsewhere. A6.4 and A6.5 require high-risk and critical security updates to be installed within 14 days of release, for operating systems, router and firewall firmware, and applications. Using unsupported software anywhere in scope is also an automatic fail.

For anyone who registered early in 2026 and stalled, how long does Cyber Essentials take is no longer the useful question. How long you have left is.

Patch discipline is no longer something you can argue around at assessment time. It either happened or it did not, and that is exactly the kind of estate work our managed IT services and vulnerability management teams handle day to day.

How Quickly Can You Get Cyber Essentials Certified?

How long does Cyber Essentials take at its fastest? About a week from application to certificate, and only for a prepared organisation. That means MFA already enforced on cloud services, a patching routine that reliably closes critical updates inside 14 days, no unsupported operating systems in scope, and a clear picture of which devices belong to the business.

If all four are true, apply now. If any one of them is not, fix it first. Applying into a failing estate just starts the six-month clock while you do the work anyway.

How Long Does Cyber Essentials Plus Take on Top?

Cyber Essentials Plus adds a technical audit to the same five controls, and it must be completed within three months of your Cyber Essentials certification. The controls are identical. The assurance level is not, because an assessor independently tests a sample of your devices, all internet gateways and internet-facing servers, along with internal and external vulnerability scans.

Certify at the basic level less than three months before, and you do not repeat the self-assessment stage. Let the three months lapse and you do. We cover the audit itself in detail in our guide to Cyber Essentials Plus.

Your Cyber Essentials Timeline Checklist

  1. Download the question set and read it before you spend anything.
  2. Scope the estate: every device, every cloud service, every piece of software in scope.
  3. Remove or replace unsupported software. This is an automatic fail and often the longest job.
  4. Enforce multi-factor authentication on all cloud services.
  5. Prove you install critical updates within 14 days, because A6.4 and A6.5 now fail you outright.
  6. Apply and pay only once the above is true, then complete the self-assessment in about an hour.
  7. Write full answers so the assessor is not forced to send questions back.
  8. Keep the two working days after a fail free in your calendar. It is the tightest deadline in the scheme.
  9. Diarise renewal at eleven months, since certificates expire after twelve.

Conclusion

How long does Cyber Essentials take? Days, if the estate is ready. Weeks, if it is not. The scheme is quick and getting your estate ready for it is the project, and that is the part worth planning properly. An organisation with clean patching, enforced MFA and no unsupported software can be certified in days. An organisation discovering all three at once should count on a month or two, and should start by reading the question set rather than by paying for an assessment.

Transputec holds Cyber Essentials Plus, ISO/IEC 27001 and ISO 9001, so we have been through this from the inside as well as alongside our clients. We do not sell the certificate. We do the estate work that decides whether you pass it: patching, device configuration, access control and malware protection, delivered through our cyber security services.

If a contract date is driving your timeline, work backwards from it today and talk to our UK team about what your estate needs.

FAQs

A well-run small business with MFA enabled and current software can certify in one to two weeks, and the self-assessment itself takes about an hour. If unsupported operating systems or patching gaps turn up during scoping, expect four to eight weeks. Size matters far less than the state of the estate.

Most assessors aim to return a result within three working days. A pass produces the certificate immediately. If the assessor needs more detail to mark an answer, they return it to you and that adds a few days to the cyber essentials process.

You get a report listing every answer with the assessor’s comments on anything non-compliant, then two working days to fix simple issues and resubmit at no extra charge. The assessor aims to remark within three days. If you are still non-compliant after those two days, you reapply and pay again.

The Cyber Essentials Plus audit must be completed within three months of your Cyber Essentials certificate. Book it early, because it involves an independent technical audit with internal and external vulnerability scans and device sampling, and that needs scheduling with an assessor rather than being done on demand.

Twelve months from the date the certificate is issued, for both Cyber Essentials and Cyber Essentials Plus. IASME emails a reminder roughly a month before renewal is due, and organisations that do not recertify are removed from the certified organisations list. Diarise it at eleven months so the estate work is done in good time.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his “straight-talking” approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch