CYBER ESSENTIALS

Cyber Essentials Certification in 2026: Process, Cost and Timescale

Cyber Essentials certification

Cyber Essentials certification provides a practical way for UK organisations to demonstrate that they have fundamental technical protections in place against common cyber attacks.

But how difficult is it to get certified? How much does it cost? How long does it take? And perhaps most importantly, how can you establish whether you are ready before paying for the assessment?

The certification process itself is relatively straightforward. The work required beforehand depends on the condition and complexity of your IT environment.

An organisation with an accurate asset inventory, supported software, properly configured devices and good security management may be able to proceed quickly. Another may discover unsupported applications, missing updates, excessive administrator privileges or configuration weaknesses that need to be addressed first.

This guide explains the complete Cyber Essentials certification process in 2026, from defining your scope and assessing readiness through to completing the questionnaire and receiving your certificate.

What is Cyber Essentials certification?

Cyber Essentials is a UK Government-backed cyber security certification scheme designed to protect organisations against the most common cyber threats.

The standard concentrates on five technical controls:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

For standard Cyber Essentials, organisations complete a verified self-assessment questionnaire. A senior person within the organisation confirms that the answers are accurate and a qualified Cyber Essentials Assessor reviews the submission.

Cyber Essentials Plus uses the same technical requirements but provides a higher level of assurance because an independent technical audit is used to verify that the controls are operating correctly.

For assessments registered from 27 April 2026, organisations should prepare using the Danzell question set and Requirements for IT Infrastructure v3.3.

The Cyber Essentials certification process

A useful way to think about certification is as six stages:

Scope
Prepare
Assess
Remediate
Submit
Certify

Step 1 – Define your assessment scope

Before answering the questionnaire, establish exactly what you are certifying.

This means identifying the organisation or part of the organisation being assessed and the devices, networks, servers, cloud services and other technology that fall within the certification boundary.

Scope deserves careful attention. If a device or service is included, it needs to meet the applicable Cyber Essentials requirements.

The 2026 requirements have also strengthened the treatment of scope. For example, cloud services hosting organisational data or services must be included, and exclusions need to be justified with appropriate segregation from the systems being assessed.

Related guide: How to Define Your Cyber Essentials Assessment Scope →

Step 2 – Prepare before buying the assessment

One of the most useful characteristics of Cyber Essentials is that you can see the questions before you pay.

Download the current Danzell question set and Requirements for IT Infrastructure and work through them against your real environment.

This is the point at which organisations should establish:

  • What devices do we have?
  • What software is installed?
  • Is everything supported?
  • Are required security updates installed?
  • Are firewalls correctly configured?
  • Who has administrator privileges?
  • Is MFA correctly implemented where required?
  • Is malware protection working?
  • Are devices securely configured?

Do not treat this purely as a questionnaire-writing exercise. The objective is to determine whether the technical conditions described in your proposed answers actually exist.

Finding a problem at this stage gives you time to fix it. Finding it after purchasing and submitting the assessment can put you under unnecessary time pressure.

Step 3 – Assess your Cyber Essentials readiness

Now compare the actual environment with each of the five technical controls.

This is where technical assessment becomes particularly valuable.

For example, an organisation might believe that all Windows devices are fully updated, only to discover an overlooked laptop containing missing security fixes. It may believe users operate without administrative privileges while several endpoints still have unnecessary local administrator accounts.

Other common areas worth checking include:

  • Unsupported operating systems and applications
  • Missing security updates
  • Unnecessary software and services
  • Insecure or inconsistent configurations
  • Disabled or incorrectly configured endpoint firewalls
  • Administrator and privileged accounts
  • MFA coverage
  • Malware-protection status
  • Devices that have been overlooked in the asset inventory

The important distinction is between believing a control is in place and being able to verify it.

Where SecureX7 fits

SecureX7 helps organisations assess the technical environment behind their Cyber Essentials answers.

Rather than relying entirely on manual inventories and individual device checks, SecureX7 can help discover assets, identify installed software, assess configurations and vulnerabilities, identify security weaknesses and prioritise remediation.

This allows potential problems to be identified before the organisation pays its assessment fee or submits its declaration.

Step 4 – Remediate the gaps

A readiness assessment will often identify some work to do. This does not necessarily indicate poor security; it may simply expose inconsistencies that have accumulated as the organisation has changed.

Prioritise anything that would prevent you from meeting the Cyber Essentials requirements.

  • Update – install required security fixes.
  • Upgrade – replace software that has reached end of support.
  • Remove – uninstall unnecessary or unsupported applications.
  • Configure – correct insecure settings or enable required security features.
  • Restrict – remove unnecessary administrative privileges or access.
  • Protect – ensure malware protection, firewalls and authentication controls are correctly implemented.

Once remediation is complete, verify the affected systems again. The objective isn't merely to record that somebody was asked to fix an issue; it is to establish that the required change actually happened.

How much does Cyber Essentials cost in 2026?

The standard Cyber Essentials assessment fee is determined by organisation size.

These are the current IASME prices for the verified Cyber Essentials self-assessment.

The price of Cyber Essentials Plus is not fixed. It depends on factors including the size and complexity of the organisation's IT environment and must therefore be quoted individually by a licensed Certification Body.

The assessment fee isn't necessarily the biggest cost

The published fee can make Cyber Essentials look extremely inexpensive—and for a well-prepared organisation it can be.

However, there is an important difference between the price of certification and the cost of becoming ready for certification.

Consider the internal time involved in:

  • Creating or validating an asset inventory
  • Identifying software and versions
  • Checking security updates
  • Reviewing firewall configurations
  • Checking administrator accounts
  • Verifying MFA
  • Removing unsupported software
  • Correcting insecure configurations
  • Gathering assessment information
  • Managing remediation
  • Completing the questionnaire

For a small, well-managed environment this may be modest. For a larger or poorly documented estate, preparation can require considerably more work than completing the questionnaire itself.

That makes readiness assessment valuable not simply from a security perspective, but from a cost perspective.

Related guide: How Much Does Cyber Essentials Really Cost? →

OrganisationEmployees2026 assessment fee
Micro0–9£320 + VAT
Small10–49£440 + VAT
Medium50–249£500 + VAT
Large250+£600 + VAT

How long does Cyber Essentials certification take?

There are really two different timescales to consider:

Assessment time

If you have already prepared your answers, IASME indicates that completing the online questionnaire itself may take only around an hour.

Once submitted, an Assessor normally aims to review the answers within three working days.

Preparation time

This is much harder to predict.

A well-managed small organisation may already satisfy most requirements and need relatively little remediation.

An organisation discovering unsupported software, missing security updates, configuration weaknesses or scope problems could require substantially longer.

This is why asking “How long does Cyber Essentials take?” without first establishing readiness is rather like asking how long an MOT takes without knowing the condition of the car.

The inspection may be quick. Preparing something to pass it is the unpredictable part.

Once you purchase Cyber Essentials, you have up to six months to complete the assessment. However, there is little advantage in starting that clock before you have established what needs to be done.

What happens if your assessment doesn't pass?

Your submission is reviewed by a qualified Cyber Essentials Assessor.

If more information is required, the Assessor can return questions for clarification.

If the initial assessment is unsuccessful, the scheme provides a limited opportunity to correct the problems and resubmit without another assessment fee. The current terms provide for one further assessment without additional charge where the resubmission is made within 48 hours of the unsuccessful result.

That is another reason to identify technical problems beforehand.

If you discover that dozens of endpoints need remediation after submission, two working days can disappear very quickly.

Preparing first changes the exercise from:

Submit → discover → rush to remediate

to:

Discover → remediate → verify → submit

The second is a much more controlled process.

Should you choose Cyber Essentials or Cyber Essentials Plus?

Both certifications assess the same five technical controls. The difference is the level of assurance.

Choose Cyber Essentials when the verified self-assessment meets your business, customer or contractual requirements.

Consider Cyber Essentials Plus when you require greater independent assurance that those controls have actually been implemented or when Plus is specified by a customer, tender or contract.

Cyber Essentials is a prerequisite for Plus. If you intend to proceed to Plus, the Plus audit must normally be completed within three months of the associated Cyber Essentials certification.

Plus also requires technical testing, so allow additional time for planning, remediation and coordination with the Certification Body.

Related guide: Cyber Essentials vs Cyber Essentials Plus →

Self-led certification or professional assistance?

Organisations have several ways to approach Cyber Essentials.

SecureX7 does not replace the qualified Assessor or Certification Body. Instead, it helps provide technical visibility before certification by identifying assets, software, vulnerabilities, configuration weaknesses and remediation priorities.

The roles are complementary:

SecureX7 – discover, assess, remediate and monitor
Certification Body – assess the submission and award certification

Self-led

You can download the assessment questions and requirements, prepare internally and purchase the assessment when ready.

This can work extremely well for organisations with appropriate technical expertise and a relatively simple, well-managed environment.

Supported preparation

You may decide that you need help interpreting the requirements, defining scope or preparing the organisation.

NCSC-assured Cyber Advisors and licensed Certification Bodies can provide professional Cyber Essentials support.

Technology-assisted readiness

There is also a separate issue: establishing whether what you think is configured actually matches what exists across your estate.

This is where SecureX7 fits.

When should you pay for Cyber Essentials?

For many organisations, the best answer is:

When you are reasonably confident that you are ready to pass.

Before purchasing the assessment, ideally you should be able to answer yes to the following:

  • We have defined our certification scope.
  • We have an accurate inventory of in-scope devices.
  • We know what operating systems and applications are installed.
  • In-scope software is supported.
  • Required security updates have been applied.
  • Firewalls are enabled and appropriately configured.
  • Devices meet our secure configuration requirements.
  • Administrator access is controlled.
  • MFA is implemented where required.
  • Malware protection requirements are satisfied.
  • Identified weaknesses have been remediated and verified.
  • We can answer the Danzell questionnaire accurately.

If several of those answers are “we think so”, rather than “we have checked”, another readiness review is probably worthwhile.

From certification to continuous readiness

Successfully passing Cyber Essentials is not the end of the process.

Your certificate lasts 12 months. Your technology estate can change tomorrow.

A new laptop arrives. An employee installs an application. A configuration changes. A new vulnerability is disclosed. Software reaches end of support. Someone creates an administrator account.

By the time renewal arrives, the environment you certified may be substantially different.

This is why SecureX7 approaches Cyber Essentials as a continuous readiness problem rather than an annual questionnaire exercise.

Continuous asset visibility, security posture assessment, vulnerability identification and remediation tracking can help maintain the technical baseline throughout the year.

When renewal approaches, the objective should not be to rediscover your security position from scratch.

You should already know it.

Cyber Essentials Certification: Frequently Asked Questions

Cyber Essentials is not universally mandatory for every UK organisation. However, it can be required for certain government contracts and may also be requested by customers, partners, insurers or supply chains.

Know Before You Submit

The Cyber Essentials questionnaire is not the difficult part.

The challenge is knowing whether the devices, applications, accounts and configurations across your environment actually support the answers you are about to give.

SecureX7 helps you find out before you pay the assessment fee.

Discover your assets. Identify compliance gaps. Prioritise remediation. Verify improvements. Maintain readiness.

Assess Your Cyber Essentials Readiness →

Book a SecureX7 Demo →

SecureX7

SecureX7 is a natively built, AI-driven cyber security platform that helps organizations become operationally secure and continuously compliant, without complexity.

Popular articles