Cyber Essentials

How fast can you really get Cyber Essentials?

Every provider advertises an assessment turnaround. Almost none of them tell you about the clock that actually decides your date. Here is the honest version.

There are two clocks, and providers only advertise one

Every "Cyber Essentials in 24 hours" claim measures the same thing: the assessor's clock. It starts when you press submit on a completed self-assessment and stops when a certificate is issued. It is the short clock, and every certification body competes on it.

The clock that decides whether you hit your deadline is the other one: the time from "we need Cyber Essentials" to "our answers are all true". That is the preparation clock. Nobody advertises it, because it depends on your estate rather than on the assessor. For an organisation with managed devices, MFA everywhere and a patching routine, it can be an afternoon. For one that has to strip local admin rights off forty laptops and replace an unsupported server, it is weeks.

A six-hour assessor cannot rescue a submission that was never going to pass. That is the whole of it.

Why a failed submission costs more than a slow assessor

Cyber Essentials is pass or fail against five technical controls. If your submission does not meet them you do not get a certificate that day at any price. Instead you get a feedback cycle: the assessor says what failed, you fix it, you resubmit.

The scheme allows one free resubmission within a limited window. Miss that window, or fail twice, and you are paying again and starting over. So the arithmetic that matters is this: a six-hour assessor plus two failed submissions plus a week of remediation is worse than a one-day assessor and a submission that passes first time.

How far ahead to start

Lead time to a certificate, by estate type
Your situationStart this far aheadMain risk
Managed estate, MFA everywhere, current patching1 to 2 weeksA forgotten cloud service without MFA
Mostly managed, some legacy3 to 4 weeksUnsupported software found late
Unmanaged devices, BYOD, no central control6 to 8 weeksAdmin rights separation across every device
Previously failed an assessment2 to 4 weeksThe resubmission window expiring
Cyber Essentials Plus requiredAdd 2 to 3 weeksScheduling the hands-on audit

The three things that actually delay people

Unsupported software still in scope. An operating system, browser or application past its vendor support date is an automatic fail, and it is the most common one. Upgrading a few machines is a day. Replacing a line-of-business application that only runs on an unsupported platform is a project, and no assessor can shorten it.

MFA gaps on a cloud service nobody remembers. It is required on every cloud service for every user, administrators included. The failure is almost never the main tenant. It is an old file-sharing account, a marketing tool, a legacy mailbox. Inventory every cloud service before you answer the question, not after.

Everyday accounts with local administrator rights. Users must not do day-to-day work in an administrative account. On an unmanaged estate, separating those takes longer than people expect and needs a short period of user disruption. Start it the day you decide to certify.

What we do differently

We are an appointed IASME Certification Body, so the assessment and the certificate both come from us with no reseller in the chain. Assessment is within one business day of submission as standard, and the same day with the urgent option where you submit before midday. Every submission is reviewed by a qualified assessor and never fed into an AI system.

We will not tell you a date is achievable when it is not, and we will not pass a submission that does not meet the standard. If you see a provider guaranteeing a pass before looking at your estate, that guarantee is either meaningless or they are not really assessing you.

What a certificate actually buys you

Worth being clear about, because the speed question is usually a symptom of something else. A certificate answers a security questionnaire in one line instead of forty pages. It satisfies the Procurement Policy Note requirement on central government contracts involving personal data or technical services. It is increasingly priced into cyber insurance, and some UK insurers include automatic cover for smaller organisations that hold it.

What it does not do is make you secure on its own. It covers five controls, deliberately, because those five stop the overwhelming majority of commodity attacks. It is a floor rather than a ceiling, and anyone selling it as comprehensive security is overselling it.

The questions that catch people out

Home working and personal devices. If a device accesses organisational data it is in scope, including a personally owned phone. The home router your provider supplied is out of scope; the software firewall on the device is in.

Cloud services. All of them, including the ones nobody remembers. Infrastructure, platform and software as a service are all in scope, and the multi-factor requirement applies to every user of every one of them, not only to administrators.

Password policy. The scheme is specific: multi-factor authentication, or twelve characters minimum with no maximum below 160, or eight characters plus automated blocking of common passwords. A thirty-day forced rotation is no longer encouraged and will not help you.

Sub-contractors and temporary staff. If they use your accounts or your devices, they are in scope like anyone else.

What happens if you fail

You get written feedback saying what did not meet the standard, and a limited window in which to correct a small number of non-compliant answers. That window is the thing to watch. Miss it, or fail on something substantial rather than a handful of answers, and you are paying the fee again and starting over.

This is the argument for the gap analysis rather than for a faster assessor. Three hundred pounds spent finding out what fails, before you answer anything, is cheaper than a failed submission and a second fee, and considerably cheaper than a missed tender.

How to compare providers honestly

Four questions separate the ones worth using. Are you an appointed Certification Body, or a reseller passing my submission to someone else? Who marks it, and are they a certified assessor? Is any part of the marking automated or fed into an AI system? And what happens, specifically, if I fail?

A provider who cannot answer the first question with a register entry you can check is a broker. That is not automatically bad, but you should know you are paying a margin for it, and the turnaround they advertise includes a handover you cannot see.

Could you certify this week?

These are the five controls as an assessor reads them. Tick only what is true today, across everything in scope.

Buy your Cyber Essentials now

Fixed price by organisation size, no quote and no sales call. We give you access to the IASME portal, you complete the self-assessment, and we assess it within one business day of submission. Add the gap analysis if you would rather know what will fail before you answer the questions.

An appointed IASME Certification Body: the certificate comes directly from us, with no reseller in the chain. Verify us on the BlockMark registry.

Optional add-ons

Tick any that apply. You can select both.

Total: select your size + VAT

Payment is taken by Stripe. We never see or store your card details. Your submission is reviewed by a qualified assessor and never fed into an AI system.

Something outside the standard package?

On-site support, an unusual estate, IASME Cyber Assurance, or a deadline you want checked before you buy. Tell us what you are dealing with and you will get a straight answer, not a sales call.

Your details are handled by a real person, never fed into AI.