There are two clocks, and providers only advertise one
Every "Cyber Essentials in 24 hours" claim measures the same thing: the assessor's clock. It starts when you press submit on a completed self-assessment and stops when a certificate is issued. It is the short clock, and every certification body competes on it.
The clock that decides whether you hit your deadline is the other one: the time from "we need Cyber Essentials" to "our answers are all true". That is the preparation clock. Nobody advertises it, because it depends on your estate rather than on the assessor. For an organisation with managed devices, MFA everywhere and a patching routine, it can be an afternoon. For one that has to strip local admin rights off forty laptops and replace an unsupported server, it is weeks.
A six-hour assessor cannot rescue a submission that was never going to pass. That is the whole of it.
Why a failed submission costs more than a slow assessor
Cyber Essentials is pass or fail against five technical controls. If your submission does not meet them you do not get a certificate that day at any price. Instead you get a feedback cycle: the assessor says what failed, you fix it, you resubmit.
The scheme allows one free resubmission within a limited window. Miss that window, or fail twice, and you are paying again and starting over. So the arithmetic that matters is this: a six-hour assessor plus two failed submissions plus a week of remediation is worse than a one-day assessor and a submission that passes first time.
How far ahead to start
| Your situation | Start this far ahead | Main risk |
|---|---|---|
| Managed estate, MFA everywhere, current patching | 1 to 2 weeks | A forgotten cloud service without MFA |
| Mostly managed, some legacy | 3 to 4 weeks | Unsupported software found late |
| Unmanaged devices, BYOD, no central control | 6 to 8 weeks | Admin rights separation across every device |
| Previously failed an assessment | 2 to 4 weeks | The resubmission window expiring |
| Cyber Essentials Plus required | Add 2 to 3 weeks | Scheduling the hands-on audit |
The three things that actually delay people
Unsupported software still in scope. An operating system, browser or application past its vendor support date is an automatic fail, and it is the most common one. Upgrading a few machines is a day. Replacing a line-of-business application that only runs on an unsupported platform is a project, and no assessor can shorten it.
MFA gaps on a cloud service nobody remembers. It is required on every cloud service for every user, administrators included. The failure is almost never the main tenant. It is an old file-sharing account, a marketing tool, a legacy mailbox. Inventory every cloud service before you answer the question, not after.
Everyday accounts with local administrator rights. Users must not do day-to-day work in an administrative account. On an unmanaged estate, separating those takes longer than people expect and needs a short period of user disruption. Start it the day you decide to certify.
What we do differently
We are an appointed IASME Certification Body, so the assessment and the certificate both come from us with no reseller in the chain. Assessment is within one business day of submission as standard, and the same day with the urgent option where you submit before midday. Every submission is reviewed by a qualified assessor and never fed into an AI system.
We will not tell you a date is achievable when it is not, and we will not pass a submission that does not meet the standard. If you see a provider guaranteeing a pass before looking at your estate, that guarantee is either meaningless or they are not really assessing you.
What a certificate actually buys you
Worth being clear about, because the speed question is usually a symptom of something else. A certificate answers a security questionnaire in one line instead of forty pages. It satisfies the Procurement Policy Note requirement on central government contracts involving personal data or technical services. It is increasingly priced into cyber insurance, and some UK insurers include automatic cover for smaller organisations that hold it.
What it does not do is make you secure on its own. It covers five controls, deliberately, because those five stop the overwhelming majority of commodity attacks. It is a floor rather than a ceiling, and anyone selling it as comprehensive security is overselling it.
The questions that catch people out
Home working and personal devices. If a device accesses organisational data it is in scope, including a personally owned phone. The home router your provider supplied is out of scope; the software firewall on the device is in.
Cloud services. All of them, including the ones nobody remembers. Infrastructure, platform and software as a service are all in scope, and the multi-factor requirement applies to every user of every one of them, not only to administrators.
Password policy. The scheme is specific: multi-factor authentication, or twelve characters minimum with no maximum below 160, or eight characters plus automated blocking of common passwords. A thirty-day forced rotation is no longer encouraged and will not help you.
Sub-contractors and temporary staff. If they use your accounts or your devices, they are in scope like anyone else.
What happens if you fail
You get written feedback saying what did not meet the standard, and a limited window in which to correct a small number of non-compliant answers. That window is the thing to watch. Miss it, or fail on something substantial rather than a handful of answers, and you are paying the fee again and starting over.
This is the argument for the gap analysis rather than for a faster assessor. Three hundred pounds spent finding out what fails, before you answer anything, is cheaper than a failed submission and a second fee, and considerably cheaper than a missed tender.
How to compare providers honestly
Four questions separate the ones worth using. Are you an appointed Certification Body, or a reseller passing my submission to someone else? Who marks it, and are they a certified assessor? Is any part of the marking automated or fed into an AI system? And what happens, specifically, if I fail?
A provider who cannot answer the first question with a register entry you can check is a broker. That is not automatically bad, but you should know you are paying a margin for it, and the turnaround they advertise includes a handover you cannot see.
Could you certify this week?
These are the five controls as an assessor reads them. Tick only what is true today, across everything in scope.