Getting Cyber Essentials certified is a short process wrapped around a potentially long one. The certification itself can take about an hour of form-filling if you have prepared. Making the answers true is the part that takes weeks. This is the route through — and, at the end, how to run a Cyber Essentials certification check on a supplier who says they already have it.
The route, step by step
1. Download the question set before you pay
It is free from IASME. Reading it first turns unpleasant surprises into planned work, and it is the single highest-leverage thing you can do. If you have prepared your answers in advance, completing the self-assessment might take about an hour.
2. Decide your scope
Cyber Essentials is assessed against a defined scope: all end-user devices, servers, cloud services and networks used to access organisational data or services. That includes home working devices and personally owned devices used for work.
You can certify a clearly segmented sub-network rather than the whole organisation, but the boundary has to be real and you will be asked to describe it. Note that the fee band is set by the whole organisation's headcount regardless — narrowing scope reduces work, not cost.
3. Fix the automatic-fail items
Two things reliably cost people a second assessment fee:
- Unsupported software anywhere in scope. IASME is unambiguous that this fails the assessment outright. An end-of-life operating system on one in-scope machine is enough.
- Missing multi-factor authentication on cloud services. Usually not the main identity provider, but a standalone SaaS tool somebody bought on a card.
Inventory before you apply, not after.
4. Choose a certification body
Every certification body submits your assessment through the same IASME platform, so the assessment fee does not vary between them. What varies is the support wrapped around it — gap analysis, help completing the question set, remediation advice. If one quote is materially higher, you are buying that service, not a better certificate.
5. Apply, pay, and mind the clock
You get six months from the date of application to complete and submit. After that your account may be closed and you would have to apply and pay again, with no refund.
6. Get board sign-off
A board member must sign a declaration confirming the answers are true. This is not a formality — it is what gives a self-assessment its weight given that nobody scans your network at the base level. It also takes calendar time to arrange, so start it early.
7. Submit, and know the feedback loop
Most assessors aim to return results within about three days. If you have not passed, you get two working days to review the feedback, correct simple issues and resubmit, and the assessor re-marks at no extra charge. Fail after that and you reapply and pay again.
Two days is enough for a configuration change and nowhere near enough for a migration off unsupported software — which is why step 3 comes before step 5.
8. If you need Plus, book it inside three months
The question set is part of the Cyber Essentials Plus process, but if you certified less than three months earlier you do not repeat it. Beyond that window you do the work twice.
About the assessor
A Cyber Essentials assessor works for an IASME-licensed certification body and is qualified to mark submissions; for Plus, a qualified assessor performs the technical audit — internal and external vulnerability scans plus hands-on testing of a random sample of in-scope systems, typically around 10 per cent.
Assessors mark against a defined standard, so the outcome should not depend on which one you draw. Where a submission does not contain enough information to mark a question, the assessor returns it asking for more, which adds a few days.
Renewal
Certificates last 12 months, and both levels are annually renewable. Recertification is a fresh assessment at the same published fee band, and IASME is explicit that you re-enter all the information each time — deliberately, so that it functions as an annual review rather than a rubber stamp.
Two practical notes. Keep a copy of your submitted answers, because you will be answering the same question set next year and the questions themselves may have changed. And diarise renewal at ten months rather than twelve, because certification lapses on the date and IASME removes organisations from its certified list if they have not certified within the year.
Cyber Essentials certification check: verifying a supplier
If a supplier tells you they hold Cyber Essentials, you can verify it. IASME maintains a register of certified organisations, and organisations that have not certified within the past year are removed from it — which makes the register a currency check as well as an existence check.
Searching the register answers whether they hold it. It does not answer the questions that actually matter for your risk assessment:
- Which level? Base and Plus are frequently conflated in supplier questionnaires. Only one of them involved anyone testing anything.
- What scope? The certificate does not state it. A supplier can certify a sub-network that excludes the system you are buying. Ask for the scope statement.
- When was it issued? Twelve months is the validity, so a certificate issued fourteen months ago describes an expired state.
- What has changed since? This is the real limitation. The certificate describes the day of assessment, and nothing in the scheme monitors the supplier afterwards. A new internet-facing service, a lapsed patch cycle or an acquisition can undo it the week after.
The practical answer is to treat a certificate as a floor rather than an answer: confirm it on the register, ask for the scope statement and the date, and pair it with an assessment method that keeps working between certifications. That is what supplier risk management is for, and it is why the certificate is the beginning of a supplier conversation rather than the end of one.
Scheme details verified against IASME on 23 August 2026.
