how long does cyber essentials certification last

A Cyber Essentials certificate does not expire quietly. It expires on a fixed date, twelve months after the assessment was passed, and after that date it stops being valid for whatever it was being used for, a tender, an insurance renewal, a client’s due diligence check.

Cyber Essentials is the UK Government-backed scheme run by the National Cyber Security Centre. Five technical controls sit underneath it, firewalls, secure configuration, access control, malware protection and security updates, and every assessment checks the same five whether it’s a first certification or a tenth renewal. Government suppliers need it. So do a growing number of care providers, schools, accountants and solicitors whose insurer or biggest client has started asking for proof rather than taking their word for it. If that’s the position your business is in, how long does Cyber Essentials certification last, and what actually happens at renewal, are worth knowing properly rather than guessing.

How Long Does Cyber Essentials Certification Last?

Twelve months. That’s the full answer, though the certificate makes a slightly bigger deal of it than a subscription renewal does, listing an explicit issue date and expiry date on the document itself. Once that expiry date passes, the certification stops counting, no matter how tight the underlying security actually still is.

The scheme sets the term at a year on purpose. A firewall rule gets loosened for a quick fix and nobody puts it back. Someone leaves the business and keeps their login for another eight months because offboarding is not top of anyone’s list on a Friday afternoon. None of that shows up on the day of the original assessment, since the systems were genuinely compliant that day. It shows up twelve months later, which is exactly when the scheme checks again.

Does Renewal Take as Long as the First Certification?

Not if the environment has been maintained. First-time certification for a reasonably well-managed IT setup typically takes two to four weeks from the initial conversation to holding the certificate, and most of that time goes on preparation rather than the assessment itself. Businesses with legacy systems or multiple sites needing to meet the standard can be looking at six to twelve weeks. Renewal should be faster than that, in theory, because the environment has already been through the process once.

In practice it often isn’t. Most businesses drift out of compliance within weeks of certifying and don’t notice until the renewal assessment flags it. At that point renewal starts to look a lot like the first certification all over again, remediation, re-testing, the same gap-finding exercise, just annually instead of once. The difference between a fast renewal and a slow one usually comes down to whether anyone was watching the controls in the twelve months between assessments.

When Should You Start Prepping for Renewal?

Waiting for the expiry date to arrive before thinking about renewal is how businesses end up needing the six to twelve week version of the process instead of the two to four week one. A sensible marker is to start a review around four to six weeks out, working back through the same five controls the assessment checks.

  • Firewalls and internet gateways, checking no rule was loosened for a temporary fix that never got reversed
  • Secure configuration across every device and piece of software, not just the defaults set on day one
  • User access control, especially anyone who left the business but never lost their login
  • Malware protection, confirmed active and updated rather than assumed to still be running
  • Security updates, applied promptly rather than queued and left for later

That leaves enough runway to fix anything that has slipped before the formal assessment happens.

The better answer is not to need a marker at all. Lift Off IT built Orbit because the twelve month gap between assessments is exactly where compliance quietly falls apart. Instead of checking against the Cyber Essentials controls once a year, Orbit checks continuously. A device falls out of line and it gets flagged that day, not eleven months later at the renewal deadline. Everything gets logged as it happens too, so by the time the annual reassessment comes round there is nothing left to find that wasn’t already caught and fixed months earlier. Renewal stops being a project someone has to remember to start. It becomes a formality that happens on schedule. Full detail on how Orbit works alongside Cyber Essentials certification is on our dedicated page.

Does Renewal Cost the Same as the Initial Certification?

The assessment fee is structured the same way at renewal as it is for first-time certification. Priced against the size of the business and the number of devices involved, so that part of the bill looks similar year to year. What changes is remediation. That’s where the real cost difference between renewal and initial certification actually sits.

A business getting certified for the first time has usually never applied all five controls properly, and gaps built up over years do not fix themselves for free. Expect a remediation cost on top of the assessment fee in that scenario, almost every time. Renewing after twelve months of active monitoring is a different story. Far less to fix means a lower bill, even when the assessment fee itself hasn’t moved. Skip the monitoring for a year and let things drift instead, and the renewal bill can land close to what was paid the first time round, for the privilege of getting back to where the business already was.

Should You Move Up to Cyber Essentials Plus at Renewal?

Cyber Essentials Plus covers the same five controls as standard certification, but it replaces the self-assessment questionnaire with a hands-on technical audit and vulnerability scan of the actual systems. It carries more weight in a formal procurement process because nobody has to take a business’s word for it. Renewal is the natural point to make the switch, since the environment is already being reviewed against the same five controls and moving to Plus adds the technical verification rather than starting a separate process from nothing.

Whether it is worth the jump depends on who is asking. If a public sector contract or a larger client has started requesting Plus specifically, that answers the question. If nothing has changed about who the certificate needs to satisfy, sticking with standard Cyber Essentials for another year and revisiting Plus at the next renewal is a reasonable call too. Demand for Cyber Essentials Plus has been climbing steadily among Liverpool businesses chasing public sector and enterprise contracts, and that trend shows no sign of reversing.

What Happens if You Miss the Renewal Date?

Miss the renewal date and the certificate does not pause. It lapses, and the business goes back to being uncertified until a new assessment is booked and passed, the same process as applying for the first time. Any tender, insurance renewal or client due diligence check that relied on an active certificate during that gap sees an expired one instead.

Running a cyber essentials certification check against the public IASME register takes a couple of minutes and confirms the exact expiry date, rather than relying on memory or an old PDF. It is worth doing on any supplier claiming to hold certification too, not just a business’s own. Being able to check Cyber Essentials certification status quickly matters more than it sounds, because for a business in a live procurement process, a lapsed certificate is not a technicality. It is the difference between qualifying for a contract and being disqualified from it.

A certificate with an expiry date is only useful if someone is tracking that date, and what is happening to the systems underneath it in the twelve months between assessments. Lift Off IT works as a Cyber Essentials certification service for Liverpool businesses across care, education, accountancy, law and beyond, through first-time certification and every renewal after it, with Orbit running in the background so the gap between assessments does not undo the work already done. For the full breakdown of what Cyber Essentials covers and what it costs to get certified in the first place, our complete guide to Cyber Essentials certification in Liverpool covers that in more detail, and our cyber security services cover what happens once the certificate is in place. Get in touch to talk through where the business stands against the five controls, or book a free review and find out whether renewal is going to be a formality or a fire drill.

Contact Us