Most businesses treat Cyber Essentials renewal as a formality. It is not. It is a fresh assessment against the requirements as they stand on the day you submit, not the ones you passed against last year. The question set moves, the scheme version moves, and your organisation has spent twelve months quietly changing underneath both.

The good news is that renewal is genuinely easier than the first time, provided you start before the certificate expires rather than after.

12 monthsHow long a certificate is valid
6 weeksWhen we suggest starting renewal
48 hrsTo fix and resubmit free if you fail

What renewal actually is

Your certificate expires twelve months to the day after it was issued. There is no grace period and no partial credit for having held it before. Renewal means completing the current question set, having a board member or equivalent confirm the answers are accurate, and having a licensed assessor mark it, exactly as in year one.

Two things make it different from a first certification. You already know your scope, your asset list and where your evidence lives, which removes most of the work. And you are answering against requirements that may have changed since you last looked.

That second point is the one that catches people. The scheme moved to version 3.3, known as Danzell, in April 2026. A business that certified in early 2026 and renews now is answering a different question set from the one it passed. If you have not read the current requirements since your last assessment, read them before you start.

What changes in year two

  • Your people changed. Leavers whose accounts were never disabled, joiners set up in a hurry with more access than they need, and the person who left with an administrator account still active. Account review is where most renewal remediation actually happens.
  • Your devices changed. New laptops, replaced phones, a tablet someone bought and never told anyone about. Every device that touches organisational data is in scope, including personally owned devices used for work.
  • Your cloud services changed. The new project tool, the new accounting package, the marketing platform someone signed up for on a trial. Every cloud service holding your data is in scope, and the list is almost never the same twelve months on.
  • Your software aged. This is the big one. Software that was supported last year may not be now. Anything no longer receiving vendor security updates cannot stay in scope, so it must be upgraded, replaced, removed from scope through a valid scope definition, or covered by recognised vendor extended support.
  • The requirements moved. Version 3.3 tightened several areas. Our guide to the five things that most commonly fail an assessment covers what bites hardest under the current rules.
  • Your scope may have changed. A new office, a new subsidiary, a team that went remote. If the organisation you are certifying is not the organisation you certified last year, say so at the start rather than letting it surface mid assessment.

When to start

Six weeks before expiry, for a straightforward organisation. Longer if you already know something needs fixing.

The reasoning is simple arithmetic. Reviewing accounts, confirming the cloud service list and checking device patching takes a few evenings. If that review finds unsupported software or a device that needs replacing, procurement and deployment take weeks, not days. Starting six weeks out means a problem found is a problem fixed. Starting the week before expiry means a lapsed certificate.

A lapse matters more than it sounds. Your certification is either current or it is not, and the tender question asks for a valid certificate, not a recently expired one with a good excuse. If your certification underpins a contract, treat the expiry date the way you treat an insurance renewal.

What it costs

Renewal is priced as a new assessment, on the same size bands set by IASME. The fee is not discounted for existing holders, though the effort on your side usually is.

Organisation sizeEmployeesCyber EssentialsCyber Essentials Plus
Micro0 to 9£320 + VAT£1,195 + VAT fixed
Small10 to 49£440 + VAT£1,450 + VAT fixed
Medium50 to 249£500 + VATfrom £1,750 + VAT
Large250 or more£600 + VATfrom £2,500 + VAT

The included cyber liability insurance also renews with the certificate for eligible UK organisations certifying their whole organisation, so letting certification lapse quietly drops the cover with it. Full detail is in our Cyber Essentials pricing guide.

If you hold Cyber Essentials Plus

Plus follows the same twelve month cycle and depends on a current Cyber Essentials certificate, so the two need sequencing rather than booking separately at the last minute. The technical testing is repeated, not carried over, which means the estate needs to be in the state you claim it is in on the day, not the state it was in last year.

Practically: start the Cyber Essentials renewal six to eight weeks out, agree the Plus testing window at the same time, and give yourself room between the two.

Getting the most from the annual cycle

The twelve month cycle is the useful part of the scheme. It puts a date in the diary for the housekeeping that otherwise slips: accounts reviewed, leavers removed, the software inventory checked, cloud services accounted for, unsupported equipment dealt with before it becomes a problem.

Businesses that use renewal as a genuine annual review of how they operate get twelve months of maintained security rather than a single good day in the year. The certificate proves the work. The work is what protects the business.

If your renewal is approaching and you would rather it was straightforward, get in touch. We are a licensed certification body and assess anywhere in the UK, so we can tell you what has changed since your last assessment and whether anything in your estate would fail today. More detail on the service is on our Cyber Essentials certification page.