The honest answer is that Cyber Essentials takes between two days and three months, and the difference has almost nothing to do with the assessment.

Filling in the questions takes an hour or two. Getting to the point where you can answer them truthfully is the part that varies, and it is where every deadline is won or lost.

1-2 hrsTo complete the questions, if you are prepared
3 daysAssessor review, and the same for any resubmission
InstantCertificate issued on passing

The published timings

These are the parts of the process with fixed, known durations:

StageHow long
Completing the assessment questionsOne to two hours, if your answers are prepared
Assessor review of your submissionWithin three working days
Responding to a request for more informationYou have two working days
Review of any resubmissionWithin three working days
Certificate issued after a passImmediately
Time allowed to use your registrationSix months from payment

Add those up and a prepared organisation goes from submission to certificate inside a working week. Which is why “how long does Cyber Essentials take” is really a question about what happens before you submit.

What actually takes the time

  • Building the asset list. Every device, every cloud service, every account. For a business that has never done it, this is the single biggest job, and it is almost always longer than expected because nobody knows about the marketing team's subscription until someone asks.
  • Fixing what the list reveals. Missing multi-factor authentication takes an afternoon. Replacing a machine running unsupported software takes weeks: procurement, configuration, migration, and the person who insists the old application will not run on anything newer.
  • Getting answers out of a third party. If your systems are managed externally, your timeline includes their response time, not just yours. Ask early and ask specifically.
  • Agreeing your scope. Straightforward for most organisations, but if a subset is involved it is a network design exercise before it is an assessment. Our guide to scope covers what that involves.
  • Board sign-off. Someone senior must confirm the answers are true. If that person is away for a fortnight, that fortnight belongs to your timeline.

Three realistic timelines

The prepared organisation: under a week. Modern equipment, supported software, multi-factor authentication already on, someone who knows what is in the estate. Answers prepared in a day, submitted, reviewed within three working days, certificate the same day it passes.

The typical organisation: two to four weeks. Nothing badly wrong, but the asset list needs building, a few accounts need tidying, one or two settings need changing, and the answers need checking with whoever manages the systems.

The organisation with a real problem: one to three months. Usually unsupported software or an unsupported operating system in scope. That is a procurement and migration project, and no amount of assessment urgency shortens it. This is the case that misses tender deadlines, and it is entirely predictable if you look early.

Working backwards from a deadline

If a customer or tender requires certification by a date, plan backwards rather than forwards:

  1. Certificate needed by the deadline date.
  2. Submit at least two weeks before, allowing for a resubmission cycle if the assessor asks for more information. Nobody passes first time by right.
  3. Start the honest review four to six weeks before that, which is when you find out whether you have a two-week problem or a two-month one.

In practice: six to eight weeks of lead time is comfortable, four is tight but achievable for most organisations, and under two weeks only works if you already know your estate is clean.

The one thing that changes the answer

Check for unsupported software first. Before the asset list, before the questions, before anything.

Software still receiving vendor security updates can stay in scope; software that does not, cannot. That single check is the difference between a two-week project and a three-month one, and it takes an afternoon to answer. Our guide to the five things that most commonly fail an assessment covers what else to look at while you are there.

Cyber Essentials Plus takes longer, and depends on the first

Plus requires a passing Cyber Essentials certificate before the technical audit can happen, so the two need sequencing rather than booking together at the last minute. Allow additional time to agree a testing window, and remember that the estate has to be in the state you described on the day of testing, not the state you intend it to be in.

For a deadline involving Plus, add three to four weeks on top of the Cyber Essentials timeline.

Find out where you stand

The fastest route to certification is knowing on day one which of the three timelines above you are on. That is a conversation, not an assessment, and it costs nothing.

Get in touch or call 01722 445972 and we will tell you what would fail today and roughly how long fixing it takes. If you are ready, we assess anywhere in the UK, remotely as standard. More detail on the service is on our Cyber Essentials certification page, with pricing published by organisation size.