PassCyber
PassCyber / Guides

Cyber Essentials renewal — the honest guide

Your certificate lasts twelve months, then you certify again from scratch — and the rules have tightened since last time. Here's what renewal actually involves, why businesses that passed last year fail this year, what it should cost, and the thing incumbent providers don't advertise: switching is trivially easy.

Updated for the current question setReading time 5 minutes

Renewal isn't a rubber stamp — it's a fresh certification

There is no "renewal discount" version of Cyber Essentials. Every year you complete the current self-assessment in full, it's assessed against the current requirements, and you pass or you don't. That matters because the requirements move: the question set you certified under last year is not necessarily the one you'll face this year.

Why businesses that passed last year fail this year

Two rules now fail an assessment outright, and both catch renewing businesses who "just resubmit last year's answers":

Multi-factor authentication on every cloud service. MFA on all cloud services that offer it is now a hard requirement — partial coverage that scraped through before now fails on its own. If you've adopted a new cloud tool during the year without switching MFA on, that one service sinks the submission.

The 14-day update rule, strictly applied. High-risk security updates applied within 14 days, and nothing in scope that's out of vendor support. The classic renewal-time failure: a machine still running an operating system that left support during your certified year (Windows 10's retirement caught thousands of businesses exactly this way).

Scope drift does the quiet damage too: new starters' laptops, that tablet in the workshop, home-working kit added mid-year — all in scope, all assessable, none of it in last year's answers.

What renewal should cost

The certification fee itself is set by the scheme and depends on your size — for micro and small organisations it's a few hundred pounds. What varies wildly is what providers charge around it: some quote the bare assessment and leave you to fight the question set alone; others bundle "consultancy" you may not need at four figures. The honest structure — ours — is a fixed price that includes reviewing your answers against the current requirements before submission, fixing what would fail, and resubmission if needed. You should know the total before you start, in writing.

The part nobody tells you: you can switch provider freely

Because every year is a fresh certification, there is no lock-in whatsoever. Your certificate belongs to you, not to the company that processed it; nothing transfers, nothing needs permission, and no notice is owed. If last year's provider was a portal and a shrug, renewal is precisely the moment to choose better — the effort is identical, only the support changes.

The sensible renewal timeline

Start about six weeks before expiry: enough time to fix an unsupported machine or roll out MFA without panic, and to keep the badge continuous — which matters if a contract, framework or insurer requires an unbroken certificate. Week one: re-check your scope and run a readiness check against the current rules. Weeks two to four: close the gaps. Week five: submit. Leaving it to the final week converts £0 problems into emergency ones.

Get the renewal checklist — free

One page: the scope re-check, the two auto-fail traps, and the six-week timeline, as a checklist you can work through. We'll also tell you honestly whether your renewal looks straightforward or has a trap in it.

Done — the checklist's on its way to your inbox.
The two-minute head start

Before anything else, run our free readiness check against the current rules — it flags the MFA and 14-day traps specifically, so you know in two minutes whether this year's renewal is a formality or a project.

PassCyber

Renewing this year? Make it the easy kind.

Fixed price, current-rules review before submission, fixes included, resubmission covered. Tell us your expiry month and we'll map the timeline back from it — whoever certified you last year.

hello@passcyber.co.uk  ·  Take the readiness check

PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd