How to get Cyber Essentials certification, start to finish
The whole route in one place: what to decide before you start, what to fix, how the questionnaire and assessment actually work, and how long each stage genuinely takes for a small organisation.
Cyber Essentials is a self-assessment against five technical control areas, reviewed by a qualified assessor at an IASME-accredited certification body. There is no site visit at the basic level, no penetration test, and no requirement to own an IT department. The work is in three places: deciding the scope properly, fixing what would fail, and answering the questionnaire accurately. Here is the route in order.
Step 1 — Decide who and what is being certified
Before any technical question: which legal entity (or entities) is certifying, and is it the whole organisation or a defined subset? Whole-organisation is the default, the cleanest, and what most customers reading your certificate expect. If you certify a subset, the scope must be clearly described and exclusions justified — and cloud services can never be excluded.
Get the identity details exact at this stage too: registered name as it appears on the register, registered office rather than trading address, every entity that needs to appear. Submissions bounce on these before anyone reads a security answer — we cover the specifics in the details that bounce an application.
Step 2 — Inventory everything in scope
List every device used for the organisation's work — including home computers and personal phones that access organisational data or email, which are in scope regardless of who owns them (how that works). List every cloud service: email, accounts package, storage, website admin, banking, payroll, CRM. For each device: operating system and version. For each service: who has access and whether MFA is on.
For most small organisations the inventory is the longest stage — not because it is hard, but because nobody has ever written it down. It is also the most valuable artefact the process produces, certificate aside.
Step 3 — Fix the gaps against the five controls
Work the inventory against the five control areas: firewalls on every internet-connected device; secure configuration (default passwords changed, unused software and accounts removed, device locking); security update management — every operating system and application vendor-supported and patched promptly, with high-risk updates applied within 14 days; user access control — individual accounts, admin rights separated from daily use, MFA on cloud services; and malware protection.
The two findings that end assessments on their own are unsupported operating systems and missing MFA — both common, both fixable, and both far better discovered by you than by the assessor. The full failure list is in why applications fail. For a typical small organisation, remediation is configuration time rather than new kit — unless something is running an out-of-support operating system, in which case that machine is the budget conversation.
Step 4 — Choose the level and the certification body
Basic Cyber Essentials is the questionnaire route and what most contracts require; Cyber Essentials Plus adds an independent technical audit of a sample of your devices, and can only be taken alongside or shortly after the basic certification (which to choose). Assessment fees are set in published size bands — modest for a small organisation — and certification runs through an IASME-accredited certification body; the certificate is awarded by the certification body, not by any consultant you use. Costs, including what remediation really costs, are covered in how much does Cyber Essentials cost.
Step 5 — Complete the questionnaire, honestly
The self-assessment asks how your organisation actually operates — device counts, OS versions, account practices, MFA coverage, update habits. Answer from the inventory, not from memory or optimism: the declaration is signed at board level confirming the answers are accurate, and a certificate obtained on wrong answers protects nobody and voids the point of holding it. If a question reads ambiguously for your setup, resolve it before answering — that is precisely the moment support earns its keep (stuck on a question?).
Step 6 — Assessment, queries, and the certificate
An assessor reviews the submission and either passes it, or comes back with queries and a limited window to clarify or evidence answers. Respond specifically and promptly — assessor queries are usually about precision, not suspicion. On a pass, the certificate arrives quickly, lasts twelve months, and most small organisations also receive cyber liability insurance included with certification. Diarise the renewal immediately: it is a fresh assessment against a standard that will have moved (why year two catches people out).
How long it really takes
- Already tidy — inventory known, MFA on, supported systems: the whole process can complete inside a fortnight.
- Typical small organisation — some unknowns, some remediation: four to six weeks, driven almost entirely by how quickly the inventory and fixes happen.
- Starting from scratch — shared logins, unknown devices, an old machine or two: six to eight weeks, and worth every one of them.
The deadline that matters is usually a tender or a contract renewal — so count backwards from it and start the inventory now rather than the week the requirement lands.
Or hand us the whole route
We scope it, build the inventory with you, fix what would fail, and take you through to certificate — done for you, one all-in price. Start by seeing where you stand today.
Take the free readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Scheme requirements and fee bands are set by the NCSC and IASME and are reviewed periodically. Confirm the requirements applying to your own assessment before you begin.