Monitor

Blog › Article

22 July 2026 · Article

Cyber Essentials renewal: the year between assessments

A certificate records what was true on the day you answered the questionnaire. Renewal asks whether it is still true a year later — and for most organisations the honest answer is "mostly", which is not an answer the scheme accepts.

How Cyber Essentials renewal works

A Cyber Essentials certificate is valid for twelve months from the date it's issued. Renewing isn't a formality or a tick-box extension: you complete a new self-assessment questionnaire, it's reviewed again, and you pay the same fee again, set by organisation size.

Three things catch people out.

Why renewals fail

First assessments fail because nobody knew what the scheme asked. Renewals fail for a different reason: the organisation passed, then carried on changing, and nobody checked the changes against what it had declared.

New machines set up in a hurry

A new starter's laptop, built on the day they arrive, with a local administrator account "just for now" and updates that haven't caught up.

Temporary exceptions that became permanent

Admin rights given to install one piece of software. A firewall rule opened for a supplier's support session. Updates paused before a busy week. Each was reasonable at the time, and none was reversed.

New cloud services without MFA

A team starts using a new file-sharing or project tool. It's in scope the moment it holds organisational data, and if it offers MFA and it isn't switched on, that's an automatic fail.

Software that reached end of support

An operating system or application that was supported at the last assessment may not be now. Windows feature releases reach end of support on a schedule, and unsupported software can't be patched, so it can't meet the fourteen-day rule.

Leavers who still have access

Accounts that should have been disabled the day someone left, still active months later — often with the permissions they had on their last day.

None of these is a failure of the original assessment. They're what happens to every estate over twelve months. The difference between an easy renewal and a hard one is whether anyone was looking during the year.

A six-week renewal plan

Six weeks out

Four weeks out

Two weeks out

Submission

Doing it once a year versus all year

The six-week plan works, but it's the same scramble every year: finding the drift after it has happened, in a hurry, just before a deadline. The alternative is to watch the things that drift — update age, admin accounts, firewall and antivirus state — continuously, so that each problem is found in the week it appears rather than the month before renewal.

For an MSP that's also a better service to sell. A client whose certificate stays true all year is a client with a monthly reason to keep paying, and a renewal that takes an afternoon rather than a fortnight.

Quick answers

How long does a Cyber Essentials certificate last?

Twelve months from the date it's issued.

How much does renewal cost?

The same as the first assessment: the fee is set by organisation size and charged each year. Cyber Essentials Plus is priced separately by each certification body.

Is renewal the same questionnaire as last year?

Not necessarily. You answer the current question set, which may have changed since your last certificate.