Blog › Article
Cyber Essentials renewal: the year between assessments
A certificate records what was true on the day you answered the questionnaire. Renewal asks whether it is still true a year later — and for most organisations the honest answer is "mostly", which is not an answer the scheme accepts.
How Cyber Essentials renewal works
A Cyber Essentials certificate is valid for twelve months from the date it's issued. Renewing isn't a formality or a tick-box extension: you complete a new self-assessment questionnaire, it's reviewed again, and you pay the same fee again, set by organisation size.
Three things catch people out.
- The question set may have changed. An organisation certified under the previous questions renews under the current ones. The April 2026 change made MFA on cloud services and fourteen-day patching automatic-fail questions, so a renewal can fail on something the last certificate never tested.
- Lapsing has consequences. Contracts that require Cyber Essentials usually require a valid certificate throughout, and the bundled cyber insurance for eligible organisations follows the certificate. Don't plan around a grace period.
- Cyber Essentials Plus depends on it. Plus is built on a current Cyber Essentials certificate, so the base certificate has to be renewed first.
Why renewals fail
First assessments fail because nobody knew what the scheme asked. Renewals fail for a different reason: the organisation passed, then carried on changing, and nobody checked the changes against what it had declared.
New machines set up in a hurry
A new starter's laptop, built on the day they arrive, with a local administrator account "just for now" and updates that haven't caught up.
Temporary exceptions that became permanent
Admin rights given to install one piece of software. A firewall rule opened for a supplier's support session. Updates paused before a busy week. Each was reasonable at the time, and none was reversed.
New cloud services without MFA
A team starts using a new file-sharing or project tool. It's in scope the moment it holds organisational data, and if it offers MFA and it isn't switched on, that's an automatic fail.
Software that reached end of support
An operating system or application that was supported at the last assessment may not be now. Windows feature releases reach end of support on a schedule, and unsupported software can't be patched, so it can't meet the fourteen-day rule.
Leavers who still have access
Accounts that should have been disabled the day someone left, still active months later — often with the permissions they had on their last day.
None of these is a failure of the original assessment. They're what happens to every estate over twelve months. The difference between an easy renewal and a hard one is whether anyone was looking during the year.
A six-week renewal plan
Six weeks out
- Check which question set you'll renew under, and read what changed.
- Re-establish the scope: every device, user, site and cloud service in use now, not the list from last year.
Four weeks out
- List every cloud service and confirm MFA for administrators and users.
- Find every machine more than fourteen days behind on high-risk updates, including applications, and the reason why.
- Identify anything running unsupported software.
Two weeks out
- Review administrator accounts and remove rights that are no longer needed.
- Disable accounts belonging to leavers.
- Review firewall rules and close anything that was opened temporarily.
Submission
- Answer for the estate as it is on the day, not as it was last year.
- Keep the evidence behind each answer.
Doing it once a year versus all year
The six-week plan works, but it's the same scramble every year: finding the drift after it has happened, in a hurry, just before a deadline. The alternative is to watch the things that drift — update age, admin accounts, firewall and antivirus state — continuously, so that each problem is found in the week it appears rather than the month before renewal.
For an MSP that's also a better service to sell. A client whose certificate stays true all year is a client with a monthly reason to keep paying, and a renewal that takes an afternoon rather than a fortnight.
Quick answers
How long does a Cyber Essentials certificate last?
Twelve months from the date it's issued.
How much does renewal cost?
The same as the first assessment: the fee is set by organisation size and charged each year. Cyber Essentials Plus is priced separately by each certification body.
Is renewal the same questionnaire as last year?
Not necessarily. You answer the current question set, which may have changed since your last certificate.