By EJN Labs · 25 Jun 2026 · 7 min read
How long does Cyber Essentials Plus take? For a prepared UK organisation, the technical audit itself runs one to three days, but the realistic end-to-end timeline is two to six weeks once you include the self-assessment, remediation of any failures and scheduling. Larger or unprepared estates can stretch to eight weeks or more.
How long does Cyber Essentials Plus take from start to certificate
Two to three weeks from kick-off to certificate is achievable for a well-prepared small business. An organisation that has never been certified, has a sprawling device estate or is carrying known vulnerabilities should plan for four to eight weeks, because remediation, not the assessment itself, sets the timeline.
The hands-on assessment is short. The single biggest variable is not the assessor’s diary, it is how much remediation you need to complete before the technical audit can pass.
Cyber Essentials Plus is the audited tier of the UK government-backed scheme administered by IASME. Unlike the self-assessed entry-level Cyber Essentials, the Plus tier requires an external assessor to independently verify your controls through hands-on testing. That verification step is fast. Getting your environment into a state where it will pass that test is where the weeks accumulate.
A realistic week-by-week timeline
Breaking the process into stages makes the timeline easier to plan against. The phases below assume a typical UK SME with a single office or a remote-first workforce and a few dozen devices.
- Week 0, scoping and self-assessment: You define the certification boundary (which devices, users, cloud services and networks are in scope) and complete the Cyber Essentials self-assessment questionnaire. This typically takes two to five working days of internal effort.
- Weeks 1 to 3, remediation: You close any gaps found during scoping, patching unsupported software, enabling multi-factor authentication, hardening configurations and removing unsupported operating systems. This is the most elastic phase and is where most timelines slip.
- Week 3 or 4, the technical audit: The assessor runs the hands-on tests across a representative sample of devices. For most SMEs this takes one to two days of assessor time.
- Week 4, certification decision: If everything passes, the certificate is usually issued within a few working days. If anything fails, you enter a remediation window.
If you already hold valid Cyber Essentials and your estate is in good shape, you can compress the front end and realistically certify within two weeks.
What the technical audit actually involves
The audited element is the part people underestimate, so understanding it removes surprises. A CE+ assessor verifies the five technical controls through evidence rather than self-declaration, sampling a representative set of in-scope devices, including end-user workstations, mobile devices and servers.
The assessment typically covers an authenticated vulnerability scan of sampled devices to confirm patching is current and that no high or critical vulnerabilities older than 14 days remain unaddressed, a test of malware protection, a check that multi-factor authentication is enforced on cloud services and administrative accounts, and a simulated email and web test to confirm that malicious payloads are blocked or quarantined. The assessor also reviews account separation and confirms that default or unsupported software has been removed. None of this is adversarial; it is a structured verification, which is precisely why it moves quickly when your controls are genuinely in place.
Why timelines slip and how to avoid it
Most delays trace back to a handful of recurring issues. Knowing them in advance lets you front-load the work.
- Unsupported operating systems: A single Windows 10 device past its support date or an end-of-life server will fail the audit outright. Replacing or upgrading hardware mid-process adds the most time of any single issue.
- Patch latency: Cyber Essentials requires high and critical vulnerabilities to be patched within 14 days, and the CE Plus audit verifies it. If your patch cadence is slower, the scan will flag findings and you will need a remediation pass.
- Multi-factor authentication gaps: Missing MFA on a cloud admin account or a forgotten SaaS service is one of the most common single-point failures.
- Scope confusion: Bring-your-own-device fleets, contractor laptops and shadow cloud services often surface late. Defining scope honestly at week zero prevents a scramble during the audit.
Booking the assessor early and treating the gap analysis as the real start of the project, rather than the audit date, is the most reliable way to keep to a tight schedule. For organisations that want assurance that runs deeper than the scheme’s baseline, a parallel Cyber Essentials penetration testing engagement surfaces issues a compliance audit is not designed to find.
How recertification and the annual cycle work
Cyber Essentials Plus is valid for 12 months, so recertification comes round every year. It is usually faster than first certification because your controls, evidence and scope are already documented, and a returning organisation that has maintained its baseline can often complete renewal in one to two weeks.
Maintaining patching, MFA and configuration standards through the year is what makes that possible. Teams that let standards drift after the first certificate turn an easy renewal back into a multi-week remediation project, so treating CE+ as a continuous standard rather than an annual event is the cheapest way to keep future timelines short.
How EJN Labs approaches Cyber Essentials Plus
EJN Labs is a CREST-accredited UK security firm, and we hold Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we run the certification we ask clients to achieve. Our work is delivered by senior and principal testers, never junior staff, and we begin every engagement with a gap analysis so you know exactly what stands between you and a pass before the assessor’s diary is booked. We give you fixed, scope-based pricing with no surprise day-rate creep, and where remediation testing is needed, retests are included so you are not penalised for fixing what we find. That combination of accredited assurance and clear timelines is what lets clients plan CE+ around their commercial deadlines rather than the other way round.
Frequently Asked Questions
How long does Cyber Essentials Plus take if we are already certified for the basic tier?
If you already hold valid Cyber Essentials and your estate is well maintained, Cyber Essentials Plus can usually be completed in two to three weeks. The self-assessment groundwork is done, so the timeline is driven mainly by booking the assessor and confirming your controls pass the hands-on audit.
Can Cyber Essentials Plus be done in a week?
Yes, it is possible but uncommon. A small, fully prepared organisation with current patching, enforced multi-factor authentication and no unsupported software could schedule the audit and receive a certificate inside a week. Most organisations do not start from that position, so a one-week pass is the exception.
Most organisations need a remediation window first, which pushes the realistic timeline to two to six weeks.
What slows a Cyber Essentials Plus project down the most?
Unsupported operating systems and unpatched high or critical vulnerabilities are the two biggest causes of delay. Both require remediation before the technical audit can pass, and replacing end-of-life hardware in particular can add weeks to a timeline that would otherwise be short.
How long after the audit do we get the certificate?
When the technical audit passes cleanly, the certificate is typically issued within a few working days. If the assessor finds failures, you enter a remediation window and book a partial retest, which adds time depending on how quickly the issues are closed.
How much does the timeline change for a larger organisation?
Larger estates take longer because the assessor samples more devices and there is simply more to remediate. Organisations with multiple sites, mixed device fleets or significant cloud sprawl should plan for six to eight weeks or more, with scope definition becoming the critical early task.
Get a clear CE+ timeline for your organisation
The fastest way to a predictable Cyber Essentials Plus timeline is an honest gap analysis up front. Explore our full range of cybersecurity services, see how a deeper assurance engagement complements the scheme on our Cyber Essentials penetration testing page, and when you are ready to plan dates and scope, request a CREST penetration testing quote from our accredited team.




Leave a Reply