Cyber Essentials certification isn’t a one-time badge — it’s a 12-month commitment. Once your certificate expires, there’s no grace period: the moment your window closes, so does your ability to display the badge, claim certified status, or rely on the accompanying cyber-liability insurance. If you supply central government, the NHS, MOD, or sit anywhere in a regulated supply chain, a lapsed certificate can pause contracts and flag your supplier record. Treat renewal like a project, not paperwork.
When to start
Most certification bodies let you begin your renewal submission up to 90 days before your current certificate expires. A sensible minimum is to start planning at least four weeks out. Submitting early doesn’t shorten next year’s coverage — your new 12 months simply starts from whenever you pass, so certifying a little early just pushes your next expiry date forward.
What actually changes at renewal
The renewal process itself mirrors your original application: a self-assessment questionnaire for Cyber Essentials, or a self-assessment plus external vulnerability scan for Cyber Essentials Plus. What can genuinely change year to year are:
• The requirements themselves.
IASME refreshes the Cyber Essentials question set roughly every April. If your renewal lands after a refresh, you’re assessed against the new version — even if you certified against the old one eleven months earlier.
The most recent update, v3.3, rolled out from late April 2026 and applies to assessment accounts created after that date. It introduced mandatory multi-factor authentication across all accounts, tighter patching rules (including new auto-fail questions if high-severity vulnerabilities aren’t fixed within 5 days, down from up to 14), full inclusion of cloud services within scope, and a director sign-off requirement.
• Your own environment.
New devices, new cloud tools, staff changes, office moves, or shifts to remote working all affect scope. Your renewal should reflect where your organisation is now, not where it was a year ago.
A four-stage approach
1. Review – Check the current requirements version against what you were assessed on last time, and map any gaps against your existing controls.
2. Prepare – Close those gaps: enforce MFA everywhere it isn’t already, confirm your patching process meets the current fix-time windows, and make sure every cloud service in use is properly documented and in scope.
3. Submit – Complete the self-assessment questionnaire (and third-party audit, if going for Plus).
4. Verify and certify – Once your assessor signs off, your new 12-month certificate is issued from that date.
Practical tips
• Don’t just copy last year’s answers — use them as a starting point, then check every question against the current version.
• If you’re close to your renewal date and know your environment needs work, consider whether certifying now or waiting to fully implement changes is the better call — some organisations deliberately certify just before a new question set lands to buy themselves a full year to adjust properly.
• If your certificate does lapse, some assessors offer a late-renewal path within 30 days of expiry, treating it as a renewal rather than a brand-new application — worth asking about before assuming you have to start from scratch.
The bottom line
Renewal is easy to underestimate because the process looks identical to your first certification. The real risk isn’t the paperwork — it’s assuming nothing has changed when both the requirements and your own IT estate almost certainly have. Build renewal into your annual compliance calendar, start early, and check the current question set rather than relying on memory of last year’s.
✅ Get certified for Cyber Essentials
✅ Get certified for Cyber Essentials
✅ Cyber Essentials + Cyber Essentials Plus combined package
Get Help Preparing for the New Standard
As an IASME-accredited certification body, we can help you review your infrastructure against the new v3.3 requirements, identify gaps before you apply, and guide you through certification under the Danzell question set — with no jargon and no surprises during assessment.
📧 Get in touch: mailto:info@cybercompliance.org.uk