WHY CYBER ESSENTIALS EXPIRES AFTER 12 MONTHS
The 12-month cycle is intentional. Cyber threats evolve, IT environments change, and the scheme requirements are updated periodically to keep pace - the Danzell update (v3.3) in April 2026 introduced the first automatic failure conditions in the scheme's history. Annual recertification ensures your certificate reflects your current environment and the requirements that are live today, not those from 12 or 24 months ago.
This matters in practice. An organisation that certified two years ago under different requirements, with a different device estate and different cloud services, would not have its certification mean much without annual verification. The 12-month cycle is what keeps the certificate credible to clients, procurement teams, and insurers.
WHEN TO START YOUR RENEWAL
Start at least 4-6 weeks before your certificate expires. This gives you time to:
- Review the current requirements - check whether anything has changed since your last certification
- Run through the controls to identify any drift from when you last certified (new cloud services added, new staff accounts created, patching processes slipped)
- Address any gaps before submission rather than after a failed attempt
- Complete the assessment before your current certificate lapses
The biggest mistake organisations make is treating renewal as a same-day task. A pre-submission check takes a little time to work through properly. If any remediation is needed, you want the weeks, not days, to address it.
Know your expiry date. Your certificate date is on the original certificate and verifiable via the IASME register and Blockmark registry. Add a calendar reminder 8 weeks before expiry - 6 to start the process, 2 weeks of buffer.
IS THE RENEWAL PROCESS THE SAME AS INITIAL CERTIFICATION?
Yes. Renewal follows exactly the same four steps as your initial certification:
- Scope confirmed - your current environment is reviewed, including any changes since last year
- Pre-submission gap check - controls reviewed against the current version of the requirements before anything is submitted; gaps identified and addressed first
- Guided submission - questionnaire completed with plain-English support; you complete and sign the declaration yourself
- Assessed and certified - once submitted, assessments at Vincent Cyber Defence are typically completed within 1-2 business days
There is no streamlined or abbreviated renewal path. The self-assessment questionnaire is completed in full each time, reflecting your current environment against the current requirements. This is what makes the certificate meaningful.
One practical benefit of renewing with the same certification body: your assessor already has context from your previous assessment. At Vincent Cyber Defence, you deal with the same named assessor year after year. That continuity means the pre-submission review at renewal is faster - we know your environment, your scope, and what changed.
WHAT MIGHT BE DIFFERENT THIS YEAR
Two things can change between certification cycles:
1. The Requirements
IASME updates the Cyber Essentials requirements periodically. If you certified under the previous Willow question set and your renewal falls after 27 April 2026, your renewal will be assessed under Danzell (v3.3). That means the new auto-fail rules now apply:
- MFA must be enabled for all users on all cloud services - if any cloud service supports MFA and it is not enforced, your assessment will automatically fail
- OS and firmware patches must be applied within 14 days of release (auto-fail if not)
- Application patches must be applied within 14 days of release (auto-fail if not)
- Cloud services are formally in scope - Microsoft 365, Google Workspace, and similar platforms cannot be excluded from scope if used for business purposes
Organisations that have been compliant for years are sometimes caught out at renewal by requirement changes they did not know had been introduced. Reviewing the current version before you start the questionnaire is not optional - it is the point of doing it annually.
2. Your IT Environment
Over the course of a year, most organisations add new devices, adopt new cloud services, add or remove staff, change remote working arrangements, or move offices. Your renewal self-assessment must reflect your environment as it is now, not as it was when you last certified.
Common sources of scope drift:
- New cloud services adopted mid-year without MFA being enforced from day one
- New staff accounts created without following the access control procedures from your last assessment
- New devices (laptops, mobile phones) added without being enrolled in patching or endpoint protection
- Software installations that are not covered by automatic update policies
- Changes to remote working that bring home network devices into scope
The renewal questionnaire is not a copy-paste from last year. It should reflect your current environment. An assessor reviewing a questionnaire that clearly does not match what has changed will flag it. Organisations that keep a simple IT change log throughout the year find renewal significantly faster.
WHAT HAPPENS IF YOUR CERTIFICATE LAPSES?
There is no grace period. The moment your Cyber Essentials certificate expires, you are no longer certified. This has immediate consequences if:
- You hold a government contract that requires current Cyber Essentials - a lapsed certificate is a compliance failure, not a near-miss
- Your cyber liability insurance was tied to your Cyber Essentials certification - check your policy terms carefully
- A client or procurement team asks for evidence of certification - your certificate will show as expired on the IASME register and Blockmark
- You are using your CE badge on your website or in tender submissions - a lapsed certificate means you are no longer entitled to use it; continuing to do so after expiry is misrepresentation
A lapsed certificate cannot be extended - you recertify from scratch. The process and cost are the same as a new certification. The only consequence of lapsing is the gap in certified status between expiry and your new certification date.
For DCC Level 0 holders: a lapsed Cyber Essentials certificate puts your DCC Level 0 certificate at risk. The CE renewal obligation runs throughout your 3-year DCC cycle. Do not let CE lapse.
HOW MUCH DOES RENEWAL COST?
The same as initial certification. There is no renewal premium, and there is no loyalty discount either - the pricing bands are fixed by organisation size each year.
| Organisation | Annual Renewal Cost |
|---|---|
| Micro (0–9 employees) | £320 + VAT |
| Small (10–49 employees) | £440 + VAT |
| Medium (50–249 employees) | £500 + VAT |
| Large (250+ employees) | £600 + VAT |
All prices include the IASME certification fee. There are no additional charges for the pre-submission gap check, assessor support, or resubmission if the initial submission needs further work.
The free cyber liability insurance up to £25,000 also resets with each annual renewal for eligible UK organisations (turnover under £20m, whole-organisation scope). No separate application is needed - it renews automatically with your new certificate.
CAN YOU SWITCH CERTIFICATION BODY AT RENEWAL?
Yes. You are not locked into the certification body that issued your previous certificate. Your certification history is recorded on the Blockmark registry and the IASME certificate search tool, and it remains there regardless of which certification body assessed you. Switching at renewal is straightforward - you simply start the process with a new provider.
If you want to switch to Vincent Cyber Defence at renewal, get in touch and we will walk you through the process. We assess against the same IASME requirements as any other approved body, with the addition of the pre-submission gap check and direct assessor access included as standard.
UPGRADING FROM CE TO CE PLUS AT RENEWAL
Renewal is the natural moment to consider upgrading from Cyber Essentials to Cyber Essentials Plus. The process works as follows:
- CE basic renews as normal - self-assessment questionnaire, same process and pricing as above
- Once CE is certified, you have 90 days to complete and pass CE Plus
- The CE Plus technical audit follows - typically 3-5 business days after the audit starts
If your reasons for upgrading are contract-driven - a new government contract, an NHS tender, or an enterprise client that has started requiring Plus - you need to factor in the timeline. If you have a specific deadline, speak to your certification body at least 6-8 weeks before your CE expiry date to ensure both certifications can be completed in time.
Vincent Cyber Defence handles CE and CE Plus as a single engagement. You do not need to manage the sequencing yourself - we run the CE renewal and CE Plus audit back to back. See our CE Plus pricing guide for bundle costs if you are purchasing both together.
CYBER ESSENTIALS PLUS RENEWAL
If you already hold Cyber Essentials Plus, both your CE basic and CE Plus certificates are valid for 12 months. They renew together, following the same sequence each year:
- CE basic self-assessment renewed first
- CE Plus technical audit follows within 90 days of CE certification
- Your current CE Plus certificate remains valid throughout the renewal process - there is no gap in certified status while renewal is in progress
Start 4-6 weeks before expiry. The Pre-Assessment Check is included as standard with all CE Plus assessments at Vincent Cyber Defence, so any gaps are identified before the audit begins. Our CE Plus readiness checklist covers all seven audit areas.
DCC LEVEL 0: ANNUAL CE RENEWAL IS A REQUIREMENT
If you hold DCC Level 0, annual Cyber Essentials recertification is mandatory - it is built into the DCC certification structure, not optional. Your 3-year DCC certificate requires:
- Annual CE recertification (same process and cost as above)
- Annual attestation confirming your controls are maintained and your scope has not materially changed
Both the CE renewal and the attestation must be completed each year to keep your DCC certificate active. A lapsed CE certificate means your DCC Level 0 is at risk. Vincent Cyber Defence supports DCC holders through the annual attestation process as standard - it is not an extra. If your CE renewal is part of your DCC obligations, contact us early to manage both together.
YEAR-ROUND COMPLIANCE
The organisations that find renewal straightforward are those that treat Cyber Essentials as an ongoing discipline rather than an annual event. A few practical habits that make a real difference:
- Keep a simple IT change log - note new devices, new cloud services, new staff accounts, and software changes as they happen. Completing the renewal questionnaire from a change log takes a fraction of the time of trying to reconstruct a year's worth of changes from memory
- Check MFA coverage quarterly - new staff, new cloud services, and new applications can all introduce accounts without MFA. Under Danzell, a single account without MFA on a cloud service that supports it is an automatic failure
- Maintain your patching discipline year-round - the 14-day rule does not pause between certifications; it applies continuously. Organisations that patch consistently find the renewal assessment straightforward
- Run our readiness checklist before starting the renewal questionnaire - even if you were fully compliant last year, the CE readiness checklist will catch any drift in under 20 minutes
- Do not start the renewal on the day your certificate expires - if something needs addressing, you have no time to fix it
Ready to renew? Vincent Cyber Defence is an IASME Approved Certification Body. We guide UK organisations through annual Cyber Essentials renewal with the same pre-submission gap check, direct assessor access, and fixed all-in pricing as initial certification. Get in touch to start your renewal →
