Cyber Essentials Annual Renewal Readiness
Prepare current scope, technical-control answers, evidence, and Cyber Essentials Plus testing readiness before the 12-month certificate expires.
Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months. Renewal is a new assessment against the current question set and technical requirements, not an administrative extension of last year’s answers.
Renewal preparation
- Reconfirm the organization, scope, networks, cloud services, end-user devices, servers, remote access, and boundary devices.
- Identify unsupported software and changes affecting firewalls, secure configuration, security updates, user access control, and malware protection.
- Rebuild responses against the current question set and retain accurate supporting records.
- For Cyber Essentials Plus, prepare representative systems and personnel for the required independent technical verification.
- Time submission to avoid a coverage gap while recognizing that the new certificate runs from its issue date.
Certification-body boundary
The IASME certification body and assessor control the assessment, follow-up, and certificate decision. Readiness support helps prepare accurate information and remediate gaps; it cannot mark its own submission or promise certification.
IASME, the NCSC delivery partner, confirms that both certificates are annually renewable and expire after 12 months. Review the current Cyber Essentials renewal guidance.