Cyber Essentials renewal is not a renewal in the usual sense: the certificate expires twelve months after it was issued, nothing rolls over, and the organisation goes through the full assessment again — a new question set if IASME has issued one, every answer re-entered, the same fee, and the same pass-or-fail marking. That design is deliberate. The scheme treats the annual reassessment as the organisation’s annual review, and the question set changes each April, so a certificate earned against last year’s requirements is not evidence against this year’s.
Most renewal failures come from exactly that gap: an estate that passed under one version and has drifted, or a version change that moved a control. This guide sets out the renewal cycle and its dates, what changes between assessments, the fee, the timing rules for Cyber Essentials Plus, what a lapse costs in practice, and a twelve-month routine that turns the renewal into a confirmation rather than a scramble.

What Cyber Essentials renewal actually involves
| Element | Rule | Consequence |
|---|---|---|
| Validity | Twelve months from the date of certification | The certificate has an expiry date; customers and PPN 014 checks read it |
| What renews | Nothing — a new assessment is purchased and completed | The previous year’s answers are not confirmed or carried forward; each is re-entered |
| Question set | The set current at the time of purchase — Danzell from 27 April 2026, with Requirements for IT Infrastructure v3.3 | A certificate earned under Willow (v3.2) is renewed under Danzell; anything Danzell added or tightened applies |
| Fee | The IASME assessment fee for your size band, again: £320 micro, £440 small, £500 medium, £600 large, plus VAT (published September 2026) | A recurring annual line, not a one-off |
| Marking | Pass or fail; two working days to correct answers that are unclear or incomplete; a fail means reapplying and paying again | Answer from checked facts, not last year’s memory |
| Declaration | A board member or equivalent signs that the answers are true and that the controls will be maintained during the certificate’s life | The renewal is a governance act, not an IT form |
| Insurance | The £25,000 cyber liability cover, where eligible, runs with the certificate | Lapsed certificate, lapsed cover |
Why Cyber Essentials renewal fails
- Drift. A device or software product that was supported at the last assessment reached end of life; a critical update was missed beyond 14 days; a cloud service was added without MFA enforced; an ex-employee’s account was never removed. The controls were true once.
- Version change. The April update moved a requirement. Danzell in 2026 made scope descriptions unlimited in length and required out-of-scope areas to be documented, named the legal entities in scope with addresses and company numbers, ruled that cloud services cannot be excluded from scope, and tightened retesting for Plus. Answers copied from the previous submission miss all of it.
- Scope change. An acquisition, a new site, home workers issued with routers, a new BYOD population — the scope answered last year is not the estate that exists now.
- Timing. The certificate expired before the renewal was submitted; a Plus audit was booked more than three months after the basic pass and the basic had to be redone.
- Optimistic answers. Under Danzell several answers fail the assessment outright — an unsupported operating system inside scope, an unpatched critical update — and a fail costs the full fee again.
Cyber Essentials renewal and Cyber Essentials Plus
Plus is not renewed on its own. The Plus audit has to be carried out within three months of the basic self-assessment pass, so a Plus renewal means renewing the basic certificate first and booking the audit inside that window. Organisations that hold Plus therefore run the two together each year: submit the self-assessment, pass, then have the certification body test the sampled devices, the patch status, the MFA settings and the malware protection against the same question set.
Since v3.3, updates identified during the Plus audit must be applied across the whole scope rather than only to the sampled devices, which makes a clean basic pass more important than it was. Our guide to Cyber Essentials Plus covers the audit; the Cyber Essentials cost guide covers what the two together cost.
What a lapse costs
The scheme itself imposes nothing for a late renewal — there is no penalty, no grace period and no expedited route; you simply have no certificate until the new assessment passes. The cost is commercial. Under PPN 014, in-scope UK public bodies must ensure suppliers on higher-risk contracts hold the certification; a lapsed certificate on a live contract is a compliance breach for the buyer and a contractual one for you.
Private-sector supplier questionnaires increasingly ask for the certificate number and expiry date, and a supplier portal will flag an expired one automatically. The insurance lapses with the certificate. And a renewal submitted in a hurry after expiry is marked against the current question set with no time to fix what drifted, which is how a late renewal becomes a failed one and a second fee.
A twelve-month Cyber Essentials renewal routine
| When | What | Why |
|---|---|---|
| Month 1 (certificate issued) | Diarise the expiry date and a renewal start date ten weeks before it; file the submitted answers and the scope description | The answers are next year’s checklist |
| Monthly | Patch report: every in-scope device and firmware within 14 days of critical and high-risk updates; unsupported software list at zero | Security update management is the control that drifts fastest and fails outright |
| Quarterly | Access review: leavers removed, admin accounts separate, MFA enforced on every cloud service; asset inventory reconciled to the scope | User access control and scope are the next two failure points |
| April | Read IASME’s changes notice for the new question set and requirements version; list every question that changed | The renewal will be marked against the new set |
| Ten weeks before expiry | Run the current question set internally as a dry run, with evidence checked, not recalled; fix what fails | Two working days is not enough to fix a control after marking |
| Six weeks before expiry | Purchase the assessment; enter the answers from the dry run; obtain the board-level declaration; submit | Leaves time for the two-day correction window and, if needed, a resubmission before expiry |
| Within three months of the pass | Book and complete the Plus audit, if held | The basic pass expires as a basis for Plus after three months |
Our guide to the Cyber Essentials questionnaire covers the questions the dry run uses; Cyber Essentials scope covers the description that has to be rewritten when the estate changes.
Frequently asked questions
How often does Cyber Essentials need to be renewed?
Every twelve months. The certificate expires on its anniversary and a complete new assessment is purchased and submitted; nothing is carried over from the previous year.
Is Cyber Essentials renewal cheaper than the first certification?
No. The IASME assessment fee is the same for your size band each year — £320 to £600 plus VAT in 2026 — and a Plus audit is quoted separately each time.
Can we submit last year’s answers again?
Every answer is re-entered and marked against the current question set, which changes each April. Answers that were true a year ago may fail now, and questions Danzell added were not in last year’s submission at all.
What happens if our certificate expires before we renew?
There is no penalty from the scheme, but you have no certificate, the insurance lapses, and any contract or tender that requires certification is exposed. There is no grace period or fast track; the new assessment takes as long as it takes.
Does Cyber Essentials Plus renew separately?
No. Plus depends on a current basic pass and the audit must be carried out within three months of it, so a Plus renewal is a basic renewal followed by the audit inside that window.
Where this leaves you
Run Cyber Essentials renewal as a twelve-month control cycle with a submission at the end: patch to the 14-day rule every month, review access and scope every quarter, read the April changes, dry-run the current question set ten weeks out, and submit six weeks before expiry with the board’s declaration. The certificate that results is the same one you had — but the assessment behind it has to be earned again each year, against this year’s requirements.
References
- IASME — Cyber Essentials frequently asked questions — Validity, renewal, fees, the correction window and resubmission.
- IASME — Important update: changes to Cyber Essentials for April 2026 — The Danzell question set and Requirements v3.3, applying from 27 April 2026.
- NCSC — Cyber Essentials: Requirements for IT Infrastructure v3.3 — The controls the renewal is marked against.
- GOV.UK — PPN 014: Cyber Essentials scheme — Why a lapsed certificate matters on public-sector contracts.
More on Cyber Essentials
- Cyber Essentials renewal — you are here
- Cyber Essentials certification: the complete guide
- The Cyber Essentials questionnaire
- Cyber Essentials Plus: what the audit adds
- Cyber Essentials cost in 2026
- Cyber Essentials requirements: the five controls
The patch management and access review procedures, the asset inventory, the scope definition and the evidence records that make the annual dry run a check rather than a rebuild are in the Cyber Essentials UK Toolkit, or start with the free templates.