How long does Cyber Essentials take? A practical guide for Sussex SMEs

One of the most common planning questions we hear from Sussex businesses exploring Cyber Essentials is a simple one: how long is this actually going to take?

The honest answer depends on where you're starting from. A business with a well-maintained IT environment and good existing security practices can move through the process relatively quickly. A business that hasn't had much IT governance attention will need longer. Here's a practical breakdown of what to expect at each stage.

Stage 1: Understanding where you stand (1–2 weeks)

Before you do anything else, you need to know what gap exists between your current security posture and the Cyber Essentials requirements. Skipping this step is the single biggest cause of businesses going into an assessment underprepared.

A proper pre-assessment review looks at each of the five control areas — firewalls, secure configuration, user access control, malware protection, and patch management — against your actual technical setup. Not against your best intentions or your memory of what was set up two years ago. Against what's actually running today.

For most Sussex SMEs, this takes one to two weeks depending on the size of your environment and how readily available the relevant information is. If you're working with a managed IT provider, they should be able to pull this together relatively quickly. If you're doing it yourself without much documentation, allow more time.

Stage 2: Remediation — the variable that determines your timeline (2–8 weeks)

This is the stage that most businesses underestimate, because the time required depends entirely on what the pre-assessment review reveals.

If your environment is broadly compliant already — good firewall configuration, current patches, managed endpoint protection, sensible account management — remediation might be two to three weeks of focused work tidying up specific gaps.

If there are significant issues — firewall rules that need a full review, a patch estate that's weeks or months behind, endpoint protection missing from remote worker devices, admin accounts that haven't been governed properly — you could be looking at six to eight weeks of work before you're ready to go through the assessment.

The specific areas that tend to take longest are patch management (because catching up a neglected patch estate needs to be done carefully to avoid breaking things), user access control (because reviewing and restructuring accounts across an organisation takes methodical work), and firewall configuration (because documenting and justifying every rule takes longer than people expect).

Our advice: don't set an assessment date until you've completed the pre-assessment review and have a realistic view of what remediation involves. Booking an assessment before you're ready and failing it costs you the assessment fee and the time to rebook.

Stage 3: The self-assessment (1–2 days for Cyber Essentials)

Once your controls are in place, the Cyber Essentials self-assessment questionnaire itself is not the time-consuming part. For a well-prepared organisation, completing the questionnaire takes a day or two. The accredited certification body typically reviews and issues a decision within a few working days.

For a well-prepared business, from submitting the questionnaire to having your certificate can be as quick as a week.

For Cyber Essentials Plus: add 3–6 weeks

Cyber Essentials Plus has additional stages that extend the timeline. Once you've implemented and self-assessed your controls, an independent assessor conducts:

•       External vulnerability scanning — typically takes a few days of scanning plus time to review and deliver findings.

•       Internal technical assessment — requires scheduling access to your network and systems; usually a one to three day engagement depending on your environment.

•       Remediation of assessment findings — critical issues found during the Plus assessment must be fixed before the certificate can be issued.

•       Verification and certification — the assessor confirms remediation and issues the certificate.

From starting the Plus process after your controls are in place, allow three to six weeks for the full independent assessment cycle. For a complex or larger organisation, it can be longer.

Realistic total timelines

For a well-prepared business with good existing IT governance, Cyber Essentials can be achieved in four to six weeks from starting the process to receiving the certificate.

For a typical Sussex SME starting from a moderate baseline — some good practices in place, some gaps to address — allow eight to twelve weeks for Cyber Essentials, or twelve to sixteen weeks for Cyber Essentials Plus.

For a business with significant remediation work needed, allow three to six months. It sounds like a long time, but trying to rush a poorly-maintained environment through the process rarely ends well.

If you have a deadline to meet

Some businesses come to us with a specific deadline — a contract that requires certification by a certain date, or a client that's asked for evidence of Cyber Essentials within a quarter. If that's your situation, the most important thing is to start the pre-assessment review immediately.

Once you know what remediation is needed, you can make an informed judgement about whether the deadline is achievable and what resource you'd need to meet it. Starting without that knowledge and hoping for the best is a plan that rarely survives contact with the actual state of your IT environment.

Getting started

If you're trying to plan your Cyber Essentials timeline, the right first step is a security audit that gives you a clear picture of where you're starting from. That's what our free security audit does — it maps your current posture against the Cyber Essentials requirements and tells you exactly what needs to happen before you're ready for the assessment.

We work with businesses across Sussex — from Haywards Heath and Burgess Hill to Crawley, Horsham, and Worthing — helping them navigate the certification process without the surprises that come from going in underprepared.

If Cyber Essentials is on your agenda for this year, let's talk. We'll give you a realistic timeline and a clear plan for getting there.

Previous
Previous

Managed IT vs In-House IT: Which Is Right for Your Business?

Next
Next

5 things West Sussex businesses get wrong before a Cyber Essentials audit