Cyber Essentials Certificate: what it is, how to get one, and how long it lasts (2026)
A Cyber Essentials certificate is a dated, verifiable digital document issued by an IASME-licensed certification body. This guide covers exactly what the certificate proves, how long it is valid, how third parties verify it, and the fastest, cheapest route to getting one in 2026.

Section 01
Cyber Essentials Certificate: what it is, how to get one, and how long it lasts (2026)
A Cyber Essentials certificate is a commonly requested cyber-security credential in UK procurement. It is a dated, verifiable digital document issued by an IASME-licensed certification body, confirming that an organisation has been assessed against the five Cyber Essentials controls and passed.
That sentence contains four specific claims that matter when a buyer asks to see your Cyber Essentials certificate, and this guide pulls them apart - what the certificate is, what it proves, how long it lasts, how a third party verifies it, and how to get one in 2026 at the lowest published price and shortest turnaround in the UK.
Section 02
What a Cyber Essentials certificate actually is
A Cyber Essentials certificate is issued digitally. Verify its details through the IASME certificate search, and follow the current scheme branding rules when using the badge. The certificate's integrity comes from three things:
1. The issuing body is IASME-licensed. IASME is the sole delivery partner appointed by the National Cyber Security Centre (NCSC) to run the scheme. Only an IASME-licensed body can issue a valid certificate.
2. The organisation's details can be checked through the IASME certificate search. Search by name or reference and compare the result's level, dates and scope with the presented certificate. Ask the issuing body or IASME about details that are not displayed.
3. The certificate is dated and time-bound. A Cyber Essentials certificate is valid for 12 months from the date of issue. After that, it expires and the organisation needs to recertify to maintain the entitlement to use the badge.
Check the presented certificate's named organisation, scope, level, reference, issue and expiry dates against the issuing body's record; do not assume every public search result displays every field.
Section 03
What a Cyber Essentials certificate proves
A Cyber Essentials certificate proves that, on the date of issue, the certified organisation met the five technical control requirements of its applicable account version (v3.3 for applications started from 27 April 2026; earlier applications may continue under v3.2):
- Boundary firewalls and internet gateways - every internet-facing boundary is controlled, default credentials changed, ports restricted.
- Secure configuration - devices, servers and cloud services are hardened against known weaknesses, unused accounts and services disabled.
- User access control - users are given only the access they need, admin rights are separated from day-to-day accounts, MFA is enforced.
- Malware protection - endpoint protection is present and functioning across the scope.
- Security update management - software, firmware and operating systems are maintained within the 14-day high-severity patching rule.
What the certificate does not prove:
- It is a point-in-time assessment. Check its explicit expiry date; controls may have drifted even while the certificate remains current.
- It is not a full information-security management system (that is what ISO 27001 provides).
- It does not verify that every device inside the organisation passes every test. The standard Cyber Essentials assessment is a verified self-declaration; the hands-on technical testing happens at Cyber Essentials Plus.
That combination makes the certificate useful evidence where a buyer or insurer asks for it. The exact level, entity, scope and acceptable equivalents depend on the applicable contract or policy; a Basic certificate is not a universal minimum for every government, healthcare, legal or defence purchase.
Section 04
How long a Cyber Essentials certificate is valid
Twelve months from the date of issue. Check the explicit issue and expiry dates on the award and IASME certificate search. Do not infer validity from a generic twelve-month statement alone.
Some buyers ask for "a current Cyber Essentials certificate." In practice that means one whose expiry date is still in the future at the time the buyer checks. Organisations working in regulated procurement typically start the renewal process 60-90 days before expiry to avoid any gap in coverage. If the certificate lapses, the organisation drops off the IASME directory listing as "current" and the badge can no longer be used in marketing.
The 12-month cycle continues under v3.3. New applications from 27 April 2026 use v3.3, while earlier accounts may continue under v3.2. Check the account version and exact requirements. A privately owned home router used for internet access is normally out of scope; an organisation-supplied router is in scope.
Section 05
How to verify a Cyber Essentials certificate
Anyone checking a presented award can search the public IASME certificate search. The separate certification-body directory verifies the issuer's licence. Compare the result with the actual document and contract scope.
Three things to check on any certificate presented to you:
1. The organisation name matches the legal entity you are working with (not a parent company, not a dormant shell, not a sister trading name).
2. The explicit expiry date has not passed; check the issue date and any scope changes too.
3. The certification body on the certificate is IASME-licensed - the licence ID on the certificate should be searchable on the IASME find-a-certification-body page.
If a search does not return the certificate, check the entity name, reference and dates and ask the issuing body or IASME to verify it. A failed lookup alone does not establish invalidity.
Section 06
How to get a Cyber Essentials certificate
The end-to-end process in 2026 is entirely online. A fully-prepared small organisation can go from purchase to issued certificate inside the same working day with a fast certification body.
Step 1 - Size your organisation. Certification bodies price in tiers based on headcount: Micro (1-9), Small (10-49), Medium (50-249), Large (250 - 9,999). Include full-time staff, part-time, contractors, and directors. The tier you fall into sets the assessment fee, not the complexity of the assessment.
Step 2 - Run a readiness check. Before you pay, verify you meet the five controls. Fig Group's free readiness checker produces a score against each v3.3 control in under 10 minutes; the NCSC's own published requirements document is the primary reference for what "compliant" looks like.
Step 3 - Choose a certification body. Four things to confirm before buying:
- Published price on the website (no "request a quote" gate).
- Published turnaround SLA in working hours.
- Current licence for the required scheme on the IASME certification-body directory.
- Clear statement of how many free re-submissions are included if the first submission fails.
Step 4 - Buy the assessment. Pay online, receive portal login, complete the self-assessment questionnaire (typically 60-90 minutes for a prepared organisation). Attach supporting evidence where requested.
Step 5 - Receive the certificate. If the submission passes, the certificate is issued digitally and emailed, and verify the award through the IASME certificate search; publication timing should be checked with the issuing body. If the submission flags gaps, written feedback comes back through the portal with the number of free re-submissions included in your purchase.
Step 6 - Use the certificate. Add the badge to the website, include the certificate PDF in tender responses, and add it to supplier-onboarding packs. Keep a reminder 60 days out from expiry to begin the renewal cycle.
Section 07
How much a Cyber Essentials certificate costs in 2026
Check IASME direct prices and each body's current package; these are provider offers, not one IASME-standard market range.
Fig Group publishes Cyber Essentials from £299.99 + VAT for Micro, Fig Group's published standalone Micro price under its current offer. Full tier pricing is on the pricing page; nothing is gated and nothing is quote-based.
Section 08
How quickly you can get a Cyber Essentials certificate
Fig Group publishes a conditional six-working-hour Basic guarantee after receipt of a complete, compliant submission before midday UK time on a UK business day. This is a stated provider commitment, not a market-wide outcome or a guarantee that preparation and corrections fit within one day. Compare other providers' current written terms on equivalent conditions.
Different written clocks can reflect intake, assessor capacity, clarification and customer remediation. Compare equivalent package and submission conditions. If your procurement deadline is tight, the body you pick determines whether you hit it.
Section 09
Getting a Cyber Essentials certificate with Fig Group
Three verifiable facts that matter when a buyer asks for your certificate:
- Fastest. 6-hour turnaround on compliant submissions - a published guarantee after receipt of a complete, compliant Basic submission before midday UK time on a UK Business Day, subject to terms.
- Cheapest. Cyber Essentials from £299.99 + VAT - the lowest published price for a standalone assessment from any IASME-licensed body in the UK.
- Verifiable. The Cyber Essentials licence is independently verifiable through its Blockmark badge and registry link on the trust page. 5.00 / 5 on Google across verified reviews.
A Cyber Essentials certificate is meant to be a clear, fast, affordable proof point. Fig Group operates on that premise end-to-end - you can buy the assessment in five minutes and, for a fully-prepared organisation, hold the certificate the same working day.
Section 10
Bottom line
A Cyber Essentials certificate is a dated, verifiable digital document from an IASME-licensed certification body. It records a successful assessment against the account's applicable requirements and has an explicit expiry date. Fig Group publishes a Micro Basic assessment below £300 + VAT with a conditional six-working-hour guarantee; other packages may include support or Plus testing that changes price and timing.
Start your Cyber Essentials certificate from £299.99 + VAT | All pricing tiers | Run the free readiness check | FAQ
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Accreditation: the UK guide to getting and keeping your certificate (2026)
The phrase "Cyber Essentials accreditation" is used widely to describe the process of getting certified - but strictly speaking, accreditation applies to IASME, not to the organisations it certifies. This guide explains the accreditation chain, who sits where, and the fastest, cheapest route to joining it in 2026.
Read articleGuides
Cyber Essentials Online: the complete UK guide for 2026
Cyber Essentials is an online certification - the self-assessment, the evidence review, the assessor feedback, and the certificate itself all happen through a portal. This is what that actually looks like in 2026, what to watch for when you pick a certification body, and where the market currently sits on price and turnaround.
Read articleGuides
How to verify a Cyber Essentials certificate: the buyer and procurement-team guide (2026)
A supplier has sent you a PDF claiming to be their Cyber Essentials certificate. How do you confirm it is real, current, and issued to the organisation you are actually contracting with? This is the verification guide for procurement and tender-assessment teams.
Read article

