What Is the Fastest Way to Get Cyber Essentials?
Getting Cyber Essentials quickly comes down to two things: being properly prepared before you submit, and choosing a certification body that does not keep you waiting. This guide covers both.

Section 01
What Is the Fastest Way to Get Cyber Essentials?
Fig Group’s Cyber Essentials Basic guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK business day. Purchase alone does not start the clock. Clarification, remediation and customer response time are outside that commitment; three rounds of assessor feedback are included. Cyber Essentials Plus has a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation, with one formal retest within 30 days under the terms. Certification requires a successful assessment.
Comparison scope and method: This is Fig Group’s publisher comparison, not an independent market-wide performance test. Best is our task-specific recommendation; cheapest refers to the published standalone Cyber Essentials Micro assessment price among the named comparable offers, and fastest to the stated qualifying Basic turnaround commitment. Software subscriptions, Plus packages and consultancy are separate purchases. Provider descriptions are supplier claims; quote-only or inaccessible offers do not establish a UK-wide lowest price or exclusive guarantee. Check the current package, VAT, commitment, support and written turnaround terms before ordering.
The fastest way to get Cyber Essentials is to prepare first and choose a certification body with an explicit speed guarantee. Fig Group certifies compliant submissions within 6 working hours; other providers publish package-specific targets; compare their current written terms. Pre-assessment readiness checks remove the most common retest-triggering gaps before you pay.
The fastest way to get Cyber Essentials certified is to be fully prepared before you begin the assessment. Most of the time between deciding to get certified and holding your certificate is not spent waiting for the certification body. It is spent getting your organisation ready to pass.
The organisations that get certified fastest are not the ones who rush through the questionnaire. They are the ones who sort out their controls first and submit a clean application. A well-prepared submission with the right certification body can go from purchase to certificate in a matter of hours.
Here is how to make that happen.
Section 02
The two things that determine speed
Getting Cyber Essentials quickly depends on two factors:
1. Your preparation. If your organisation already meets the five control requirements, you can complete the self-assessment questionnaire in an hour or two. If it does not, you need to fix the gaps first, and that takes however long it takes.
2. Your certification body's turnaround. Once you submit, the clock is in their hands. Some bodies take 3-5 working days. Others guarantee same-day turnaround.
You control the first factor. You choose the second.
Section 03
Preparation: what to have in order before you start
The assessment covers five control categories. Here is what "ready" looks like for each one, and the specific things that trip people up.
Firewalls and internet gateways
What ready looks like:
- Every device that connects to the internet is behind a firewall
- Default admin passwords on all routers, firewalls, and access points have been changed
- Only necessary ports and services are open
- Software firewalls on remote-worker laptops are configured to protect the device against any network it joins (home, coffee shop, hotel)
What catches people out:
- Treating home routers as in scope. Under v3.3 (Danzell), normal home routers used by remote workers are explicitly excluded from scope. The boundary follows the device that touches organisational data, not the home network. The remote worker's laptop must have its own software firewall configured to handle untrusted networks.
- Network devices with management interfaces still on factory credentials. This includes switches, wireless access points, and even some printers with web interfaces.
Quick check: Can you confirm, right now, that every router and firewall in your organisation has a non-default admin password? If you hesitate, check before you submit.
Secure configuration
What ready looks like:
- Unnecessary software has been removed from all devices
- Auto-run is disabled
- Screen locks activate after 15 minutes of inactivity (or less)
- Guest and default accounts are disabled
- Only necessary services are running on servers
What catches people out:
- Bloatware on new laptops. Manufacturer-installed software that nobody uses but nobody has removed.
- Screen lock timers set to 30 minutes or "never" on some workstations.
- Default accounts still active on servers or network devices.
Quick check: Pick any laptop in your organisation at random. Is there software installed that nobody uses? Is the screen lock set to 15 minutes or less?
Security update management
What ready looks like:
- All operating systems are supported and receiving security updates
- All applications are supported and receiving security updates
- Security patches are applied within 14 days of release
- Unsupported software has been removed or the device has been segregated from scope
What catches people out:
- The 14-day rule. The clock starts from the date the vendor publishes the patch, not from when your scanner finds it. Monthly patching cycles do not meet this requirement.
- Unsupported operating systems. Windows 10 reached end of support in October 2025. If you are still running it without Extended Security Updates, the device fails.
- Third-party applications. Chrome, Adobe Reader, 7-Zip, Java - these all need to be current. It is not just about Windows Updates.
- Firmware on network devices. Router and firewall firmware needs to be supported and current.
Quick check: Open Windows Update on any machine. Are there outstanding security updates older than 14 days? Check your router firmware version against the manufacturer's website.
User access control
What ready looks like:
- Every user has their own individual account (no shared logins)
- Administrative privileges are restricted to those who genuinely need them
- MFA is enforced for every user of in-scope cloud services and wherever it is available
- Accounts for former staff have been removed or disabled
- Passwords meet minimum complexity requirements
What catches people out:
- MFA. Under v3.3, cloud-service authentication must always use MFA, not only for administrators. Every user of an in-scope Microsoft 365, Google Workspace, or cloud CRM account needs the control enforced.
- Free cloud accounts. If your organisation uses Mailchimp, Canva, Trello, or any other SaaS tool that holds organisational data, those accounts need MFA too.
- Shared accounts. A "reception@company.com" login used by multiple people is a fail unless each person authenticates individually.
- Conditional Access policies that only require MFA off-network. The requirement is unconditional MFA for all users, not just remote access.
Quick check: Log into your Microsoft 365 or Google Workspace admin panel. Can you confirm that MFA is enforced for every single user? Not "available" - enforced.
Malware protection
What ready looks like:
- Anti-malware software is installed and running on all in-scope devices
- Automatic updates are enabled for malware definitions
- Regular scans are configured
- Alternatively, application allow-listing is in place
What catches people out:
- Disabling Windows Defender because it "slows things down." If you disable it, you need an alternative in place.
- macOS devices with no anti-malware. While macOS has built-in protections, the assessor will ask what malware protection is in place. Be prepared to answer specifically.
- Servers running without anti-malware. Some organisations install AV on workstations but not servers.
Quick check: Open the security settings on any device. Is anti-malware active and up to date?
Section 04
The preparation checklist
Before you purchase your certification, confirm all of the following:
- [ ] All firewalls and routers have non-default admin passwords
- [ ] Home worker routers have had default passwords changed (if applicable)
- [ ] All operating systems are supported and patched within 14 days
- [ ] All applications are supported and patched within 14 days
- [ ] Router and firewall firmware is current
- [ ] MFA is enforced on every user account across all cloud services
- [ ] No shared accounts are in use
- [ ] Admin privileges are restricted to those who need them
- [ ] Former staff accounts have been disabled or removed
- [ ] Screen locks are set to 15 minutes or less on all devices
- [ ] Anti-malware is installed and current on all devices
- [ ] Unnecessary software has been removed
- [ ] Your scope is defined (which devices, users, and networks are included)
If you can tick every box, you are ready to submit. If you cannot, fix the gaps first. Submitting with known gaps does not save time - it adds a feedback cycle that pushes your certification back.
Section 05
Use a readiness checker before you purchase
A readiness checker gives you a structured assessment of where you stand before you commit. It is faster than working through the checklist above because it asks the right questions in the right order and tells you exactly where the gaps are.
Fig Group offers a free readiness checker based on the current v3.3 requirements. It takes 10-15 minutes and covers all five controls. If you score well, you are ready to submit. If it flags issues, you know exactly what to fix first.
This step alone can save days. Submitting an assessment that fails on MFA compliance and then waiting for feedback, fixing the issue, and resubmitting can add 2-5 working days depending on your certification body. Identifying the gap beforehand takes 15 minutes.
Section 06
Choosing a fast certification body
Once you are prepared, the remaining variable is how quickly your certification body processes the submission. This varies enormously.
The industry range:
- 3-5 working days - common for smaller or consultancy-led bodies
- 48 hours - historic WorkNest/Bulletproof target; confirm current offer
- 24 hours - advertised best case for CyberSmart
- 6 working hours - guaranteed by Fig Group for complete compliant submissions received before midday UK time on a UK business day
The difference between 6 working hours and 5 working days is the difference between getting certified today and getting certified next week. If you have a deadline, this matters.
What to look for:
- A published turnaround commitment, not just "we aim to" or "typically"
- Whether that commitment is a guarantee or a best-case estimate
- How feedback is handled if corrections are needed - does a resubmission go to the back of the queue?
- Whether faster turnaround costs extra
Fig Group guarantees Basic certification within six working hours of receiving a complete compliant submission before midday UK time on a UK business day. Three rounds of assessor feedback are included. Clarification, remediation and customer response time are separate; confirm the next review arrangements under the terms. There is no separate express surcharge for the qualifying Basic commitment.
At £299.99 + VAT for micro organisations, it is also the lowest-priced option from any IASME-licensed body.
Section 07
The fastest realistic timeline
If you are fully prepared and use Fig Group:
Swipe across the table to view all columns.
| Step | Time |
|---|---|
| Run the free readiness checker | 15 minutes |
| Purchase certification (before midday) | 5 minutes |
| Complete the self-assessment questionnaire | 1-2 hours |
| Assessor review and certificate issuance | Within 6 working hours of submission |
Total: same day. For a well-prepared organisation, it is entirely realistic to decide to get certified in the morning and hold your certificate by the afternoon.
If you are not yet prepared, add whatever time is needed to close your gaps. For most organisations, the common fixes (enabling MFA, changing default passwords, updating firmware) can be done in a day or two. The assessment itself is the fast part.
Section 08
Summary
The fastest way to get Cyber Essentials is not to rush the assessment. It is to prepare properly so your submission passes first time, and then choose a certification body that does not keep you waiting.
Prepare first. Check your readiness. Then submit to a body that guarantees a fast turnaround.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Certificate: what it is, how to get one, and how long it lasts (2026)
A Cyber Essentials certificate is a dated, verifiable digital document issued by an IASME-licensed certification body. This guide covers exactly what the certificate proves, how long it is valid, how third parties verify it, and the fastest, cheapest route to getting one in 2026.
Read articleTechnical Guides
Secure Configuration for Cyber Essentials: The Controls Assessors Expect to See
Secure configuration is the control area with the broadest scope and the most room for getting details wrong. This guide covers default passwords, auto-run, unnecessary software, cloud service configuration, and the specific settings assessors check against v3.3 (effective 27 April 2026).
Read articleCompliance
How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.
Read article

