Skip to content
Compliance

Cyber Essentials in Under 6 Hours: Preparation and Guarantee

The fastest qualifying Cyber Essentials Basic route, step by step: scope, readiness, current controls and submission. Understand the six-working-hour guarantee and the preparation needed before its clock starts.

five assorted country wall clocks

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

16 min read

Share

Section 01

Cyber Essentials in Under 6 Hours: Preparation and Guarantee

For the fastest qualifying Basic route, prepare the environment and accurate answers before submission. This is a preparation playbook, not an authenticated customer timeline or a measured claim about every UK provider’s speed.

The Basic guarantee: Fig Group issues Cyber Essentials within six working hours of receiving a complete, compliant submission before midday UK time on a UK business day. Purchase, preparation, clarification, remediation and customer response time do not form part of that clock. Three rounds of assessor feedback are included; this is not unlimited certification attempts. A human assessor makes the certification decision. Read the service terms.

Section 02

Step 1: confirm the requirement and scope

Read the customer or tender requirement: Basic and Plus are different assurance levels. Identify the legal organisation, total headcount, devices, accounts, cloud services and any justified exclusions. Personally owned devices and remote access are not automatically outside scope. For virtual desktops, consider both the hosted environment and devices accessing organisational data under the current rules.

Use the current NCSC v3.3 requirements and applicable questionnaire. A historic pass or an informal readiness score does not establish current compliance. v3.3 became effective on 27 April 2026; Q1 2026 figures cannot establish results against that version.

Section 03

Step 2: prepare the five control areas

Firewalls and secure configuration

Configure the applicable boundary and device firewalls, remove unnecessary access and services, and change default credentials. A home router supplied by the ISP is outside scope, but an organisation-supplied router needs the actual scheme treatment. Remote devices need protection on untrusted networks. Avoid assuming that one office firewall covers every remote device.

For device-only unlocking, apply the relevant six-character minimum, credential-quality controls and guessing protection. Credentials also used for authentication need the full password requirements. Screen locking is relevant; a 15-minute setting is a local configuration choice, not a universal scheme minimum. Do not enforce regular password expiry or complexity; change compromised credentials promptly.

Security updates

Keep in-scope software supported and install applicable vendor-approved vulnerability fixes within 14 days of release where severity is high or critical, CVSS v3 is 7 or above, or severity is unspecified. This includes applicable firmware and applications. A current stable-release label or monthly maintenance schedule is not a substitute for the release-based deadline. Avoid a static OS allowlist: actual edition, support and extended-update coverage matter.

User access control

Use individually attributable accounts, least privilege, separate administrative access and prompt leaver removal. Apply MFA wherever available and always for authentication to cloud services. Document actual service-account treatment against the current rules; an unsupported exemption or a screenshot of enabled-but-unenforced MFA is not proof of the required control.

Malware protection

Use an applicable anti-malware or organisational application-allowlisting route on each relevant device. Keep protection current and configured for the scheme requirements. Do not treat a particular MDM product, tamper-protection setting or 24-hour signature cadence as a universal requirement. Gatekeeper alone is not proof of an organisational application allowlist.

Section 04

Step 3: gather accurate evidence and select the size band

Have the device inventory, software support/update records, user and administrator lists, cloud authentication settings and relevant configuration records ready. Confirm that evidence matches implemented controls. The readiness checker is preparation guidance, not the official questionnaire or a pass guarantee.

Swipe across the table to view all columns.

Organisation sizeEmployeesCyber Essentials price
Micro1–9£299.99 + VAT
Small10–49£399.99 + VAT
Medium50–249£449.99 + VAT
Large250+£549.99 + VAT

Choose using total organisation headcount and confirm any complex scope. The Large band is 250+. Existing accepted orders, subscriptions and signed terms remain unchanged by new website pricing.

Section 05

Step 4: order early and submit before the cutoff

Allow time for order processing, portal access and questionnaire completion. The qualifying clock starts when the complete compliant submission is received before midday UK time on a UK business day. Buying before noon is not enough on its own.

An illustrative prepared applicant might order in the morning and submit before midday, leaving the qualifying six-working-hour assessment window. These are planning steps, not a real redacted March case, a guaranteed database-listing time or proof of an average purchase-to-certificate duration.

Section 06

Step 5: respond to feedback by fixing the control

Read the specific requirement, implement the correction and update the evidence before changing the answer. Three rounds of assessor feedback are included. Remediation and customer response time are outside the commitment; there is no reset-clock, unlimited-pass or same-day-all-corrections promise.

No 400+ submission cohort, 72% first-pass rate or 15-minute pickup benchmark is established in this playbook. Those would need authentic records, a period, denominator and method. Human assessors retain decision authority.

Section 07

Renewal and Plus

Use the expiry date printed on the certificate and plan ahead. Renewal assesses the current environment and applicable questions; prior evidence can help but does not create a one-click certification. Plus requires valid matching Basic certification and a successful technical assessment; its prepared-assessment target is 2–3 working days with scheduling, access and remediation dependencies, and one formal retest within 30 days under the terms.

Section 08

Choosing the fastest suitable service

Our fastest positioning concerns the qualifying Basic commitment in the named-provider comparison. It does not establish that no other provider offers same-day work or that software alone determines speed. Compare current written terms, preparation needs and the actual deadline.

Explore our fastest Cyber Essentials service | Check readiness | Buy Micro Basic | See every size band

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group