Skip to content
Compliance

What happens if your Cyber Essentials certificate lapses

An expired Cyber Essentials certificate is historical evidence, not current certification. Check renewal timing and the actual buyer or contract consequences.

clear glass hour glass with black liquid

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

What happens if your Cyber Essentials certificate lapses

Cyber Essentials certification lasts 12 months. Check the expiry shown on your certificate and complete renewal before that date if continuous certification is required. Once expired, the old certificate is historical evidence, not current certification; there is no general scheme grace period that makes it current.

This guide covers what actually happens when a certificate lapses, how to recover fast, and how to set up a renewal cadence that does not miss the window.

Section 02

What happens on the lapse date

After the expiry shown on the certificate, keep three things separate:

1. Current certification has ended. A buyer should check the certificate dates, legal entity and scope. The IASME Certificate Search describes certificates issued in the last 12 months; the separate Supplier Check FAQ says recently expired records can remain visible. Visibility in a tool does not renew a certificate.

2. Your contract may require action. If it requires continuous current certification, follow its notice, cure and evidence terms. Current PPN 014 requires annual renewal when Cyber Essentials is specified for an in-scope procurement; it does not grant every supplier a standard post-expiry cure period.

3. The old certificate remains historical evidence. Its dates and scope can document what was certified previously, but it cannot satisfy a requirement for a current certificate.

Section 03

Who finds out (and when)

Two groups care about the lapse:

Customers doing due diligence. A customer may check your certificate at onboarding, renewal or during the contract. Tell the relevant customer if its agreement requires notice, and follow the actual response provisions. Do not assume a fixed checking frequency or automatic stop-work result.

Procurement frameworks. Evidence rules depend on the framework and call-off contract. For a current public procurement, read the tender, applicable note and buyer decision. PPN 014 requires relevant, proportionate controls and allows equivalent evidence; an exceptional buyer risk decision is not a general permission to continue presenting an expired certificate as current.

Section 04

The re-certification process

For renewal, complete a fresh self-assessment against the applicable scheme version and current scope, then submit it for independent review. Confirm the current question set and evidence requirements with your certification body; do not assume a prior submission still covers new services, devices or people.

An organisation with maintained controls may have less preparation to do, but the time depends on its actual scope and findings. Fig Group's published Basic assessment guarantee is six working hours for a complete, compliant submission received before midday UK time on a UK Business Day, subject to certification terms. It does not include remediation or a Plus audit.

Section 05

The cost of lapse

Three costs to consider:

1. The re-certification fee. Check your organisation-size tier and accepted order. Fig Group's published Basic prices are £299.99-£549.99 + VAT by tier; current prices show the applicable offer. Do not infer a different fee or penalty from an expired certificate alone.

2. The gap in certification. A new certificate does not make the preceding gap disappear. Tell customers where notice is required, and agree any remediation or alternative evidence under their actual terms. There is no reliable general "30-day acceptance" rule.

3. The contract risk. Read the signed agreement, tender and framework conditions. PPN 014 calls for annual renewal where Cyber Essentials is specified and evidence before data is passed to a supplier; any exceptional decision or cure period belongs to the buyer's documented risk process, not a blanket scheme grace period.

Section 06

v3.3 re-certification in 2026

For a new assessment registered from 27 April 2026, use the current v3.3 requirements and Danzell question set. If your last assessment used v3.2 or earlier, review the changes before renewal:

  • Cloud MFA wherever available, including paid options, for in-scope cloud services. IASME describes failure to implement it as an automatic assessment failure under the April 2026 rules. Read the update.
  • Clarified BYOD and home-router scope: include work devices and cloud services according to their actual access; a router provided to a worker by the organisation is in scope, while other home routers are excluded.
  • Explicit cloud service obligations - IaaS, PaaS, SaaS configurations must be documented.

Do not assume the prior submission will pass as-is. Re-read the current requirements before re-submitting.

Section 07

The renewal cadence that works

Renewal can be missed when ownership and dates are unclear. Put an accountable owner and expiry reminder in a shared system.

Do not rely solely on reminder emails from any provider; use the date shown on your own certificate and your contract's evidence deadline.

A good cadence:

  • 60 days before expiry: book the renewal slot. Start reviewing the current questionnaire against v3.3.
  • 30 days before expiry: run the readiness checker against the current requirements.
  • Well before expiry: submit a complete assessment, leaving time for clarification or remediation. An eligible Basic submission has the six-working-hour assessment guarantee, but submission alone is not certification.
  • On issue: record the new certificate dates, entity and scope, and provide evidence to buyers who require it.

Plan a buffer based on your actual estate, assessor availability, buyer deadline and contract. A fixed 14-day plan may be too short if controls need work.

Section 08

If you have already lapsed

If you are reading this because your certificate lapsed yesterday or last week:

1. Check the affected obligations. Tell customers where notice is required, and agree next steps under the actual contract.

2. Complete and submit a current assessment. The eligible Basic assessment clock begins only after Fig Group receives a complete, compliant submission before midday UK time on a UK Business Day; remediation and Plus are separate.

3. Log the lapse internally. Record the date range of the gap and the reason. Future DDQs may ask about continuity.

4. Fix the calendar. Put the next renewal into a shared cadence, not a personal calendar.

Section 09

Plan your renewal

An expired certificate is historical evidence, not current certification. Its impact on a buyer relationship depends on the actual contract, and public-search visibility varies by tool. Check the expiry, renew against current requirements and give buyers accurate evidence.

Do not let the certificate lapse in the first place. If you are close to expiry now, book the renewal today.

Start a Cyber Essentials renewal | See current tier prices | Speak to our team

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group