Case Study
Case Study: Cyber Essentials in 24 Hours for a Tender Deadline
Published 30 April 2026
The brief
A management consultancy bidding on a £180k Government Commercial Agency framework. The PQQ required a current Cyber Essentials certificate, verifiable on the IASME register. They had no certificate and had assumed it would take weeks.
The starting position
- 12 staff, all on Microsoft 365 (Business Premium)
- Conditional Access deployed but MFA not enforced on all users
- Two staff using personal iPhones for work email without account-level MFA
- Patches managed by their MSP – good evidence available
- No legacy authentication audit had been done
What we did
- 30-minute readiness call at 4:15pm Monday. Confirmed fast-track was viable if MFA could be enforced overnight.
- MFA enforcement – their MSP rolled out a Conditional Access policy enforcing MFA on all users by 9am Tuesday.
- Legacy authentication blocked – disabled SMTP AUTH, IMAP and POP at the tenant level.
- SAQ completed together over a 90-minute call from 9:30am Tuesday.
- Pre-submission review at 11:30am – flagged one wording issue on BYOD scope, fixed in 10 minutes.
- Submission and issue – submitted via the IASME portal at 12:15pm. We reviewed and issued the certificate at 2:00pm Tuesday.
The outcome
- Certificate issued 22 hours after first contact
- Bid submitted 3 hours before deadline
- Bid won, contract value £180k
- Total cost: £320 + VAT (no rush surcharge)
- Client now retained for annual renewals and CE Plus next year
Lessons
Fast-track is achievable when the underlying tech stack is healthy. The fixes here were small – extending MFA enforcement and disabling legacy auth. Without an IASME-licensed Certification Body in the loop, the same submission would have sat in a review queue for 3–5 days.
Need the same? See our urgent tender service.
