Cyber Essentials Renewal: What You Need to Know
Your certificate expires 12 months after issue. This guide explains the renewal process, what changed when the Danzell question set went live on 27 April 2026, and how to switch assessor without losing momentum.
Why renewal matters more than you think
A Cyber Essentials certificate is not a one-time achievement – it is an annual assertion that your security posture still meets NCSC's baseline. Three things stop being true the moment your certificate lapses.
You disappear from the IASME register. Procurement teams, insurers and customer due-diligence checks read directly from the public IASME database. Your name being missing is treated as not-certified, even if you are mid-renewal.
Your £25,000 cyber liability insurance switches off if you were eligible for it. The IASME-bundled cover is contingent on a live certificate. There is no grace period.
Contract eligibility evaporates. Government frameworks, NHS supply contracts and most enterprise supplier programmes require certification to be current, not historical.
When to start your renewal
Begin 6–8 weeks before your expiry date.
That gives you time to review changes in the IASME question set, refresh evidence, address any drift in your environment, and submit comfortably before the deadline. Last-minute renewals are the single most common reason certifications lapse.
The six evidence areas to refresh every year
The IASME question set typically changes modestly each year, but your environment changes more than you think. These are the six areas to walk through annually.
Asset inventory
Confirm new starters, leavers, replaced devices and any new cloud services adopted in the last 12 months are accounted for.
Operating systems
Verify every device is running a vendor-supported version. Windows 10 ESU status, macOS major version and mobile OS minimums all matter.
Cloud account MFA
Re-confirm MFA is enforced on every cloud admin and user account – including for contractors and shared mailboxes.
Patching evidence
Refresh screenshots of update settings and any patch management dashboards. The 14-day patching rule for high/critical updates is now strictly enforced.
Password policy
Update your written policy if NCSC guidance has shifted. Re-check that minimum length and breached-password screening are in place on cloud services.
BYOD scope
Re-document any personal devices used for work email or business apps. The Danzell question set is more explicit about BYOD scope boundaries.
What changed in the April 2026 IASME update
IASME publishes a refreshed question set each April. The Danzell update, in force since 27 April 2026, is incremental rather than revolutionary, but three areas have moved from "encouraged" to "expected" in assessor reviews:
- Cloud admin MFA – must be enforced, not just available, on every cloud platform with admin access (Microsoft 365, Google Workspace, AWS, Azure).
- 14-day patching for internet-facing services – the window for high/critical CVEs has been tightened, with explicit evidence expected.
- Asset inventory completeness – assessors now ask for a documented method, not just a spreadsheet snapshot.
Switching assessor at renewal
Renewal is the natural moment to review whether your existing Certification Body is still the best fit. There is no penalty, no lock-in and no continuity disadvantage to moving – IASME runs the public register, so your certificate history is preserved there regardless of which Certification Body issues your next certificate.
Clients typically move to NixInfinity-AI for one of three reasons:
- They want a more hands-on, advisory relationship rather than a portal-only service.
- They are ready to step up from Cyber Essentials to CE Plus or IASME Cyber Assurance and want a single partner across both.
- They want a fixed price with the £25,000 cyber insurance benefit confirmed in writing where they are eligible.
We import your previous evidence at no extra charge so you don't start the renewal from a blank page.
Renewal pricing
The IASME certification fee is identical for renewals and new applications, set by organisation size. NixInfinity-AI applies a reduced preparation rate for renewal clients because the heavy-lift scoping work has already been done.
See our full pricing guide for the IASME fee by organisation size, or request a tailored renewal quote below.
Frequently Asked Questions
Renew before your certificate lapses
Reduced renewal pricing. £25,000 cyber insurance kept active for eligible organisations. We import your previous evidence.
Get my renewal quote