Cyber Essentials in 30 Days, the Week-by-Week Founder Plan
Net Sec Group is an IASME and NCSC certification body. We have delivered more than 800 Cyber Essentials and Cyber Essentials Plus engagements, and the most common preparation runway we see is four weeks. The 30-day plan is the right product for a UK founder or operations lead whose company has Microsoft 365 or Google Workspace, a fleet of laptops, and the kind of casual security posture that sufficed before a tender or contract turned certification into a deadline. This article is the week-by-week founder plan, the cost markers per week, and the practitioner observation about the week that slips most often.
The 30-day plan complements two other speed paths on this site. The 12-hour fast-track engagement is for applicants who arrive ready. The 7-day prep plan is the middle path for applicants with the basics in place. The 30-day plan is the path that allows enough room to fix structural gaps without panic. The timelines hub indexes all three with a decision matrix.
This is the founder-facing version of the plan. For the operations team, the deeper technical playbook lives at Net Sec Group's 30-day preparation plan, which goes into the per-control test depth this article does not.
What 30 days assumes about your starting position
The 30-day plan assumes a starting baseline of: you have laptops and Office 365 or Google Workspace, you have informal admin practices, and you have not yet run any of the five Cyber Essentials controls through a structured assessment. If MFA is not yet on every cloud admin account, that is normal at this starting point and the plan accommodates the rollout. If you have an end-of-life Windows server still in production, the plan accommodates the upgrade or scoping decision.
The plan does not assume you have a CISO, a compliance manager, or an IT team. The signatory is the founder or a board-level officer; the operations work is done by whoever runs IT day to day, including external IT support if that is your model.
The 30-day plan, week by week
Week 1: scope and asset list
Goal: have a written scope and a complete asset list by end of week.
Tasks:
- Decide whether to certify the whole organisation or a defined subsidiary
- Pull the device list from your MDM, identity provider, and finance system
- Reconcile the three sources into a single master inventory
- Document any out-of-scope networks, branches, or business units, with the rationale for each exclusion
- Confirm the named signatory (founder or board-level officer) and their availability for week 4
Cost marker: time only, no software purchases this week. Two to four founder hours plus operations support.
Checkpoint: would the assessor accept the scope and asset list as definitive? Read both aloud, fix ambiguity.
Week 2: control gaps and purchase decisions
Goal: identify which of the five Cyber Essentials controls have gaps, decide what tooling needs purchasing, and place the orders.
Tasks:
- Run a self-assessment against the five controls (boundary firewalls, secure configuration, user access control, malware protection, security update management) using the CE Self-Assessment Tool
- For each gap, decide between configuration fix (no purchase needed), tool purchase (MDM, business antivirus, password manager, patch-management tool), or scope reduction (remove the asset that fails)
- Place orders for any tooling needed, factoring lead time for licence provisioning
- Begin MFA rollout planning if MFA is not yet enforced on all cloud admin accounts; this is the single most common purchase-and-rollout decision in week 2
Cost marker: this is typically the only paid week. Founder cost band starts here. Microsoft 365 Business Premium for MFA and MDM, business antivirus subscription where Defender is not enough, a patch-management tool if your current setup does not cover the estate. Total is firm-specific; a 5-user firm on Microsoft 365 Business Premium (currently £18.10 per user per month list price) lands under £1,100 of recurring annual licence cost, scaling linearly above that on seat count. A 15-user firm on the same path is around £3,260 annual; a 30-user firm around £6,520. Patch-management tooling is on top of that and varies widely between included-in-contract (where a managed service provider already covers it under your existing IT contract) and standalone (a per-device monthly fee on top). The right framing for the founder: this is a one-week purchase decision in week 2, not a recurring sticker shock through the rest of the plan.
Checkpoint: do you have a written remediation plan, and have you ordered every tool that plan needs?
Week 3: evidence collection and the 14-day patching window
Goal: capture evidence for every control, and have the 14-day patching standard demonstrably in place.
Tasks:
- Capture the user access control evidence (admin separation, MFA enforcement, leaver-process record, joiner-process record, access-review cadence)
- Capture the secure configuration evidence (standard build per OS, firewall state, default-account state, password policy)
- Capture the malware protection evidence (endpoint state, console screenshots)
- Run the patch-management console report; identify and apply any outstanding critical and high-severity patches; ensure the 14-day standard is verifiably in place
- Document the patch cycle in writing (frequency, coverage, exception handling)
Cost marker: time and operations work; no new purchases unless week 2 missed something. The remediation work itself is the largest variable in the month.
Checkpoint: does the evidence pack for each of the five controls answer every relevant SAQ question without further work?
Week 4: SAQ submission and assessor review
Goal: submit the IASME SAQ, complete the assessor review cycle, receive the certificate.
Tasks:
- Day 22 to 24: open the SAQ, work through every question, attach evidence captured in week 3
- Day 25: self-review every answer for ambiguity, missing context, or claims unsupported by evidence; tighten weak answers
- Day 26: book the standard 48-hour engagement with Net Sec Group at the published price
- Day 27 to 28: assessor reviews, asks corrections, you tighten and resubmit
- Day 29 to 30: certificate issues, IASME register entry appears
Cost marker: the engagement fee on the standard 48-hour tier is the second cost band in the month. See the pricing page for current Net Sec Group fees.
Checkpoint: does the IASME register show your certificate by end of day 30?
The week that slips most often
Week 3 slips more than weeks 1, 2, or 4. The pattern is consistent across our 800-plus engagement history.
The slip happens because the 14-day patching window is mid-flight when someone notices an unsupported operating system that has to be replaced or scoped out. End-of-life Windows on a finance server, end-of-life macOS on a designer's laptop, an Android phone on a vendor-discontinued OEM build with corporate mailbox access, an old NAS running an unsupported Linux distribution. Any one of these is a structural gap that does not patch its way out; it requires a hardware refresh, an OS upgrade, or a scoping decision.
When week 3 slips, the right move is to acknowledge it on day 16 or 17 (the earlier the better), shift the SAQ submission from day 22 to day 25 or later, and use the bought time for the structural fix. The 30-day plan has more cushion than the 7-day plan precisely because of this; do not panic, do not try to compress week 4 to compensate. The assessor accepts a clean SAQ on day 31 the same as a clean SAQ on day 30.
The decision triage on day 16 or 17 is straightforward. The unsupported asset gets one of three outcomes. Scope it out: the asset is non-critical, it can be removed from in-scope networks for the assessment, and the operational impact is acceptable; document the exclusion in the scope statement and proceed. Replace it: the asset is in-scope-critical, the upgrade or hardware refresh has a defined supplier and a known lead time, and the lead time fits inside the day 16 to day 28 window; place the order and treat the asset as in-scope on the new build. Accept the slip: neither path works inside the original 30-day calendar; shift the SAQ submission to day 35 or later, accept the engagement runs at 5 to 6 weeks total, and use the bought time properly rather than half-resolving the gap. The third outcome is the most common one when an applicant discovers an end-of-life server in week 3 and the replacement lead time is 4 to 6 weeks. The plan stretches; the certificate quality stays.
What 30 days does not buy you
The 30-day plan delivers a passing CE Basic certificate. It does not deliver:
- A clean transition to CE Plus on the same calendar; CE Plus runs 3 to 5 working days end-to-end on top of CE Basic, with 1 to 2 days of pre-assessment readiness (estate scan and vulnerability remediation) before the 4 to 6 hour assessment day
- A long-term security culture; the certificate documents the controls in place at a point in time, the controls then need maintaining
- An ISO 27001 evidence pack; CE Basic and ISO 27001 share material but the ISO scope is far broader and runs months not weeks. See Cyber Essentials versus ISO 27001 cost and time for the comparison
For the longer-term operational picture, see why Cyber Essentials fails on the first try and the broader Net Sec Group reference at Cyber Essentials Common Failures Guide.
Common questions
What if my company is too small for the 30-day plan?
A microbusiness with 5 laptops and no servers can complete the plan in 7 to 14 days because there is less to inventory and less to evidence. See the Cyber Essentials microbusiness scope article for the proportionality guidance, then run a compressed version of weeks 1 to 4.
What if my company is too large for the 30-day plan?
Estates with hundreds of devices, multiple offices, or complex cloud architectures can run the same week-by-week structure but with the work parallelised across an internal team. The plan still works; the bottleneck shifts from clock time to coordination time. The 800-plus engagement history includes companies of every size; the plan structure stays the same, the per-task time stretches.
Can I run the 30-day plan and book the 12-hour fast-track tier at the end?
Yes. The 30-day plan completes the preparation; the 12-hour fast-track engagement is the certification on day 31. Total elapsed: 31 days, founder cost = 30-day prep work plus the fast-track tier price.
What if I miss a tool order in week 2 and it does not arrive until week 3?
This is the most common week 2 to 3 slip. The plan accommodates it by treating tool delivery as a precondition for week 3 work; if the tool arrives mid-week 3, the evidence-collection tasks for that tool shift to the back of week 3 or into week 4. The SAQ submission day is the variable, not the engagement quality.
Where do we book?
Book your Cyber Essentials assessment with Net Sec Group when the SAQ is ready in week 4. The booking form lets you nominate the SAQ-ready date, and the assessor schedules the 48-hour engagement to start that day.
Reference material
For the deeper technical operations playbook (per-control test depth, edge cases, evidence formats), see:
- Cyber Essentials 30-day Preparation Plan (the netsecgroup.io technical playbook)
- Cyber Essentials 14-day Patching Guide
- Cyber Essentials Certification Guide
- Cyber Essentials Common Failures Guide
- CE Self-Assessment Tool
Where this fits on this site
The 30-day plan is the longest path on the speed pillar. The faster paths are the 7-day prep plan and the 12-hour fast-track engagement. All three end at the same IASME certificate. The timelines hub indexes all three.
The 30-day plan ends at a booking. Book a Cyber Essentials assessment with Net Sec Group when the SAQ is ready in week 4, and the 48-hour engagement starts the day you nominate.