Cyber Essentials in 30 Days, the Week-by-Week Founder Plan

Net Sec Group is an IASME and NCSC certification body. We have delivered more than 800 Cyber Essentials and Cyber Essentials Plus engagements, and the most common preparation runway we see is four weeks. The 30-day plan is the right product for a UK founder or operations lead whose company has Microsoft 365 or Google Workspace, a fleet of laptops, and the kind of casual security posture that sufficed before a tender or contract turned certification into a deadline. This article is the week-by-week founder plan, the cost markers per week, and the practitioner observation about the week that slips most often.

The 30-day plan complements two other speed paths on this site. The 12-hour fast-track engagement is for applicants who arrive ready. The 7-day prep plan is the middle path for applicants with the basics in place. The 30-day plan is the path that allows enough room to fix structural gaps without panic. The timelines hub indexes all three with a decision matrix.

This is the founder-facing version of the plan. For the operations team, the deeper technical playbook lives at Net Sec Group's 30-day preparation plan, which goes into the per-control test depth this article does not.

What 30 days assumes about your starting position

The 30-day plan assumes a starting baseline of: you have laptops and Office 365 or Google Workspace, you have informal admin practices, and you have not yet run any of the five Cyber Essentials controls through a structured assessment. If MFA is not yet on every cloud admin account, that is normal at this starting point and the plan accommodates the rollout. If you have an end-of-life Windows server still in production, the plan accommodates the upgrade or scoping decision.

The plan does not assume you have a CISO, a compliance manager, or an IT team. The signatory is the founder or a board-level officer; the operations work is done by whoever runs IT day to day, including external IT support if that is your model.

The 30-day plan, week by week

Week 1: scope and asset list

Goal: have a written scope and a complete asset list by end of week.

Tasks:

Cost marker: time only, no software purchases this week. Two to four founder hours plus operations support.

Checkpoint: would the assessor accept the scope and asset list as definitive? Read both aloud, fix ambiguity.

Week 2: control gaps and purchase decisions

Goal: identify which of the five Cyber Essentials controls have gaps, decide what tooling needs purchasing, and place the orders.

Tasks:

Cost marker: this is typically the only paid week. Founder cost band starts here. Microsoft 365 Business Premium for MFA and MDM, business antivirus subscription where Defender is not enough, a patch-management tool if your current setup does not cover the estate. Total is firm-specific; a 5-user firm on Microsoft 365 Business Premium (currently £18.10 per user per month list price) lands under £1,100 of recurring annual licence cost, scaling linearly above that on seat count. A 15-user firm on the same path is around £3,260 annual; a 30-user firm around £6,520. Patch-management tooling is on top of that and varies widely between included-in-contract (where a managed service provider already covers it under your existing IT contract) and standalone (a per-device monthly fee on top). The right framing for the founder: this is a one-week purchase decision in week 2, not a recurring sticker shock through the rest of the plan.

Checkpoint: do you have a written remediation plan, and have you ordered every tool that plan needs?

Week 3: evidence collection and the 14-day patching window

Goal: capture evidence for every control, and have the 14-day patching standard demonstrably in place.

Tasks:

Cost marker: time and operations work; no new purchases unless week 2 missed something. The remediation work itself is the largest variable in the month.

Checkpoint: does the evidence pack for each of the five controls answer every relevant SAQ question without further work?

Week 4: SAQ submission and assessor review

Goal: submit the IASME SAQ, complete the assessor review cycle, receive the certificate.

Tasks:

Cost marker: the engagement fee on the standard 48-hour tier is the second cost band in the month. See the pricing page for current Net Sec Group fees.

Checkpoint: does the IASME register show your certificate by end of day 30?

The week that slips most often

Week 3 slips more than weeks 1, 2, or 4. The pattern is consistent across our 800-plus engagement history.

The slip happens because the 14-day patching window is mid-flight when someone notices an unsupported operating system that has to be replaced or scoped out. End-of-life Windows on a finance server, end-of-life macOS on a designer's laptop, an Android phone on a vendor-discontinued OEM build with corporate mailbox access, an old NAS running an unsupported Linux distribution. Any one of these is a structural gap that does not patch its way out; it requires a hardware refresh, an OS upgrade, or a scoping decision.

When week 3 slips, the right move is to acknowledge it on day 16 or 17 (the earlier the better), shift the SAQ submission from day 22 to day 25 or later, and use the bought time for the structural fix. The 30-day plan has more cushion than the 7-day plan precisely because of this; do not panic, do not try to compress week 4 to compensate. The assessor accepts a clean SAQ on day 31 the same as a clean SAQ on day 30.

The decision triage on day 16 or 17 is straightforward. The unsupported asset gets one of three outcomes. Scope it out: the asset is non-critical, it can be removed from in-scope networks for the assessment, and the operational impact is acceptable; document the exclusion in the scope statement and proceed. Replace it: the asset is in-scope-critical, the upgrade or hardware refresh has a defined supplier and a known lead time, and the lead time fits inside the day 16 to day 28 window; place the order and treat the asset as in-scope on the new build. Accept the slip: neither path works inside the original 30-day calendar; shift the SAQ submission to day 35 or later, accept the engagement runs at 5 to 6 weeks total, and use the bought time properly rather than half-resolving the gap. The third outcome is the most common one when an applicant discovers an end-of-life server in week 3 and the replacement lead time is 4 to 6 weeks. The plan stretches; the certificate quality stays.

What 30 days does not buy you

The 30-day plan delivers a passing CE Basic certificate. It does not deliver:

For the longer-term operational picture, see why Cyber Essentials fails on the first try and the broader Net Sec Group reference at Cyber Essentials Common Failures Guide.

Common questions

What if my company is too small for the 30-day plan?

A microbusiness with 5 laptops and no servers can complete the plan in 7 to 14 days because there is less to inventory and less to evidence. See the Cyber Essentials microbusiness scope article for the proportionality guidance, then run a compressed version of weeks 1 to 4.

What if my company is too large for the 30-day plan?

Estates with hundreds of devices, multiple offices, or complex cloud architectures can run the same week-by-week structure but with the work parallelised across an internal team. The plan still works; the bottleneck shifts from clock time to coordination time. The 800-plus engagement history includes companies of every size; the plan structure stays the same, the per-task time stretches.

Can I run the 30-day plan and book the 12-hour fast-track tier at the end?

Yes. The 30-day plan completes the preparation; the 12-hour fast-track engagement is the certification on day 31. Total elapsed: 31 days, founder cost = 30-day prep work plus the fast-track tier price.

What if I miss a tool order in week 2 and it does not arrive until week 3?

This is the most common week 2 to 3 slip. The plan accommodates it by treating tool delivery as a precondition for week 3 work; if the tool arrives mid-week 3, the evidence-collection tasks for that tool shift to the back of week 3 or into week 4. The SAQ submission day is the variable, not the engagement quality.

Where do we book?

Book your Cyber Essentials assessment with Net Sec Group when the SAQ is ready in week 4. The booking form lets you nominate the SAQ-ready date, and the assessor schedules the 48-hour engagement to start that day.

Reference material

For the deeper technical operations playbook (per-control test depth, edge cases, evidence formats), see:

Where this fits on this site

The 30-day plan is the longest path on the speed pillar. The faster paths are the 7-day prep plan and the 12-hour fast-track engagement. All three end at the same IASME certificate. The timelines hub indexes all three.

The 30-day plan ends at a booking. Book a Cyber Essentials assessment with Net Sec Group when the SAQ is ready in week 4, and the 48-hour engagement starts the day you nominate.