Cyber Essentials in 7 Days, the Day-by-Day Prep Plan

Net Sec Group is an IASME and NCSC certification body. Across our 800-plus engagements we see two patterns of buyer who want a 7-day prep plan: the buyer with a tender deadline closing next week, and the buyer who has the basics in place but needs to push the work into a structured calendar to actually finish it. Both work in 7 days, but only when one specific precondition is true on day 1. This article is the calendar plan, the per-day checkpoint criteria, and the practitioner observation about the precondition.

The 7-day plan is not the same as the 12-hour fast-track engagement. The fast-track is a paid product where Net Sec Group blocks 12 working hours of assessor diary time and the engagement runs continuously. The 7-day plan is a self-led preparation calendar that compresses your work down to one working week before booking a 48-hour standard engagement at the end. Different products, different scopes, complementary purposes.

The precondition that decides the week

Before reading the day-by-day plan, confirm one thing: multi-factor authentication is already enforced on every cloud admin account on Microsoft 365, Google Workspace, AWS, Azure, or any other cloud service in scope. At CE Basic the IASME requirement is MFA enforced and verifiable on every cloud admin account; per-user MFA at the account level is acceptable evidence at this tier. Conditional Access is the requirement at CE Plus, where the assessor samples the enforcement. If MFA is in place on day 1, the 7-day plan works. If MFA still needs to be enabled, the plan does not work in 7 days; estate-wide MFA enablement runs longer than the week itself when you factor in user rollout, support tickets, and evidence capture.

This is the practitioner observation we publish on every speed-pillar piece. Enabling MFA from scratch is not a day's work in any organisation that has been running without it. It is an estate-wide configuration change with a user-impact tail. Read the why Cyber Essentials fails on the first try article if you suspect MFA is not fully in place; the 7-day plan resumes once MFA is sorted.

The 7-day plan

Each day below has one core deliverable, a list of concrete tasks, and a checkpoint criterion. The checkpoint criterion is the question you ask yourself at end of day; if you cannot answer yes, the day is not complete and tomorrow's day starts late.

Day 1, asset list complete and signed off

Core deliverable: a complete inventory of every device, server, virtual machine, hypervisor, mobile device, and cloud service in scope.

Tasks:

Checkpoint: can you say, with no caveats, "this is every in-scope asset"? If not, day 1 is not complete.

Day 2, scope boundary documented

Core deliverable: a written scope statement covering what is included, what is excluded, and the rationale for any exclusion.

Tasks:

Checkpoint: would the assessor accept your scope statement without question? Read it aloud, look for ambiguity, fix it.

Day 3, User Access Control evidence

Core deliverable: complete evidence pack for the User Access Control control.

Tasks:

Checkpoint: does the evidence pack answer every User Access Control question on the SAQ without further work?

Day 4, Secure Configuration and Malware Protection evidence

Core deliverable: complete evidence packs for Secure Configuration and Malware Protection.

Tasks:

Checkpoint: would the assessor accept this evidence pack as proof that Secure Configuration and Malware Protection are working as required?

Day 5, the 14-day patching standard evidenced

Core deliverable: evidence that critical and high-severity patches are applied within 14 days of vendor release across the in-scope estate.

Tasks:

Checkpoint: is every in-scope device inside the 14-day window for critical and high-severity patches?

Day 6, SAQ completed and double-checked

Core deliverable: every SAQ question answered with reference to the evidence captured days 1 to 5.

Tasks:

Checkpoint: would the assessor reject any answer in this SAQ on first read? If yes, fix before end of day.

Day 7, assessor review and submission

Core deliverable: assessor sign-off and IASME certificate issued.

Tasks:

Checkpoint: does the IASME register show your certificate? If yes, the week worked. If not, the engagement carries forward into the following week without restarting and without additional fees on the NetSec standard tier.

What gets the plan into trouble

Across the 7-day engagements we have observed, four issues account for the days that slip.

Asset-list reconciliation is harder than it looks when MDM, identity provider, and finance system disagree about which devices exist. The reconciliation step on day 1 is the largest variable in the week; budget for it taking a full day, not a half day.

Patch-management console gaps show up on day 5 when an applicant believed their patch-management tool covered the entire estate but in fact one team's laptops were enrolled in a different MDM that was not patched. The fix is to extend the patch-management coverage; the cost is one extra day to roll out and validate.

Cloud admin MFA gaps that the precondition check missed: a service account or break-glass account without MFA, or a backup admin account in an inactive subscription that is still administratively privileged. Day 3 evidence capture surfaces these, and the rollout-then-validate cycle to fix them rarely completes inside day 3.

Signatory availability over days 6 and 7: a signatory who is mid-flight, in surgery, or on a remote shoot pushes the certificate issue date to the following week. Day 2 confirms the signatory is available; do not skip this confirmation.

When a slip happens, do not panic. The plan continues from where it stopped, and the assessor accepts late submissions inside the standard 48-hour engagement window without penalty. The slip just means the certificate issues on day 8 or 9 rather than day 7.

When 7 days is too tight

Three signals tell you the 7-day plan is the wrong product for your estate, and the 30-day prep plan is the right one:

  1. MFA is not yet enforced on all cloud admin accounts (the precondition fails)
  2. There is an end-of-life operating system in scope that needs upgrading or excluding (this is structural, not a one-week fix)
  3. The patch-management console reveals a meaningful patching backlog (multiple in-scope devices outside the 14-day window, or a category of devices not covered by the patch tool at all); the remediation cycle alone runs longer than 7 days

Booking the 30-day plan when one of these signals is true is cheaper, calmer, and produces a stronger evidence pack on first attempt. The same applicants tend to be the ones who renew on time, because the structural fixes from the 30-day plan stay fixed if MFA and patching discipline carry forward.

Common questions

What if I slip on day 5 because patching takes longer than expected?

Push the SAQ submission day from day 7 to day 9 or 10. The 48-hour assessor engagement is booked once the SAQ is ready; there is no pressure to submit early. The assessor sees a clean SAQ on day 9 the same as a clean SAQ on day 7.

Can I run the 7-day plan and book the 12-hour fast-track tier?

Yes, and we see this combination often. The 7-day plan completes the preparation; the 12-hour fast-track engagement is the certification on day 8 or 9. Total elapsed time: 8 to 9 days, with the fast-track price for the engagement and your own time for the preparation.

Is the 7-day plan suitable for a microbusiness with no IT team?

The plan works in proportion to the estate. A 5-person microbusiness on Microsoft 365 with 5 laptops and no servers can compress days 1 to 5 into 2 to 3 days because there is less to inventory and less to evidence. See the Cyber Essentials microbusiness scope article for the proportionality guidance.

What happens if the SAQ comes back from the assessor with corrections?

You apply the corrections and resubmit. Corrections are normal; rejections are not. The standard 48-hour engagement assumes one correction cycle is included; multiple cycles do not incur extra fees on the NetSec standard tier.

Where do we book?

Once the 7-day plan completes, book a Cyber Essentials assessment with Net Sec Group. The booking form lets you nominate the SAQ-ready date, and the assessor schedules the 48-hour engagement to start that day.

Reference material

For broader Net Sec Group references on Cyber Essentials preparation:

Where this fits on this site

The 7-day plan is the middle path on the speed pillar. The faster path is the 12-hour fast-track engagement, for applicants who arrive ready. The slower path is the 30-day prep plan, for applicants with structural gaps to close. All three paths end at the same IASME certificate. The timelines hub indexes the three paths in one place with the picker decision matrix.

Book your Cyber Essentials assessment with Net Sec Group when the 7 days complete and the SAQ is ready.