Cyber Essentials in 7 Days, the Day-by-Day Prep Plan
Net Sec Group is an IASME and NCSC certification body. Across our 800-plus engagements we see two patterns of buyer who want a 7-day prep plan: the buyer with a tender deadline closing next week, and the buyer who has the basics in place but needs to push the work into a structured calendar to actually finish it. Both work in 7 days, but only when one specific precondition is true on day 1. This article is the calendar plan, the per-day checkpoint criteria, and the practitioner observation about the precondition.
The 7-day plan is not the same as the 12-hour fast-track engagement. The fast-track is a paid product where Net Sec Group blocks 12 working hours of assessor diary time and the engagement runs continuously. The 7-day plan is a self-led preparation calendar that compresses your work down to one working week before booking a 48-hour standard engagement at the end. Different products, different scopes, complementary purposes.
The precondition that decides the week
Before reading the day-by-day plan, confirm one thing: multi-factor authentication is already enforced on every cloud admin account on Microsoft 365, Google Workspace, AWS, Azure, or any other cloud service in scope. At CE Basic the IASME requirement is MFA enforced and verifiable on every cloud admin account; per-user MFA at the account level is acceptable evidence at this tier. Conditional Access is the requirement at CE Plus, where the assessor samples the enforcement. If MFA is in place on day 1, the 7-day plan works. If MFA still needs to be enabled, the plan does not work in 7 days; estate-wide MFA enablement runs longer than the week itself when you factor in user rollout, support tickets, and evidence capture.
This is the practitioner observation we publish on every speed-pillar piece. Enabling MFA from scratch is not a day's work in any organisation that has been running without it. It is an estate-wide configuration change with a user-impact tail. Read the why Cyber Essentials fails on the first try article if you suspect MFA is not fully in place; the 7-day plan resumes once MFA is sorted.
The 7-day plan
Each day below has one core deliverable, a list of concrete tasks, and a checkpoint criterion. The checkpoint criterion is the question you ask yourself at end of day; if you cannot answer yes, the day is not complete and tomorrow's day starts late.
Day 1, asset list complete and signed off
Core deliverable: a complete inventory of every device, server, virtual machine, hypervisor, mobile device, and cloud service in scope.
Tasks:
- Pull the device list from your MDM, your Microsoft Intune or Google Endpoint Management or Jamf console
- Pull the user list from your identity provider
- Pull the cloud-services list from your finance system (anything with a recurring subscription is in scope unless documented otherwise)
- Reconcile the three lists into one master inventory
- Flag any device or service whose ownership is unclear and resolve those flags before end of day
Checkpoint: can you say, with no caveats, "this is every in-scope asset"? If not, day 1 is not complete.
Day 2, scope boundary documented
Core deliverable: a written scope statement covering what is included, what is excluded, and the rationale for any exclusion.
Tasks:
- Decide whether to certify the whole organisation or a defined subsidiary or business unit
- Document any out-of-scope networks, branches, or legal entities, and explain why each is excluded
- Confirm that out-of-scope networks have no logical path into the in-scope estate (firewall rule check, no shared admin accounts, no flat-network adjacency)
- Confirm the named signatory and their availability over days 6 and 7
Checkpoint: would the assessor accept your scope statement without question? Read it aloud, look for ambiguity, fix it.
Day 3, User Access Control evidence
Core deliverable: complete evidence pack for the User Access Control control.
Tasks:
- Export the administrator account list from every cloud service in scope
- Confirm MFA enforcement on every administrator account (this is the precondition; today's task is evidence capture, not enablement)
- Document the leaver process, including a worked example of a leaver who has been processed in the last 90 days
- Document the joiner process and the access-review cadence
- Capture screenshots of the admin separation (admin work happens in dedicated admin accounts, not day-to-day user accounts)
Checkpoint: does the evidence pack answer every User Access Control question on the SAQ without further work?
Day 4, Secure Configuration and Malware Protection evidence
Core deliverable: complete evidence packs for Secure Configuration and Malware Protection.
Tasks:
- Capture the standard build for each operating system in scope (Windows 11 24H2 Pro, macOS 15, Ubuntu 24.04 LTS, etc.) including default-account state, firewall state, and disabled services
- Capture screenshots of the Malware Protection state on a sample device per build (Defender, ESET, Sophos, Bitdefender, whichever is deployed)
- Document any application allow-list or sandboxing configuration if you use one
- Capture the password policy from the identity provider and confirm it meets the IASME minimum
Checkpoint: would the assessor accept this evidence pack as proof that Secure Configuration and Malware Protection are working as required?
Day 5, the 14-day patching standard evidenced
Core deliverable: evidence that critical and high-severity patches are applied within 14 days of vendor release across the in-scope estate.
Tasks:
- Export the patch-management console report covering the last 60 days
- Identify any in-scope device with an outstanding critical or high-severity patch older than 14 days
- Apply the missing patches today
- Re-run the patch-management report and capture the post-remediation screenshot
- Document the patch cycle (frequency, coverage, exception handling) in writing
Checkpoint: is every in-scope device inside the 14-day window for critical and high-severity patches?
Day 6, SAQ completed and double-checked
Core deliverable: every SAQ question answered with reference to the evidence captured days 1 to 5.
Tasks:
- Open the IASME SAQ and work through every question
- For each answer, attach or reference the specific evidence file from days 1 to 5
- Self-review every answer for ambiguity, missing context, or claims unsupported by evidence
- Tighten weak answers; replace screenshots with configuration exports where the brief calls for it
- Save the SAQ in draft state, do not submit yet
Checkpoint: would the assessor reject any answer in this SAQ on first read? If yes, fix before end of day.
Day 7, assessor review and submission
Core deliverable: assessor sign-off and IASME certificate issued.
Tasks:
- Submit the SAQ to the assessor
- Stand by for assessor questions and respond within working hours
- Apply any tightening the assessor flags
- Re-submit if needed
- Receive the certificate and the IASME register entry
Checkpoint: does the IASME register show your certificate? If yes, the week worked. If not, the engagement carries forward into the following week without restarting and without additional fees on the NetSec standard tier.
What gets the plan into trouble
Across the 7-day engagements we have observed, four issues account for the days that slip.
Asset-list reconciliation is harder than it looks when MDM, identity provider, and finance system disagree about which devices exist. The reconciliation step on day 1 is the largest variable in the week; budget for it taking a full day, not a half day.
Patch-management console gaps show up on day 5 when an applicant believed their patch-management tool covered the entire estate but in fact one team's laptops were enrolled in a different MDM that was not patched. The fix is to extend the patch-management coverage; the cost is one extra day to roll out and validate.
Cloud admin MFA gaps that the precondition check missed: a service account or break-glass account without MFA, or a backup admin account in an inactive subscription that is still administratively privileged. Day 3 evidence capture surfaces these, and the rollout-then-validate cycle to fix them rarely completes inside day 3.
Signatory availability over days 6 and 7: a signatory who is mid-flight, in surgery, or on a remote shoot pushes the certificate issue date to the following week. Day 2 confirms the signatory is available; do not skip this confirmation.
When a slip happens, do not panic. The plan continues from where it stopped, and the assessor accepts late submissions inside the standard 48-hour engagement window without penalty. The slip just means the certificate issues on day 8 or 9 rather than day 7.
When 7 days is too tight
Three signals tell you the 7-day plan is the wrong product for your estate, and the 30-day prep plan is the right one:
- MFA is not yet enforced on all cloud admin accounts (the precondition fails)
- There is an end-of-life operating system in scope that needs upgrading or excluding (this is structural, not a one-week fix)
- The patch-management console reveals a meaningful patching backlog (multiple in-scope devices outside the 14-day window, or a category of devices not covered by the patch tool at all); the remediation cycle alone runs longer than 7 days
Booking the 30-day plan when one of these signals is true is cheaper, calmer, and produces a stronger evidence pack on first attempt. The same applicants tend to be the ones who renew on time, because the structural fixes from the 30-day plan stay fixed if MFA and patching discipline carry forward.
Common questions
What if I slip on day 5 because patching takes longer than expected?
Push the SAQ submission day from day 7 to day 9 or 10. The 48-hour assessor engagement is booked once the SAQ is ready; there is no pressure to submit early. The assessor sees a clean SAQ on day 9 the same as a clean SAQ on day 7.
Can I run the 7-day plan and book the 12-hour fast-track tier?
Yes, and we see this combination often. The 7-day plan completes the preparation; the 12-hour fast-track engagement is the certification on day 8 or 9. Total elapsed time: 8 to 9 days, with the fast-track price for the engagement and your own time for the preparation.
Is the 7-day plan suitable for a microbusiness with no IT team?
The plan works in proportion to the estate. A 5-person microbusiness on Microsoft 365 with 5 laptops and no servers can compress days 1 to 5 into 2 to 3 days because there is less to inventory and less to evidence. See the Cyber Essentials microbusiness scope article for the proportionality guidance.
What happens if the SAQ comes back from the assessor with corrections?
You apply the corrections and resubmit. Corrections are normal; rejections are not. The standard 48-hour engagement assumes one correction cycle is included; multiple cycles do not incur extra fees on the NetSec standard tier.
Where do we book?
Once the 7-day plan completes, book a Cyber Essentials assessment with Net Sec Group. The booking form lets you nominate the SAQ-ready date, and the assessor schedules the 48-hour engagement to start that day.
Reference material
For broader Net Sec Group references on Cyber Essentials preparation:
- Cyber Essentials Certification Guide
- Cyber Essentials 14-day Patching Guide
- Cyber Essentials 30-day Preparation Plan
- CE Self-Assessment Tool
Where this fits on this site
The 7-day plan is the middle path on the speed pillar. The faster path is the 12-hour fast-track engagement, for applicants who arrive ready. The slower path is the 30-day prep plan, for applicants with structural gaps to close. All three paths end at the same IASME certificate. The timelines hub indexes the three paths in one place with the picker decision matrix.
Book your Cyber Essentials assessment with Net Sec Group when the 7 days complete and the SAQ is ready.