Cyber Essentials in 12 Hours, the Real Fast-Track Walkthrough

Net Sec Group is an IASME and NCSC certification body. We deliver Cyber Essentials in 12 working hours when the applicant arrives ready, and in 48 hours otherwise. Both are real product tiers, both end in a real IASME certificate, and the difference between them sits almost entirely in the applicant's preparation, not in any shortcut on the assessor's side. This article is the hour-by-hour walkthrough of the 12-hour path, the preconditions that have to be true before the clock starts, and the four reasons we move an applicant from the 12-hour track to the 48-hour track on the same day.

The fast-track exists because UK procurement and tender deadlines are real. A bid closes Friday, the buyer requires a Cyber Essentials certificate, and the supplier finds out on Tuesday. We see this pattern often enough that we built the engagement around it. What we never do is shorten the assessment itself. The IASME Cyber Essentials Self-Assessment Questionnaire is the same questionnaire whether the certificate issues in 12 hours or 5 working days. The certificate is the same certificate, on the same IASME register, with the same 12-month validity.

The 12-hour engagement, hour by hour

Times are working hours, not wall-clock hours. A 12-hour engagement that starts at 9am Monday certifies by mid-morning Wednesday on the published Net Sec Group fast-track service.

Hour 0 to 1, scoping call and SAQ kickoff

A 30-minute scoping call confirms the certification scope (whole organisation, or a defined subsidiary or business unit), the asset list at a high level, the cloud services in scope, and the named signatory. The signatory has to be a board-level officer or equivalent, available to attest to the SAQ when it completes. The SAQ link is issued during the call and the applicant logs in immediately.

Hour 1 to 4, evidence intake and pre-fill

The applicant works through the evidence intake list with the assessor in a shared session. The evidence intake covers all five Cyber Essentials controls (boundary firewalls and internet gateways, secure configuration, user access control, malware protection, security update management). Each item lands in a structured intake form with the configuration export, the screenshot, or the policy document attached. Where intake reveals a gap (an unmanaged personal device with mailbox access, an unpatched legacy server, a service account with disabled MFA), the gap is logged and remediated before SAQ completion. This is the part of the engagement that bumps to 48-hour standard most often.

Hour 4 to 8, SAQ completion and first assessor review

The SAQ is filled in question by question against the intake evidence. The assessor reviews each answer in real time, flags weak answers immediately, and rejects answers that do not match the intake evidence. By hour 8 the SAQ is complete and ready for formal assessor review.

Hour 8 to 10, corrections

The assessor produces a formal review note covering every question that needs strengthening. Typical corrections at this stage are clarifications (the applicant said "all servers" but the asset list shows a hypervisor that was not separately listed), evidence upgrades (a screenshot replaced by a configuration export), or a small remediation (a Conditional Access policy tightened). Corrections are made directly in the SAQ and re-submitted.

Hour 10 to 12, certification

The assessor signs off the SAQ. The IASME certificate issues, the entry appears on the IASME register, and the applicant receives the certificate PDF and the IASME register link. The 12-month validity clock starts.

Preconditions you must meet before the clock starts

The 12-hour engagement only works when the applicant arrives prepared. We confirm the following six preconditions on the scoping call. Failing any one of them moves the engagement to the 48-hour track without exception.

1. Accurate asset list

A complete inventory of every device, server, virtual machine, hypervisor, mobile device, and cloud service in scope. The list does not need to be in any particular format, but it has to be correct and up to date. An asset list with one missing server delays the engagement by hours, not minutes, while we hunt for the gap.

2. Multi-factor authentication on every cloud admin account

Every administrator account on Microsoft 365, Google Workspace, AWS, Azure, or any other cloud service in scope has MFA enforced. At CE Basic the IASME requirement is MFA enforced and verifiable on every cloud admin account. Per-user MFA enabled and verified at the account level is acceptable evidence at this tier. Conditional Access is the requirement at CE Plus, where the assessor samples the enforcement. What is not acceptable at CE Basic is one admin account anywhere without MFA enforced. We see this fail with break-glass admin accounts that the applicant believed were excluded.

3. No unsupported operating system in scope

Every device and every server runs an operating system that is currently supported by the vendor with security patches. End-of-life Windows, end-of-life macOS, end-of-life Linux distributions, end-of-life mobile operating systems, all in scope, all bumping. The fix is to upgrade or remove the device from scope before booking; on the day, neither is fast.

4. Named signatory available within working hours

The board-level signatory is in the office or reachable for sign-off during the engagement window. A signatory on annual leave or in airport mode means the SAQ does not certify. A signatory available "later in the week" pushes the engagement out of the 12-hour window.

5. The 14-day patching standard already in place

Critical and high-severity patches applied within 14 days of vendor release across the in-scope estate. We confirm this with patch-management console screenshots during evidence intake. An applicant who has been patching monthly has a real remediation backlog before the SAQ can complete.

6. Working firewall configuration

A boundary firewall in place, with documented rules, default-deny on inbound traffic, and no permitted services that are not in active use. Cloud-only businesses with no on-premises infrastructure satisfy this through the cloud platform's native firewall (AWS security groups, Azure network security groups, Google Cloud firewall rules) rather than a hardware appliance.

The four reasons fast-track engagements bump to 48-hour standard

Across our 800-plus engagements, four patterns account for almost every 12-hour to 48-hour bump.

Bump 1: scope expanded during evidence intake

The applicant scoped "the head office network" but evidence intake reveals a satellite office, a contractor's laptop on the corporate VPN, or a personal phone with the corporate mailbox. The scope expansion is correct (those devices are in scope), but it adds asset-list, evidence, and review work that does not fit the 12-hour window.

Bump 2: a single high-severity unpatched vulnerability

A patch-management console exports a backlog. One in-scope laptop with a 30-day-old high-severity Windows patch is enough to bump. The fix is straightforward (apply the patch) but the validation cycle (deploy, reboot, re-scan, re-screenshot) crosses the engagement boundary.

Bump 3: cloud admin MFA gap

A service account or break-glass account without MFA, identified during evidence intake. The fix is to enable MFA, replace the credential, and provide a fresh attestation. None of this is fast on Microsoft 365 or Google Workspace at the scale of an engagement clock.

Bump 4: signatory availability

The named signatory is mid-flight, in surgery, or on a remote shoot. The SAQ cannot certify without sign-off. We bump to 48 hours and book the signatory window directly.

When a bump happens, the engagement does not restart. The intake evidence carries forward, the SAQ stays open, and the certificate issues 36 hours later under the 48-hour standard tier with no additional fee on the NetSec fast-track product. Engagements that need structural remediation beyond 48 hours (rare on the fast-track gate, more common when a precondition was missed at booking) move out of the fast-track product to a standard remediation engagement, with the fast-track fee credited against the standard fee.

What 12 hours costs versus 48 hours

The Net Sec Group fast-track tier carries a fast-track price; the 48-hour standard tier carries the standard price. Current published pricing is on the pricing page. The fast-track tier covers the assessor's blocked diary time. There is no premium for the certificate itself; an IASME certificate issued under the fast-track tier is identical to one issued under standard.

For applicants comparing total cost, the largest variable is not the tier but how much remediation the applicant has to do during evidence intake. An applicant who arrives with all six preconditions met certifies in 12 hours and pays the fast-track price. An applicant who arrives with one or two preconditions missed bumps to 48 hours and pays the same fast-track price (no top-up). An applicant who arrives with three or more preconditions missed should book the standard 48-hour tier from the start.

Common questions

Can I do Cyber Essentials Plus on the fast-track schedule?

No. The 12-hour and 48-hour tiers are Cyber Essentials basic only. CE Plus requires a technical assessment day with a sample of devices, an internal vulnerability scan, and an email and browser test, none of which compresses below 4 to 6 hours of assessor work plus 1 to 2 days of pre-assessment readiness. CE Plus end-to-end runs 3 to 5 working days. See the timelines hub for the full timing breakdown.

What if my operating system is unsupported and I cannot upgrade in time?

We move the unsupported device out of scope or end the engagement before billing. We do not certify a scope that contains end-of-life operating systems; the IASME requirements explicitly exclude this and an audit would catch the false attestation.

What happens at renewal?

Cyber Essentials basic certificates expire after 12 months. The renewal is a fresh self-assessment plus assessor review against the current IASME requirements (the requirements update annually, so a renewal is not a copy of last year). The fast-track tier is available at renewal as long as the six preconditions still hold.

If my engagement bumps from 12 to 48 hours, do I get a refund of the fast-track premium?

No, but the engagement does not restart and there is no additional fee for the bump. The fast-track price covers the blocked diary time on our side, which we have already committed to.

Can I book the fast-track tier without a tender deadline?

Yes. The fast-track tier is a product, not a discretionary favour. A buyer who wants to certify quickly because their internal launch date demands it pays the fast-track price the same way as a buyer with a tender deadline.

Reference material

For broader Net Sec Group references on Cyber Essentials and the certification process:

Related on this site

The other speed-pillar articles on this site cover the slower paths and the failure-shape that forces them:

Where to book

The fast-track tier is built for the applicant who walks in ready. The 48-hour standard tier exists for everyone else, and there is no penalty for booking the right one from the start.

Book a fast-track Cyber Essentials engagement with Net Sec Group. Pre-engagement scoping is free, and the scoping call confirms whether the six preconditions hold for your estate. If they do not, we recommend the 48-hour standard tier or a short pre-engagement readiness sprint before booking.