Cyber Essentials Timelines, the Speed-Pathway Hub

Net Sec Group is an IASME and NCSC certification body. The Cyber Essentials certificate is one artefact at the end; the path to it is one of four. This hub indexes the four real timeline paths we run, with the per-stage timing drawn from our 800-plus engagement history rather than the generic "3 to 5 days" answer typical consultancy pages give. Pick the path that matches your starting state and your deadline; each path links to the deep-dive spoke that walks the work.

The four paths are: the 12-hour fast-track engagement for applicants who arrive ready, the 7-day prep plan for applicants with the basics in place, the 30-day prep plan for applicants with structural gaps to close, and the diagnostic for applicants trying to avoid the rework that rolls a clean engagement into a multi-attempt one. All four end at the same IASME certificate; the certificate carries the same 12-month validity regardless of the path.

Articles in this hub

Cyber Essentials in 12 Hours, the Real Fast-Track Walkthrough

The hour-by-hour walkthrough of the 12-hour engagement. Hour 0 to 1 scoping, hour 1 to 4 evidence intake, hour 4 to 8 SAQ completion and assessor review, hour 8 to 10 corrections, hour 10 to 12 certification. Six preconditions the applicant must meet before the clock starts. Four reasons the engagement bumps to 48-hour standard. The fast-track tier is a paid product where Net Sec Group blocks 12 working hours of assessor diary time; it suits buyers with a tender deadline closing next week.

Cyber Essentials in 7 Days, the Day-by-Day Prep Plan

The 7-day calendar plan, day by day, with checkpoint criteria per day. Day 1 asset list, day 2 scope statement, day 3 user access control evidence, day 4 secure configuration and malware protection evidence, day 5 the 14-day patching window evidenced, day 6 SAQ completion, day 7 assessor review and submission. The plan presupposes MFA already enforced on cloud admin; if MFA is not yet in place, the 7-day plan does not work in 7 days.

Cyber Essentials in 30 Days, the Week-by-Week Founder Plan

The 30-day plan, week by week, calibrated for a UK founder running preparation alongside a day job. Week 1 scope and asset list, week 2 control gaps and tooling purchase decisions, week 3 evidence collection and 14-day patching window completion, week 4 SAQ submission and assessor review. Includes the cost markers per week (week 2 is typically the only paid week) and the practitioner observation that week 3 is the week that slips most readily when an end-of-life operating system surfaces during patching.

Why Cyber Essentials Fails on the First Try, the Real Frequency-Ranked Causes

The diagnostic article. Eight failure causes ranked by frequency from the 800-plus engagement history, each paired with the fix and a pre-check the applicant can run themselves. The 8-item before-you-book pre-check at the end is the deciding instrument for which timeline path to pick: all 8 yes points to the 12-hour fast-track; 3 to 4 no points to the 7-day prep plan; 5 or more no points to the 30-day prep plan.

Which timeline path is right for you

Run the 8-item pre-check before deciding. The result of the pre-check tells you which path matches your starting state.

| Where you are | Read this | |---|---| | Tender deadline next week, all 8 pre-check items return yes | 12-hour fast-track engagement | | Have 1 to 2 weeks before the deadline, the basics are in place, 1 or 2 pre-check items return no | 7-day prep plan | | Have 1 month or more before the deadline, structural gaps to close (MFA rollout, EOL operating systems, patching backlog) | 30-day prep plan | | Just failed a first attempt and have a 30-day reassessment window | Why Cyber Essentials fails first try plus the prep plan that matches the failure shape | | Unsure about scope before picking a path | The scope-decisions hub settles scope first; come back here once it is settled |

How this hub relates to the other two

The timelines hub is one of three on this site. The other two:

A typical buyer journey runs: scope-decisions hub (settle who and what) → comparisons hub (settle which certification and which execution model) → timelines hub (pick the speed path) → spoke article (do the work).

Common questions

What is the absolute fastest the certificate can issue?

The 12-hour fast-track engagement is the fastest. The applicant must arrive with all six preconditions met (asset list complete, MFA on every cloud admin, no unsupported OS in scope, named signatory available, 14-day patching standard already met, working firewall configuration). End-to-end from booking to certificate is typically 24 to 36 hours.

What if my engagement runs over because of structural fixes?

The Net Sec Group standard tier accommodates the over-run inside the engagement window with no additional fee. The certificate issues when the SAQ is clean; if the SAQ takes 5 days instead of 2, the certificate issues on day 5, not earlier and not later.

Can I switch paths partway through?

Yes. If you start the 7-day plan and discover MFA needs estate-wide rollout, switch to the 30-day plan. The work already done carries forward; the only thing changing is the SAQ submission date.

Where do we book?

Pick the path above, follow the link to the spoke article, and use the booking link there. The booking form lets you nominate the SAQ-ready date.

Reference material

For the broader Net Sec Group reference covering the certification process end-to-end: