Cyber Essentials Renewal

Cyber Essentials certificates expire after 12 months, and renewal is not a rubber stamp: you complete the current question set against the current requirements. Organisations that certified under Willow last year will renew under Danzell (v3.3), and answers that passed in 2025 can fail in 2026.

RedSecLabs is preparing to offer Cyber Essentials renewal services designed around exactly this problem. Before you resubmit, we compare your previous responses against the current requirements, flag every answer the scheme changes have invalidated, and verify remediation, so your renewal is as smooth as your first pass should have been.

We also run renewal reminders at 90, 60 and 30 days, because a lapsed certificate means dropping off the NCSC register and restarting contracts’ compliance clocks.

CREST Certified Pen Test Provider ISO Certified OSCP Certified Industry Certification

Register Your Interest

Tell us about your organisation and we’ll contact you the day our Cyber Essentials service goes live. No obligation.

You’ll get our Danzell readiness checklist by reply, and one email when we launch. No mailing lists, ever.

Launching Soon RedSecLabs is preparing to offer Cyber Essentials and Cyber Essentials Plus certification services. Register your interest for priority assessment slots at launch and our free Danzell readiness checklist now.
Willow-to-Danzell gap analysis · 90/60/30-day reminders · Pre-submission review · Fixed IASME fee, no surprises · Same-day scoping response
Who this is for

This page is for you if you’re..

1
Renewing under new rules
Organisations that certified under Willow (or earlier) and now face the stricter Danzell v3.3 requirements for the first time.
2
Lapsed certificates
Businesses whose certification expired, dropping them from the NCSC register, and who need it back for a contract.
3
Estate has changed
Organisations whose scope shifted since last year: new cloud services, more remote staff, acquisitions, or replaced infrastructure.

Cyber Essentials Renewal, Quick Facts

Last reviewed: 2026-07-21
Validity
12 months from certification date; the NCSC register lists only organisations certified within the past year
Renewal = reassessment
You complete the current question set in full; there is no shortened renewal form
2026 trap
Certified under Willow? Renewal uses Danzell v3.3: MFA on all cloud services and 14-day patching are now automatic failures
Transition deadline
Legacy Willow-based assessment accounts must be finalised by 26 October 2026
Fee
Micro (0–9 staff) £320 + VAT · Small (10–49) £440 + VAT · Medium (50–249) £500 + VAT · Large (250+) £600 + VAT (same as initial certification)
Plus renewals
Cyber Essentials Plus also renews annually; the fresh CE pass restarts the 3-month Plus window
12 months
Certificate lifetime, no grace period on the register
v3.3
The requirements your renewal is judged against
2
New automatic-failure conditions since April 2026
90 days
When smart renewal preparation starts

What changes between your passes

Two things move every year: the scheme and your organisation. On the scheme side, the April 2026 update was the most consequential in years, MFA on every cloud service where available became an automatic failure, security update timescales gained auto-fail enforcement, cloud service definitions widened, and scoping language around remote workers and BYOD tightened. Answers copied from last year's spreadsheet may now describe a failing configuration.

On your side, twelve months of business change accumulates: new SaaS subscriptions nobody added to the asset list, staff turnover leaving stale accounts, devices bought outside procurement, an office move or acquisition. Renewal is the annual moment those drifts get caught, which is precisely why buyers value a current certificate over an old one.

What a well-run renewal includes:
Gap analysis of last year's answers against the current (Danzell v3.3) requirements
Refreshed asset and cloud service inventory reflecting a year of change
MFA verification across every in-scope cloud service, the new auto-fail
Patch compliance check against the 14-day high/critical window
Leaver-account and admin-separation review
Board-level declaration re-signed with confidence, not hope

Treat renewal as a health check with a certificate attached, the organisations that do find it cheaper and faster every year, because drift never accumulates.

The cost of letting it lapse

Because certification is annual, a lapse is visible: your organisation disappears from the NCSC's certified-organisations register, and any contract clause requiring you to “maintain” Cyber Essentials is technically in breach from expiry day. Re-certifying after a lapse is a full assessment either way, so delaying saves nothing and risks plenty.

The pattern we see repeatedly: certification was one person's project, that person left, the reminder email went to a dead mailbox, and the first anyone hears of it is a procurement portal rejecting a bid. A renewal process, not a calendar entry, is the fix.

Common renewal failures and their causes:
Copying last year's answers into a question set that changed underneath them
MFA gaps on cloud services adopted mid-year, instant fail under v3.3
New unsupported software that crept in via one department's purchase
Remote workers hired during the year, never brought into scope
The renewal owner left; nobody was watching the expiry date
Plus renewals missed because the 3-month window after the CE pass slipped by

Every one of these is preventable with a 90-day runway and a current-rules review. That is exactly the service we’re building.

Not sure where you stand against the 2026 (Danzell) rules? We’ll tell you, before it costs you an assessment fee.
Get a Free Readiness Review

Willow to Danzell: what changed for your renewal

If your current certificate was assessed under Willow (v3.2), these are the differences your renewal will be marked against.

AreaUnder Willow (your last pass)Under Danzell v3.3 (your renewal)
MFA on cloud servicesRequired, with assessor discretion on gapsAutomatic failure if MFA is not enabled on any in-scope cloud service where available
Security updates14-day expectation, marked with discretionAutomatic failure for unsupported software in scope or high/critical updates older than 14 days
Cloud service definitionNarrower; ‘peripheral’ services often excludedFormal, broad definition, includes the full SaaS toolchain and business social media accounts
Shared loginsDiscouragedIndividual accounts expected wherever the service supports them, including social platforms
Remote workers & BYODIn scope, with looser wordingTightened scoping language; personal devices touching work data are unambiguously in
CE Plus samplingStandard samplingRevised sampling approach designed to catch selective, assessment-week-only patching

Summary based on the published v3.3 requirements and IASME guidance as of July 2026. Legacy Willow assessment accounts must be finalised by late October 2026, check the exact deadline shown in your assessment account.

Never Miss a Renewal Again

Register your interest and tell us your current certificate’s expiry date. We’ll build your renewal runway against the 2026 rules and contact you when our service launches.

Frequently Asked Questions

Start reviewing 90 days before expiry and submit around 4–6 weeks out. That leaves room to remediate anything the current question set now treats differently, without risking a gap on the NCSC register. Certificates dated within the last 12 months are what buyers check for.

Operationally yes, you know the process and most controls persist. But it is a full assessment against the current requirements, not a shortened form. In 2026 specifically, organisations renewing from Willow face materially stricter rules than they passed under, so complacency is the main risk.

Your renewal will use the Danzell question set under Requirements v3.3 (from 27 April 2026). The headline changes: MFA is required on all cloud services where available (automatic failure if missing), high/critical updates must be applied within 14 days (automatic failure), the cloud services definition is broader, and remote worker/BYOD scoping is tighter.

You drop off the NCSC's certified-organisations register and cannot claim current certification, which matters for contracts requiring you to maintain it. There's no penalty process, but re-certification is a full assessment either way, so a lapse buys nothing and can cost a live bid.

Yes. Plus is also valid for 12 months and renewing it requires a current basic Cyber Essentials pass first, with the Plus audit completed within 3 months of that pass. Renewal is the natural moment to schedule both so the windows line up.

You still complete the current question set, but if genuinely little changed, most answers update quickly. In practice, something always changed: SaaS tools were added, staff joined and left, updates policies drifted. The review exists to catch exactly the changes organisations believe didn't happen.
📞 Call us Book a call