Skip to main content

What happens if I need to re-take Cyber Essentials or Cyber Essentials Plus?

What happens if I need to re-take Cyber Essentials or Cyber Essentials Plus?


​

If your Cyber Essentials or Cyber Essentials Plus assessment does not pass, or you need to re-take for another reason, the next steps depend on where the issue happened. Some outcomes are formal fails. Others are timing or remediation lapses that mean the current certification journey cannot continue and needs to be restarted.

Cyber Essentials Plus must be completed either within 3 months of your Cyber Essentials certification being issued, or within 30 days of your audit date - whichever is sooner.

If you do not pass Cyber Essentials

Cyber Essentials is the verified self-assessment stage of the certification journey. If your assessment is marked non-compliant, you will receive feedback explaining what did not meet the requirements. At this point, you can perform the remediations or provide the clarifications requested from the assessor and re-submit your assessment. One important exception is unsupported software & multi-factor authentication (MFA) for your cloud services. Failure to have necessary controls in place for these areas will mean you can not pass the assessment.

If your Cyber Essentials Plus process cannot be completed

Cyber Essentials Plus starts with Cyber Essentials and adds a technical audit of your in-scope systems. If the audit stage does not complete in time, or if remediation is not completed within the allowed window, your current CE/CE+ journey may stop and need to be restarted.

Scenario 1: Your CE+ audit did not take place before the 3 month deadline

This usually happens when the pre-audit steps or booking process are not completed in time. In this situation, the current CE+ journey cannot continue and the next step is usually to start a new Cyber Essentials questionnaire and then re-book the Cyber Essentials Plus audit.

Scenario 2: Your audit took place, but remediation was not completed in time

If issues are found during Cyber Essentials Plus, there is a 30-day remediation window to correct them. If the outstanding remediation is not completed within that period, or before the 3 month Cyber Essentials window lapses, the certification cannot be issued. What happens next depends on how much time is left on your Cyber Essentials certificate.

If there is still enough time remaining within the 3-month CE+ window, it may be possible to restart the CE+ stage.

If that window has also passed, a new Cyber Essentials and a new CE+ audit will be needed.

Scenario 3: Danzell only — the same vulnerabilities are found again in Sample 2

Under Danzell, if missing updates are found in the first device sample, those fixes must be applied across the full scope of the organisation, not just the devices that were originally tested. The assessor then retests the original sample and checks a second random sample.

If the same vulnerabilities are found again in Sample 2, and are not remediated within the remediation window,, the CE+ assessment fails and the Cyber Essentials certificate is revoked. In this case, you will need a new Cyber Essentials and Cyber Essentials Plus audit.

In all of these scenarios, you will need to contact your account manager to arrange re-certification. You can normally do this via the certificates page in the CyberSmart dashboard, or directly via email.

Our aim at CyberSmart is to help you avoid certification delays or failures. We will support you right the way through your Cyber Essentials journey and we provide you with all the tools you need to pass first time.

If you have any questions about anything contained in this article, reach out to our support team via the chat function or by emailing support@cybersmart.co.uk

Did this answer your question?