← All articles

How long does Cyber Essentials last?

3 September 2026 · 4 min read

A Cyber Essentials certificate is valid for twelve months from the date of issue. There is no grace period: once it lapses, you cannot claim certification, and contracts or insurance policies that require it are immediately exposed.

The twelve-month clock matters more than it first appears. Buyers and insurers increasingly check certificates at the point of signing, not the point of tendering, so a certificate that expires mid-contract can cause awkward conversations at exactly the wrong moment.

The organisations that renew painlessly treat compliance as a monthly habit rather than an annual event. They keep a dated register of cloud services, check multi-factor authentication stays enforced, and refresh their policies as the business changes. When renewal arrives, the evidence already exists.

The ones that struggle do the opposite: nothing for eleven months, then a frantic fortnight reconstructing what changed, who joined, who left and which new tools appeared. Gaps found at that point are expensive to fix under time pressure.

Kept automates the habit. Monthly evidence snapshots record the state of your controls, and renewal reminders start well before expiry — so the twelve-month deadline never becomes a surprise. Run the free scan to see where you would stand today.