Blog
Compliance
ISO 27001
Cyber Essentials
NHS DSPT v8
August 5, 2026
Approx min read

How long ISO 27001, Cyber Essentials and DSPT take

A buyer asks for ISO 27001 in September and wants the certificate in place before a contract starts in January. Whether that is achievable comes down to a sequence you do not control, and for most organisations starting from scratch the answer is no.

Most compliance planning goes wrong at this point. The requirement gets treated as a project with a flexible end date, when several of the steps sit in someone else's diary. Here is what actually sets the floor for each of the standards UK buyers ask for, and how to work backwards from a contract date without guessing.

What sets the floor for ISO 27001

The certificate is issued by a certification body accredited by UKAS. Your consultant cannot issue it and neither can a software platform. That single fact drives most of the timeline.

Initial certification runs as two audits. Stage 1 reviews your documentation and readiness. Stage 2 examines whether the information security management system is genuinely operating. Between the two, any gaps raised at Stage 1 have to be closed, and if the auditor finds the system is not yet running in practice, Stage 2 moves.

Three things have to have happened before Stage 2 is worth booking. The management system needs to have been operating long enough to produce evidence. You need a completed internal audit covering the scope. You need a management review on record. None of those can be produced on the morning of the audit, because each one is looking for a history.

Audit duration itself is calculated under rules the certification body has to follow, set out in ISO/IEC 17021-1 and ISO/IEC 27006 and checked by UKAS. Certification bodies justify audit time against objective criteria including the size and complexity of your scope, so the number of audit days is not something you can negotiate down to fit a deadline.

After certification the cycle continues. Surveillance audits fall at the end of years one and two, and a recertification audit is required before the three years are up.

The part you can compress is your own preparation. The parts you cannot are the operating period, the internal audit and management review, the certification body's availability, and whatever corrective action comes out of Stage 1.

Cyber Essentials moves fastest, until remediation starts

Cyber Essentials is a verified self-assessment, and the certificate is valid for twelve months. Of the standards UK buyers commonly ask for, it is the one you can realistically obtain inside a short window.

The change that matters this year is what happens when your answers fall short. Since late April 2026, new assessment accounts use the Danzell question set aligned to Requirements for IT Infrastructure v3.3. Three answers now fail the assessment outright. Multi-factor authentication is mandatory on every cloud service that offers it, regardless of cost. High-risk and critical security updates for operating systems and for router and firewall firmware must be installed within 14 days of release, under question A6.4. The same 14-day rule applies to applications and their associated files and extensions, under A6.5.

The practical effect on timing is that remediation now sets the length of a Cyber Essentials project. If multi-factor authentication is missing on one cloud service somewhere in scope, that is a fail, and the clock restarts on getting it fixed and evidenced.

Two further rules shape the calendar. Once an assessment account is created you have six months to complete it. And a Cyber Essentials Plus audit has to be completed within three months of your Cyber Essentials certification, so a slipped Cyber Essentials date drags Cyber Essentials Plus with it.

You can read the detail of the current requirements on the Cyber Essentials framework page.

The NHS DSPT runs on its own annual calendar

The Data Security and Protection Toolkit is an annual published assessment rather than a certificate you hold. The 2025-26 deadline was 30 June 2026.

Two consequences follow for anyone selling into the NHS. First, you cannot bring the deadline forward to suit a procurement. Whatever status you have published on the day a buyer looks is the status they see. Second, that status is public. Trusts and integrated care boards check supplier standing on the register before they sign new orders or renew at end of term.

If you did not reach Standards Met, the route back runs through an improvement plan with named actions, owners and dates, reviewed by NHS England. An approved plan moves the published status to Approaching Standards. That process has its own reporting dates through the rest of the year, covered in the piece on what happens after the DSPT deadline.

NHS DTAC has no fixed calendar at all

The Digital Technology Assessment Criteria is assessed per procurement by the buying organisation, against the evidence you supply. There is no scheme deadline to work to. The timeline belongs to the trust, it starts when they send you the assessment, and it moves at whatever pace their process moves.

The component that takes longest to assemble honestly is clinical safety. DCB 0129 expects a Clinical Safety Officer, a hazard log with causes recorded against each hazard, and evidence that the analysis informed the product. That is a body of work with a history, and it reads as retrofitted when it is written the week the assessment arrives.

Working backwards from the contract date

Take the date on the contract, since the date in the buyer's email is usually the softer of the two, and work back through the fixed steps.

For an ISO 27001 requirement, that means the certificate date, then the Stage 2 audit, then the gap for Stage 1 findings, then Stage 1, then the management review, then the internal audit, then the period the management system has to have been running. Book the certification body early in that chain, because their diary is usually the first hard constraint you hit.

For Cyber Essentials, work back from the date the buyer needs to see a current certificate, then allow for the remediation you have not done yet. Run the multi-factor authentication and patching checks before you open the assessment account, so the six-month window is not spent on fixes.

For DSPT, work back from the submission window, and treat evidence as the long pole. Assertions that expect a policy, a role assignment and a record of the thing actually happening cannot be satisfied by a document written the night before.

When the date is already too close

Say so early and say so precisely. Buyers rarely walk away because a supplier is mid-certification. They walk away when it emerges late, because by then they are judging your reliability as much as your security posture.

What holds a deal together in that conversation is specificity. Give the buyer the booked audit date and the name of the certification body. Show the internal audit date. Offer the assurance you can evidence now, whether that is a current Cyber Essentials certificate, a published DSPT status, signed and approved policies, or a defined management system scope with named owners. Put the remaining steps on a plan with dates against each one.

Then start the sequence that gates everything else. Much of the underlying work is shared. The access control evidence behind Cyber Essentials supports ISO 27001 requirements. The policy set behind ISO 27001 covers a large part of what the DSPT assertions ask for. Sequenced properly, the second framework is considerably shorter than the first.

How Naq shortens the parts you control

Naq tracks GDPR, Cyber Essentials, Cyber Essentials Plus, NHS DSPT, NHS DTAC, DCB 0129, ISO 27001 and ISO 9001 in one place, with controls mapped to the requirements they satisfy across every framework at once. Evidence attached to a control counts everywhere that control applies, so the second and third frameworks draw on work you have already done.

Naq is a Cyber Essentials Certifying Body via IASME, so Cyber Essentials and Cyber Essentials Plus run through the platform. For ISO 27001 and ISO 9001, Naq gets you audit-ready for the UKAS-accredited certification body that issues the certificate. In-house Clinical Safety Officers and virtual Data Protection Officers are included, which matters when the clinical safety or data protection evidence is the piece holding up the deal.

If a customer deadline is already on the table, book a fifteen-minute demo and bring the date with you.

A buyer asks for ISO 27001 in September and wants the certificate in place before a contract starts in January. Whether that is achievable comes down to a sequence you do not control, and for most organisations starting from scratch the answer is no.

Most compliance planning goes wrong at this point. The requirement gets treated as a project with a flexible end date, when several of the steps sit in someone else's diary. Here is what actually sets the floor for each of the standards UK buyers ask for, and how to work backwards from a contract date without guessing.

What sets the floor for ISO 27001

The certificate is issued by a certification body accredited by UKAS. Your consultant cannot issue it and neither can a software platform. That single fact drives most of the timeline.

Initial certification runs as two audits. Stage 1 reviews your documentation and readiness. Stage 2 examines whether the information security management system is genuinely operating. Between the two, any gaps raised at Stage 1 have to be closed, and if the auditor finds the system is not yet running in practice, Stage 2 moves.

Three things have to have happened before Stage 2 is worth booking. The management system needs to have been operating long enough to produce evidence. You need a completed internal audit covering the scope. You need a management review on record. None of those can be produced on the morning of the audit, because each one is looking for a history.

Audit duration itself is calculated under rules the certification body has to follow, set out in ISO/IEC 17021-1 and ISO/IEC 27006 and checked by UKAS. Certification bodies justify audit time against objective criteria including the size and complexity of your scope, so the number of audit days is not something you can negotiate down to fit a deadline.

After certification the cycle continues. Surveillance audits fall at the end of years one and two, and a recertification audit is required before the three years are up.

The part you can compress is your own preparation. The parts you cannot are the operating period, the internal audit and management review, the certification body's availability, and whatever corrective action comes out of Stage 1.

Cyber Essentials moves fastest, until remediation starts

Cyber Essentials is a verified self-assessment, and the certificate is valid for twelve months. Of the standards UK buyers commonly ask for, it is the one you can realistically obtain inside a short window.

The change that matters this year is what happens when your answers fall short. Since late April 2026, new assessment accounts use the Danzell question set aligned to Requirements for IT Infrastructure v3.3. Three answers now fail the assessment outright. Multi-factor authentication is mandatory on every cloud service that offers it, regardless of cost. High-risk and critical security updates for operating systems and for router and firewall firmware must be installed within 14 days of release, under question A6.4. The same 14-day rule applies to applications and their associated files and extensions, under A6.5.

The practical effect on timing is that remediation now sets the length of a Cyber Essentials project. If multi-factor authentication is missing on one cloud service somewhere in scope, that is a fail, and the clock restarts on getting it fixed and evidenced.

Two further rules shape the calendar. Once an assessment account is created you have six months to complete it. And a Cyber Essentials Plus audit has to be completed within three months of your Cyber Essentials certification, so a slipped Cyber Essentials date drags Cyber Essentials Plus with it.

You can read the detail of the current requirements on the Cyber Essentials framework page.

The NHS DSPT runs on its own annual calendar

The Data Security and Protection Toolkit is an annual published assessment rather than a certificate you hold. The 2025-26 deadline was 30 June 2026.

Two consequences follow for anyone selling into the NHS. First, you cannot bring the deadline forward to suit a procurement. Whatever status you have published on the day a buyer looks is the status they see. Second, that status is public. Trusts and integrated care boards check supplier standing on the register before they sign new orders or renew at end of term.

If you did not reach Standards Met, the route back runs through an improvement plan with named actions, owners and dates, reviewed by NHS England. An approved plan moves the published status to Approaching Standards. That process has its own reporting dates through the rest of the year, covered in the piece on what happens after the DSPT deadline.

NHS DTAC has no fixed calendar at all

The Digital Technology Assessment Criteria is assessed per procurement by the buying organisation, against the evidence you supply. There is no scheme deadline to work to. The timeline belongs to the trust, it starts when they send you the assessment, and it moves at whatever pace their process moves.

The component that takes longest to assemble honestly is clinical safety. DCB 0129 expects a Clinical Safety Officer, a hazard log with causes recorded against each hazard, and evidence that the analysis informed the product. That is a body of work with a history, and it reads as retrofitted when it is written the week the assessment arrives.

Working backwards from the contract date

Take the date on the contract, since the date in the buyer's email is usually the softer of the two, and work back through the fixed steps.

For an ISO 27001 requirement, that means the certificate date, then the Stage 2 audit, then the gap for Stage 1 findings, then Stage 1, then the management review, then the internal audit, then the period the management system has to have been running. Book the certification body early in that chain, because their diary is usually the first hard constraint you hit.

For Cyber Essentials, work back from the date the buyer needs to see a current certificate, then allow for the remediation you have not done yet. Run the multi-factor authentication and patching checks before you open the assessment account, so the six-month window is not spent on fixes.

For DSPT, work back from the submission window, and treat evidence as the long pole. Assertions that expect a policy, a role assignment and a record of the thing actually happening cannot be satisfied by a document written the night before.

When the date is already too close

Say so early and say so precisely. Buyers rarely walk away because a supplier is mid-certification. They walk away when it emerges late, because by then they are judging your reliability as much as your security posture.

What holds a deal together in that conversation is specificity. Give the buyer the booked audit date and the name of the certification body. Show the internal audit date. Offer the assurance you can evidence now, whether that is a current Cyber Essentials certificate, a published DSPT status, signed and approved policies, or a defined management system scope with named owners. Put the remaining steps on a plan with dates against each one.

Then start the sequence that gates everything else. Much of the underlying work is shared. The access control evidence behind Cyber Essentials supports ISO 27001 requirements. The policy set behind ISO 27001 covers a large part of what the DSPT assertions ask for. Sequenced properly, the second framework is considerably shorter than the first.

How Naq shortens the parts you control

Naq tracks GDPR, Cyber Essentials, Cyber Essentials Plus, NHS DSPT, NHS DTAC, DCB 0129, ISO 27001 and ISO 9001 in one place, with controls mapped to the requirements they satisfy across every framework at once. Evidence attached to a control counts everywhere that control applies, so the second and third frameworks draw on work you have already done.

Naq is a Cyber Essentials Certifying Body via IASME, so Cyber Essentials and Cyber Essentials Plus run through the platform. For ISO 27001 and ISO 9001, Naq gets you audit-ready for the UKAS-accredited certification body that issues the certificate. In-house Clinical Safety Officers and virtual Data Protection Officers are included, which matters when the clinical safety or data protection evidence is the piece holding up the deal.

If a customer deadline is already on the table, book a fifteen-minute demo and bring the date with you.