
An organisation holding one certificate has a renewal date. An organisation holding four has a calendar, and in most cases nobody has drawn it.
The dates arrive from different places and behave differently. Some are set nationally and apply to everyone. Some are set by your certification body and are specific to you. Some are set by a customer and appear with three weeks' notice. Treating them as one list is what produces the quarter where three things land at once and the person who owns all of them is on annual leave.
Dates the scheme sets. These are published, they apply to every organisation in scope, and they move only when the scheme operator moves them. The NHS Data Security and Protection Toolkit works this way. As at August 2026 the most recent published edition is 2025-26 version 8, whose submission deadline was 30 June 2026. NHS England has scheduled its 2026-27 toolkit webinars from 22 September 2026, so a successor edition is coming, though neither its assertions nor its deadline are published yet. When they are, the date applies to everyone at once.
Dates your certification body sets. These are yours alone and they follow your certification cycle. For an organisation certified across several sites or entities, IAF MD 1:2023 requires that the central function is audited at initial certification, at every recertification audit, and at least once a calendar year as part of surveillance. Your certification body works to your dates, and those dates are in their diary whether or not they are in yours.
Dates a buyer sets. These have no calendar at all. A trust sends a DTAC assessment when its procurement reaches that point. A security questionnaire arrives with a return date attached to somebody else's decision. You find out when it lands.
A programme planned only around the published dates covers one third of the calendar, and it is the easiest third to see coming.
Cyber Essentials certificates run for twelve months. The part that catches people is when the twelve months starts.
IASME is explicit: a new certificate is valid for twelve months from the date of submission, not from the expiry date of the previous one. Submit six weeks early and your coverage is still twelve months, and your renewal date has moved six weeks earlier for good. Do it again next year and it moves again.
Over three cycles a cautious team can walk their renewal date most of the way across a quarter without anyone deciding to. If your Cyber Essentials date has drifted away from where you expect it, this is usually why.
Certificates are also publicly searchable through IASME, so your position is not private. A buyer can check whether you currently hold a certificate without asking you for it.
Three collisions come up repeatedly.
An ISO surveillance visit and a scheme submission window falling in the same weeks, with the same person preparing both. The evidence overlaps heavily, which sounds like an advantage and is only an advantage if it was collected once.
A recertification landing in the same quarter as an acquisition or a funding round. Diligence questions and audit preparation want the same documents from the same people, and the transaction always wins the diary.
A buyer's assessment arriving during either of the above. DTAC 2.0 was published in February 2026 and the previous form is not to be used from 6 April 2026 onwards, so a supplier who last completed one under the old form is completing an unfamiliar document under someone else's deadline. NHS England has also noted that reviews of the clinical safety standards within DTAC are ongoing, so the section most likely to need specialist input is the section most likely to have moved.
A calendar with four columns: the date, what it is, who owns it by name, and what evidence it needs.
Fill the evidence column properly. The point of the exercise is seeing that the access review, the training records and the supplier list appear against three separate dates, and that collecting them three times is a choice.
Then work backwards from the earliest date. The largest piece is usually the recertification, and the thing that fails first is usually something smaller with a nearer date.
Two entries most calendars are missing. The date your Cyber Essentials certificate expires, taken from the certificate rather than from memory, given the submission-date behaviour above. And an owner for the dates you cannot predict, because a buyer's questionnaire arriving with no named owner sits unclaimed for a week before anyone starts it.
None of these dates is negotiable in any useful sense. A scheme operator does not move a national deadline for one supplier, a certification body's cycle is set by your certification decision, and a buyer's return date is set by their procurement timetable.
What is available is the state of the evidence when each date arrives. An organisation that collects an access review once and points it at every requirement it satisfies meets four dates with one piece of work. Collect it four times and you meet the first two dates, then start asking for extensions on the rest.
The Naq platform automates Cyber Essentials, ISO 27001, ISO 9001, the NHS DSPT and GDPR from a single dashboard. Controls are mapped across frameworks, so one piece of evidence satisfies requirements in several standards at the same time instead of being collected separately for each.
Policies and risks carry a named owner and a named approver, with a review date set at sign-off, so each item on the calendar belongs to a person before the date arrives. Field edits are recorded on the activity stream with the previous and the new value, and records are archived instead of deleted, so the position on any given date is something you can show afterwards. Where a framework is held more than once, each instance draws on the same underlying controls and evidence.
Naq's in-house Clinical Safety Officers and virtual Data Protection Officers cover the dates that need specialist input, alongside the platform. Naq is also a Cyber Essentials Certifying Body via IASME, and Cyber Essentials Plus assessments and CREST-accredited penetration testing are arranged through Naq's external partnership network.
For requirement detail, see the Cyber Essentials framework page, the NHS DSPT framework page and the ISO 27001 framework page, and compliance across several entities for the case where several of these run at once. If more than one legal entity is involved, certifying a group covers how the certificate itself works.
If you are looking at a quarter with two dates in it, book a fifteen-minute demo and we will map the evidence each one needs.