When the answer is "neither, yet"
Certification assesses what you already do. It is not a programme that installs good practice on your behalf, and entering early tends to produce a long list of findings and a second round of work.
Three questions are a fair self-test:
- Can you produce a current list of your devices, software and user accounts?
- Can you show that someone has restored from a backup recently, rather than that backups are running?
- Is there a named person who would run an incident, and does anyone else know their name?
If any of those is uncomfortable, that work comes first. It also tends to be the least expensive phase, because it needs decisions and record-keeping rather than new technology.
How much runway each one needs
Cyber Essentials can move quickly, because the assessment is a verified self-assessment rather than a staged audit.
Cyber Trust needs planning room, and the arithmetic is worth doing before you commit to a date. The gap between Stage 1 and Stage 2 cannot exceed six months, or Stage 1 has to be redone. Assessors also expect to see roughly three months of operating records by the time Stage 2 runs, so a control implemented the week before the audit has nothing to show. Add whatever remediation your own gap analysis turns up, which for most first-time organisations is the longest item on the list. On those three assumptions, a first Cyber Trust certification is a project you start about a year out. If your controls are already running and evidenced, it is shorter.
Funding
Support is available for both, and the mechanics differ by scheme and by your eligibility. Greenwich is a CSA-funded CISOaaS provider, so this is a conversation we have with clients before the engagement is scoped rather than after. It is worth having early, because the funding route can change how the work is staged.
The short answer
If you are an SME with a straightforward IT estate and a customer asking for assurance, start with Cyber Essentials. It is proportionate, it is finite, and it will surface the gaps that matter.
If you hold significant volumes of personal or commercially sensitive data, operate in a regulated supply chain, or have been told specifically that Cyber Trust is expected, size the tier from a risk assessment and give yourself a year.
If neither is true yet, do the inventory, prove a restore, and name an incident owner. Then call us.