Cyber Essentials 2026: What’s Changing in the UK’s Flagship Cyber-Security Scheme and How to Prepare
From 27 April 2026, the UK’s flagship cyber-security certification scheme, Cyber Essentials, is introducing a set of major changes aimed at strengthening baseline cyber defences for organisations of all sizes. These changes have been carefully designed by the National Cyber Security Centre (NCSC) and the IASME Consortium, the scheme’s managing body, to reflect modern technology trends, evolving threat landscapes, and the realities of cloud-first business environments.
If your organisation currently holds Cyber Essentials certification or plans to apply in the coming months, please read on as these changes are significant, and early preparation will make the path to compliance much smoother.
What Is Cyber Essentials? A Quick Recap
Cyber Essentials is a UK Government-backed certification that helps organisations protect themselves against the most common cyber threats. It focuses on five core technical controls:
- Firewalls and boundary security
- Secure configuration
- Security update management
- User access control
- Malware protection
Achieving Cyber Essentials certification shows customers, partners, and regulators that your organisation takes cyber-security seriously and has implemented robust, baseline protections against everyday threats such as phishing, brute-force attacks and automated malware.
Why the 2026 Update Is Happening
Technology and business practices have shifted rapidly over the last few years. More services are cloud-based, remote or hybrid working is now standard practice, and attackers are increasingly automated and sophisticated. The existing standard, while effective, no longer fully addresses these trends, especially where cloud platforms and identity management systems are central to business operations.
To keep the scheme relevant and effective, the NCSC and IASME have introduced a new version of the standard, Cyber Essentials Requirements for IT Infrastructure v3.3, which will apply to all assessment accounts created on or after 27 April 2026.
If your organisation starts a Cyber Essentials assessment before this date, you’ll have six months to complete it under the existing version, but any assessments started on or after this date must comply with the new rules.
Key Changes in Cyber Essentials 2026
Here’s a breakdown of the most important changes that organisations need to understand and act upon:
- Cloud Services Are Now Fully In Scope
Perhaps the single biggest change is that cloud services are now explicitly included in scope for Cyber Essentials.
Any online service or infrastructure that stores or processes organisational data must be assessed and secured, whether it’s:
- SaaS applications like Microsoft 365 or Google Workspace
- Cloud storage or databases
- Identity and access management systems
This shift recognises that cloud services are now fundamental to business operations, and security responsibilities can no longer be assumed to be entirely with the provider.
What you need to do:
- Create a complete inventory of all cloud services used by your organisation.
- Ensure that each service meets baseline security controls and is configured securely.
- Provide documentation and evidence of those configurations for your Cyber Essentials assessment.
- Mandatory Multi-Factor Authentication (MFA)
While MFA has long been recommended, from April 2026 it becomes mandatory wherever it’s offered by a cloud service.
This means:
- If a cloud service supports MFA, even as an optional or paid feature, it must be enabled for all accounts.
- This applies to admin and standard user accounts.
- Failing to enable MFA where available will result in an automatic failure of the assessment.
Why this matters: MFA blocks the vast majority of automated attacks and significantly improves the security of account access, especially for services accessible over the internet.
Preparation steps:
- Review all accounts for all cloud applications you use.
- Enable MFA across the board, ideally using strong methods such as authenticator apps or hardware tokens.
- Communicate and train users so they understand how and when to use MFA.
- Stronger Scoping Requirements
Cyber Essentials has always required organisations to identify what’s in scope, but the updated rules tighten this definition.
Now, any device or service that:
- Accepts inbound or outbound internet connections, or
- Processes or routes internet-connected data
must be included in your assessment. This could include laptops, mobiles, servers, IoT devices, network gear, or even devices you might not have previously considered.
If you want to exclude something from scope, you must clearly justify why it’s segregated and provide evidence that it’s isolated from your primary network.
What to do:
- Audit all endpoints and services connected to your network.
- Define your scope clearly and document any exclusions with solid technical evidence.
- Work closely with your assessor to agree on scope early in the process.
- Encouragement of Passwordless and Modern Authentication
While passwords aren’t going away yet, the new standard actively encourages passwordless authentication, such as:
- Passkeys
- Biometric logins
- Security tokens
- FIDO2 authenticators
This isn’t yet a requirement, but it signals where the scheme, and cybersecurity best practice, is heading.
How to respond:
- Begin evaluating passwordless login options for your organisation.
- Where feasible, adopt stronger login methods to reduce reliance on passwords and improve user experience.
- Greater Focus on Backups and Recovery
The updated requirements put more emphasis on documented, regularly tested backups that support recovery after an incident.
- Backups should be documented and their recovery processes tested regularly.
- This demonstrates that your organisation is resilient and can return to normal operations after disruption, a key part of modern cyber-security preparedness.
Preparation steps:
- Review your backup policies and procedures.
- Ensure backups are complete, securely stored, and tested at least quarterly.
- Document results and improvements made following tests.
- Application-Level Security Expectations
The revised standard expands the focus from just network and system controls to also include application development and secure coding practices where software is in scope.
This change reflects the increasing importance of applications and code in modern IT stacks.
How to Prepare for the April 2026 Update
Preparing early is critical. As with any compliance regime, last-minute scrambles lead to missed requirements and unnecessary stress. Here’s a roadmap for getting ready:
- Conduct a Gap Analysis
Compare your current security posture and documentation against the new requirements. Identify areas where you fall short and build a remediation plan. - Build an Asset Inventory
Document all cloud services, devices, and internet-connected systems. Ensure that your scope for assessment is complete and defensible. - Enable MFA Everywhere
Work with IT and business owners to roll out MFA across all cloud services and critical systems. Choose strong methods that are sustainable long-term. - Review Backups and Disaster Recovery
Ensure your backup strategy is robust and tested. Document your procedures and evidence. - Train Your Team
Security is only as strong as its weakest link. Educate staff on MFA usage, secure access practices, and why these changes matter. - Engage Early with an Assessor such as Minerva
Get your certification body involved early. Discuss scope, evidence expectations, and any unusual configurations in advance.
Final Thoughts
The Cyber Essentials update taking effect from April 2026 is more than a minor tweak; it’s a meaningful strengthening of UK baseline security expectations. By expanding cloud coverage, tightening scopes, and making MFA mandatory, the scheme aligns itself with modern cyber-security realities.
Whether you are just starting your preparations or you need help completing your Cyber Essentials assessment under the new framework, Minerva’s team of certified engineers and technical consultants can help you understand the updated requirements, identify gaps in your current security posture, and implement the necessary controls. From proactive system monitoring and secure configuration to documentation for certification evidence, we can provide hands-on support that allows your business to stay secure while meeting compliance obligations.
To discuss how Minerva IT Support can help your organisation navigate the updated Cyber Essentials requirements, please contact us here