The cyber threat landscape has changed significantly over the last couple of years, evolving rapidly at a rate that can seem daunting and convoluted. Expectations across sectors continue to expand concerning companies’ technical security controls and the protection of their data, moving on from the general acceptance of ‘the bare minimum ’ to paving the way for proactive, comprehensive security measures. Reflecting this higher standard, the Cyber Essentials certification scheme has introduced two key changes which now carry an automatic fail status from 27th April 2026 onward.
Cyber Essentials, a UK government-backed certification designed to safeguard your organisation’s and customers’ data against cyber attacks, has updated its own requirements in its April 2026 update (version 3.3, known as the ‘Danzell’ question set) to adjust to the growing concerns of IT security, with a heavy emphasis on preventative action and stricter non-negotiables. The National Cyber Security Centre (NCSC) endorses Cyber Essentials as the minimum standard for digital health security, and regardless of the expectation for businesses to obtain this certification when looking to get a foot in the door with the NHS, it’s simply good practice to assure the security of your company, assets and data to the highest possible standard.
Looking to dive deeper? Take a look at our guide that breaks down the need of Cyber Essentials and Cyber Essentials Plus
So, what has changed?
Mandatory MFA: Multi-factor authentication as Standard
One of the most notable changes is the now mandatory requirement for multi-factor authentication (MFA) to be applied for all cloud services. This must be implemented, where available, regardless of the means; whether it’s included in the cloud service or deployed through another provider, free or by a payable fee. This change places a heavy emphasis on the essential need for MFA when it comes to the security of your devices, particularly as the use of cloud services within businesses continues to increase.
Why is this important?
Cloud services are a primary target for attackers to gain access to business-critical systems or information, and adding multi-factor authentication for an extra layer of protection can prevent the exposure of personal and sensitive data. Failure to comply with this requirement will prevent an organisation from passing the Cyber Essentials certification, so it’s important to double-check implementation across the entire business.
What counts as a ‘Cloud Service’ under Cyber Essentials?
The definition of what a cloud service is has also been included, removing the ambiguity over what should and should not be in scope. This ensures all cloud services that store or process any company data have been securely configured with the aforementioned MFA requirement.
User Access Control: Passkeys Now the NCSC’s Preferred Default
Updates to the User Access Control section highlight the importance of both passwordless and multi-factor authentication, with Passkeys (a password-free, highly secure alternative for login authentication) being the recommended, preferred default from the National Cyber Security Centre (NCSC). With the current climate of identity-driven attacks, protecting logins is a key requirement for protecting your business from a cyber attack.
Cyber Essentials Scope: What counts as an inbound or outbound connection?
There have been amendments to terminology for inbound and outbound internet connections, with the scoping criteria removing terms such as ‘untrusted’ and ‘user-initiated’. As with the newly provided cloud service definition, this removes any ambiguity and clearly defines the parameters that any device able to connect to the internet, regardless of inbound or outbound capabilities, will be counted as within scope for the certification.
Alongside this, suppliers now need to explain networks excluded from scope to confirm what parts of the business infrastructure are being excluded, and justification as to why and how they are separated from the other networks.
The New 14-Day Patch Window for High-Risk Updates
All high and critical security risk updates must now be installed within a 14-day patch window, with no exception. Similarly to the new MFA requirement, failure to comply will result in failure of the Cyber Essentials certification. Cyber criminals actively monitor patch releases and move quickly. Each day a vulnerability goes unaddressed, it provides an opportunity for hackers to exploit the known weaknesses and gain access to your company’s data.
The Case for MDM
With the 14-day patch rule comes the challenge of asking hundreds of employees to manually update their devices. An excellent way to combat this is to invest in Mobile Device Management (MDM). MDM is a centralised management system for company devices – from laptops and desktops, to tablets and mobiles – which allows IT teams to remotely handle device updates and configuration, application downloads and other maintenance and protection capabilities. With MDM, patches can be managed remotely from one core place by the relevant IT professional, negating the need to chase down individual employees.
Cyber Essentials Application Development Changes: The Software Security Code of Practice Explained
Finally, there has been a minor adjustment to the Web Applications section, renaming this to ‘Application Development’, which aligns Cyber Essentials with the UK Government’s Software Security Code of Practice, launched in May 2025. This voluntary framework, published by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), is an encouragement to go a step beyond, to raise the baseline of software security in businesses and better protect supply chains against attacks.
The framework focuses on several principles across four core themes that cover design and development, build environment security, deployment and maintenance, and customer communication, provoking proactive security and avoiding a retrospective or reactive strategy. If you’re not already considering your approach to technical security throughout your product’s life cycle, then it’s past time to review this.
What's changed in Cyber Essentials Plus certification?
With changes to the Cyber Essentials certification, it only stands to reason that there have also been some changes to the Cyber Essentials Plus certification. The most significant of these amendments is that businesses can no longer choose specific users to present their devices for audit. The audit sample will be selected at random from an available pool provided by the company, with confirmation of the nominated devices now provided only 72 hours before the audit date.
Should the company fail the audit and a second is needed, a new random sample will be chosen, rather than re-using the original sample. This removes the ability for businesses to ‘cherry pick’ devices for audit, and guarantees that all remediation work is carried out company-wide, not just to a select few devices.
Summary
It’s more important than ever to consider the depth of your technical security from all corners of your business. The changes brought in for this year’s Cyber Essentials submission are paramount for providing your business and those within your supply chain with the assurance of good cyber security.
Cybercrime is an ever-increasing threat, rising at an alarming rate of around 10% a year, with the Healthcare sector one of the most frequent targets. This only begs the question of not if your company will experience an attempted attack, but when.
The better the controls in place to mitigate these risks, the more prepared your company can be to prevent these attacks from coming to fruition. Cybersecurity is no longer just about ticking a box and forgetting about it until next year; it’s an ongoing, vital process in day-to-day operations. Committing to stricter technical controls and preventative measures isn’t just good business; it’s good governance.