Skip to content
8foldgovernance master
  • Services
    • AI Governance
    • Medical Devices
      • Regulatory Roadmap
      • ISO 13485 Design & Build your QMS
      • Quality Management as a Service
      • Technical File Creation & Registration
      • UK Responsible Person
      • Post Market Surveillance
    • International Standards
      • ISO 13485 Certification
      • ISO 42001 Certification
      • ISO 9001 Certification
      • ISO 27001 Certification
    • DTAC
      • DTAC Management
    • Information Governance
      • Data Security & Protection (DSPT)
      • DSPT Audit
      • HIPAA Compliance
    • Clinical Safety and Risk Management
      • DCB0129
      • DCB0160
      • Clinical Safety Officers (CSO)
    • CQC Services
      • CQC Compliance Assessment
      • CQC Registration Support
      • CQC-as-a-Service
      • CQC Regulatory Review & Strategy
    • Cyber Security
    • Governance, Risk & Compliance Advisory
    • 8foldTraining
  • About
    • Meet the Team
    • Partnerships
    • Join Us
  • Blog
  • Case Studies
  • Contact
  • Services
    • AI Governance
    • Medical Devices
      • Regulatory Roadmap
      • ISO 13485 Design & Build your QMS
      • Quality Management as a Service
      • Technical File Creation & Registration
      • UK Responsible Person
      • Post Market Surveillance
    • International Standards
      • ISO 13485 Certification
      • ISO 42001 Certification
      • ISO 9001 Certification
      • ISO 27001 Certification
    • DTAC
      • DTAC Management
    • Information Governance
      • Data Security & Protection (DSPT)
      • DSPT Audit
      • HIPAA Compliance
    • Clinical Safety and Risk Management
      • DCB0129
      • DCB0160
      • Clinical Safety Officers (CSO)
    • CQC Services
      • CQC Compliance Assessment
      • CQC Registration Support
      • CQC-as-a-Service
      • CQC Regulatory Review & Strategy
    • Cyber Security
    • Governance, Risk & Compliance Advisory
    • 8foldTraining
  • About
    • Meet the Team
    • Partnerships
    • Join Us
  • Blog
  • Case Studies
  • Contact
  • +44 (0)1273 569172
Book a Call

Home - Blog - Cyber Security

Cyber Essentials April 2026 Update: Why MFA and Patch Failures Are Now Automatic Fails

  • Published: August 10, 2026
  • Category: Cyber Security

Share this post

Avatar photo
Annie Marsh

Share this post

The cyber threat landscape has changed significantly over the last couple of years, evolving rapidly at a rate that can seem daunting and convoluted. Expectations across sectors continue to expand concerning companies’ technical security controls and the protection of their data, moving on from the general acceptance of ‘the bare minimum ’ to paving the way for proactive, comprehensive security measures. Reflecting this higher standard, the Cyber Essentials certification scheme has introduced two key changes which now carry an automatic fail status from 27th April 2026 onward.

Cyber Essentials, a UK government-backed certification designed to safeguard your organisation’s and customers’ data against cyber attacks, has updated its own requirements in its April 2026 update (version 3.3, known as the ‘Danzell’ question set) to adjust to the growing concerns of IT security, with a heavy emphasis on preventative action and stricter non-negotiables. The National Cyber Security Centre (NCSC) endorses Cyber Essentials as the minimum standard for digital health security, and regardless of the expectation for businesses to obtain this certification when looking to get a foot in the door with the NHS, it’s simply good practice to assure the security of your company, assets and data to the highest possible standard.

Looking to dive deeper? Take a look at our guide that breaks down the need of Cyber Essentials and Cyber Essentials Plus

multi-factor authentication (MFA) Cyber Essentials April 2026 Update: Why MFA and Patch Failures Are Now Automatic Fails multi-factor authentication (MFA),patch management,14-day patch window,NCSC,passkeys,Mobile Device Management (MDM),Software Security Code of Practice,UK cyber security certification,IT compliance,cloud security

So, what has changed?

Mandatory MFA: Multi-factor authentication as Standard

One of the most notable changes is the now mandatory requirement for multi-factor authentication (MFA) to be applied for all cloud services. This must be implemented, where available, regardless of the means; whether it’s included in the cloud service or deployed through another provider, free or by a payable fee. This change places a heavy emphasis on the essential need for MFA when it comes to the security of your devices, particularly as the use of cloud services within businesses continues to increase.

Why is this important?

Cloud services are a primary target for attackers to gain access to business-critical systems or information, and adding multi-factor authentication for an extra layer of protection can prevent the exposure of personal and sensitive data. Failure to comply with this requirement will prevent an organisation from passing the Cyber Essentials certification, so it’s important to double-check implementation across the entire business.

What counts as a ‘Cloud Service’ under Cyber Essentials?

The definition of what a cloud service is has also been included, removing the ambiguity over what should and should not be in scope. This ensures all cloud services that store or process any company data have been securely configured with the aforementioned MFA requirement.

User Access Control: Passkeys Now the NCSC’s Preferred Default

Updates to the User Access Control section highlight the importance of both passwordless and multi-factor authentication, with Passkeys (a password-free, highly secure alternative for login authentication) being the recommended, preferred default from the National Cyber Security Centre (NCSC). With the current climate of identity-driven attacks, protecting logins is a key requirement for protecting your business from a cyber attack.

Cyber Essentials Scope: What counts as an inbound or outbound connection?

There have been amendments to terminology for inbound and outbound internet connections, with the scoping criteria removing terms such as ‘untrusted’ and ‘user-initiated’. As with the newly provided cloud service definition, this removes any ambiguity and clearly defines the parameters that any device able to connect to the internet, regardless of inbound or outbound capabilities, will be counted as within scope for the certification.

Alongside this, suppliers now need to explain networks excluded from scope to confirm what parts of the business infrastructure are being excluded, and justification as to why and how they are separated from the other networks.

The New 14-Day Patch Window for High-Risk Updates

All high and critical security risk updates must now be installed within a 14-day patch window, with no exception. Similarly to the new MFA requirement, failure to comply will result in failure of the Cyber Essentials certification. Cyber criminals actively monitor patch releases and move quickly. Each day a vulnerability goes unaddressed, it provides an opportunity for hackers to exploit the known weaknesses and gain access to your company’s data.

The Case for MDM

With the 14-day patch rule comes the challenge of asking hundreds of employees to manually update their devices. An excellent way to combat this is to invest in Mobile Device Management (MDM). MDM is a centralised management system for company devices – from laptops and desktops, to tablets and mobiles – which allows IT teams to remotely handle device updates and configuration, application downloads and other maintenance and protection capabilities. With MDM, patches can be managed remotely from one core place by the relevant IT professional, negating the need to chase down individual employees.

Cyber Essentials Application Development Changes: The Software Security Code of Practice Explained

Finally, there has been a minor adjustment to the Web Applications section, renaming this to ‘Application Development’, which aligns Cyber Essentials with the UK Government’s Software Security Code of Practice, launched in May 2025. This voluntary framework, published by the Department for Science, Innovation and Technology (DSIT) and the National Cyber Security Centre (NCSC), is an encouragement to go a step beyond, to raise the baseline of software security in businesses and better protect supply chains against attacks. 

The framework focuses on several principles across four core themes that cover design and development, build environment security, deployment and maintenance, and customer communication, provoking proactive security and avoiding a retrospective or reactive strategy. If you’re not already considering your approach to technical security throughout your product’s life cycle, then it’s past time to review this. 

What's changed in Cyber Essentials Plus certification?

With changes to the Cyber Essentials certification, it only stands to reason that there have also been some changes to the Cyber Essentials Plus certification. The most significant of these amendments is that businesses can no longer choose specific users to present their devices for audit. The audit sample will be selected at random from an available pool provided by the company, with confirmation of the nominated devices now provided only 72 hours before the audit date. 

Should the company fail the audit and a second is needed, a new random sample will be chosen, rather than re-using the original sample. This removes the ability for businesses to ‘cherry pick’ devices for audit, and guarantees that all remediation work is carried out company-wide, not just to a select few devices.

Summary

It’s more important than ever to consider the depth of your technical security from all corners of your business. The changes brought in for this year’s Cyber Essentials submission are paramount for providing your business and those within your supply chain with the assurance of good cyber security. 

Cybercrime is an ever-increasing threat, rising at an alarming rate of around 10% a year, with the Healthcare sector one of the most frequent targets. This only begs the question of not if your company will experience an attempted attack, but when. 

The better the controls in place to mitigate these risks, the more prepared your company can be to prevent these attacks from coming to fruition. Cybersecurity is no longer just about ticking a box and forgetting about it until next year; it’s an ongoing, vital process in day-to-day operations. Committing to stricter technical controls and preventative measures isn’t just good business; it’s good governance. 

Ready to upgrade to Cyber Essentials Plus?

Speak to a member of our CyberSecurity team about how we can manage your Cyber Essentials certification and annual audit requirements.
Get in touch.

Other Articles​

Loading...
Blog post: How I learnt to keep worrying, but embrace Google Gemini anyway

How I learnt to keep worrying, but embrace Google Gemini anyway

Read More →

July 15, 2026
Cybersecurity: The Vanguard of Patient Safety in Healthcare

Cybersecurity: The Vanguard of Patient Safety in Healthcare

Read More →

May 18, 2026
Compliance with the NHS Cyber Security Charter Explained

The Evidence Era: Compliance with the NHS Cyber Security Charter

Read More →

April 1, 2026
8foldgovernance master

+44 (0) 1273 569172

info@8foldgovernance.com

SERVICES

  • AI Governance
  • Medical Device Registration
  • ISO Compliance
  • Full DTAC Support
  • Information Governance
  • Clinical Safety
  • Data Security & Protection
  • CQC Services
  • Cyber Security
  • 8foldTraining

LINKS

  • Contact
  • About
  • Meet The Team
  • Blog
  • Join Us
  • Case Studies
  • Charity Work
  • Partnerships
  • FAQs
DSPT Data Security And protection Toolkit 8Fold
Information Governance Badge 8 Fold
NPSORE
ABHI Member
Cyber Essentials Plus certification badge

 © 2026 8fold | Privacy Policy | Cookie Policy | Terms & Conditions

X We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies. However you may visit Cookie Settings to provide a controlled consent.
Read More ACCEPT Cookie settings
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
Save & Accept