Cyber Essentials 2026: What Has Changed and How to Prepare

How can businesses prepare for Cyber Essentials 2026?

Businesses preparing for Cyber Essentials certification in 2026 should review the current requirements, confirm that all systems within scope meet the five technical controls and address security gaps before starting the assessment.

The current Cyber Essentials requirements are version 3.3, which came into effect on 27 April 2026. The five technical control areas remain the same, but the 2026 update introduces clearer requirements around areas including cloud services, assessment scope and security update management. The assessment process also places particular importance on MFA availability and timely application of high-risk and critical security updates.

Preparing before the assessment gives organisations an opportunity to identify gaps, confirm their scope and make the necessary changes rather than discovering problems while completing the assessment.

What is Cyber Essentials?

Cyber Essentials is a UK Government-backed certification scheme designed to help organisations protect themselves against common internet-based cyber threats. The scheme was developed by the National Cyber Security Centre (NCSC), with IASME acting as the scheme’s official delivery partner.

The certification is based on five technical controls:

  • Firewalls.
  • Secure configuration.
  • Security update management.
  • User access control.
  • Malware protection.

The scheme is available to organisations of different sizes and can help businesses demonstrate that they have implemented baseline cyber security controls. It is also required by some customers, contracts and procurement processes.

Cyber Essentials certificates are valid for 12 months, so organisations need to recertify annually if they want to maintain certification. However, certification provides assurance based on the assessment at the time of testing, so businesses should not treat the certificate as proof that their security will automatically remain compliant for the entire year.

What has changed in Cyber Essentials 2026?

The current requirements are set out in Cyber Essentials Requirements for IT Infrastructure v3.3, effective from 27 April 2026. The five technical controls have not been replaced, but the updated requirements and assessment approach provide greater clarity in several areas.

The most important areas for businesses preparing for certification include MFA, cloud services, assessment scope and security update management.

MFA requirements are now more significant

One of the most important 2026 changes concerns multi-factor authentication.

IASME states that MFA is mandatory for cloud services where it is available. Failure to implement available MFA on an applicable cloud service results in an automatic failure of the assessment.

Businesses should therefore review cloud services such as:

  • Microsoft 365.
  • Google Workspace.
  • Cloud storage platforms.
  • SaaS applications.
  • Remote access services.
  • Other cloud services that store or process organisational data.

The key point is not simply to enable MFA on administrator accounts. Organisations should review the authentication requirements for the cloud services and accounts that fall within their assessment scope.

NCSC guidance also recommends strong authentication practices for cloud environments, including MFA and appropriate protection of administrator accounts.

Cloud services cannot simply be excluded from scope

The 2026 requirements provide a clearer definition of cloud services and explicitly state that cloud services cannot be excluded from scope when organisational data or services are hosted there.

This is particularly important for businesses using multiple SaaS platforms.

For example, an organisation may have Microsoft 365 managed by its IT team while individual departments also use other cloud applications for CRM, finance, file sharing, communication or project management.

Businesses preparing for certification should maintain an accurate inventory of the cloud services that store or process organisational information and understand how the Cyber Essentials controls apply to each service.

The NCSC also recognises the shared responsibility model for cloud security. Depending on the type of cloud service, responsibility for individual controls may sit with the organisation, the provider or both.

Assessment scope needs to be accurate

Scope is one of the areas where poor preparation can create problems.

The current requirements state that an acceptable Cyber Essentials scope cannot exclude end-user devices. Where organisational data or services are hosted on cloud services, those services must also be included.

Before starting the assessment, organisations should establish:

  • Which legal entity is being certified.
  • Which users and devices are in scope.
  • Which servers, network devices and endpoints are included.
  • Which cloud services process or store organisational data.
  • Whether personally owned devices are used for business purposes.
  • Which third-party or managed services are relevant to the scope.

Accurate asset information is particularly useful because effective asset management supports the implementation of all five technical controls.

Security update management remains a critical requirement

Security update management is one of the five Cyber Essentials controls, and the current v3.3 requirements specify that software in scope must be kept up to date.

High-risk or critical security updates, as well as certain updates where no severity is provided, must be installed within 14 days of release. The requirement applies to relevant software and also covers areas such as operating systems and router and firewall firmware.

IASME has also confirmed that two security-update questions are treated as automatic-fail questions under the updated assessment approach.

Businesses should therefore review their patch management process before starting certification.

This should include:

  • Operating systems.
  • Business applications.
  • Browsers and associated extensions.
  • Routers and firewalls.
  • Network devices.
  • Other software within the assessment scope.

The objective should be to identify security updates quickly, assign responsibility for applying them and maintain a process that can consistently meet the required timescales.

The updated requirements provide greater clarity

It is worth putting the 2026 changes into context.

The NCSC describes Cyber Essentials requirements as being reviewed and updated regularly. Version 3.3 does not replace the five technical control areas. Instead, it updates the requirements and clarifies how they apply to modern IT environments, including cloud services.

For businesses, the practical implication is that certification preparation should focus on understanding how the existing controls apply across the organisation’s current technology environment.

Common preparation issues that can affect certification

Organisations can encounter problems when their security controls do not match the systems they have declared within scope.

Common areas to review include:

  • MFA not enabled on applicable cloud services.
  • High-risk or critical security updates not installed within the required timeframe.
  • Unsupported software remaining in scope.
  • Incomplete device or cloud-service inventories.
  • Excessive user or administrator permissions.
  • Incorrect assessment scope.
  • Inconsistent security configurations.
  • Incomplete understanding of third-party managed systems.

Rather than waiting until the assessment begins, businesses should perform an internal gap review and address these issues beforehand.

How to prepare for Cyber Essentials 2026

A structured preparation process can make the assessment easier to manage.

1. Confirm your assessment scope

Start by identifying the legal entity, users, devices, networks, servers and cloud services that need to be included.

Do not assume that a system is outside scope simply because it is hosted by a third party. Where organisational data or services are hosted in the cloud, the relevant cloud service needs to be considered within the assessment scope.

2. Review MFA coverage

Create an inventory of cloud services and check whether MFA is available and enabled.

Pay particular attention to:

  • Email and productivity platforms.
  • Cloud storage.
  • SaaS applications.
  • Administrator accounts.
  • Remote access services.

If a cloud service provides MFA, confirm that it is actually enabled rather than assuming that the option is available.

3. Review security updates

Check whether your organisation can consistently install applicable high-risk and critical updates within the required 14-day period.

This should cover operating systems, applications and relevant network infrastructure.

Businesses should also identify unsupported software and either remove it, replace it or take the steps required to remove it from scope.

4. Review user access

Check who can access business systems and whether each user’s level of access is appropriate.

Remove unnecessary accounts and permissions, particularly for former employees, contractors and users who have changed roles.

Administrator accounts should receive additional attention because they can provide broader access to business systems.

5. Check secure configuration

Review whether devices and systems have been configured securely.

This includes removing unnecessary services, changing default settings where required, restricting access and ensuring that devices are configured according to the applicable Cyber Essentials requirements.

6. Review malware protection and firewalls

Confirm that appropriate malware protection is operating on relevant devices and that firewall controls are correctly configured.

These remain two of the five Cyber Essentials technical controls and should not be overlooked while preparing for the newer MFA and cloud requirements.

7. Conduct an internal gap assessment

An internal review before certification can help identify issues while there is still time to fix them.

Businesses can compare their current environment against the five technical controls, review their assessment scope and document areas requiring remediation.

Organisations that want to assess their wider security posture can also consider a cyber security risk assessment before beginning the certification process.

Cyber Essentials or Cyber Essentials Plus?

Businesses often ask whether they should pursue Cyber Essentials or Cyber Essentials Plus.

Cyber Essentials uses a verified self-assessment route, with answers signed off by a board member or equivalent and marked by an assessor. Cyber Essentials Plus uses the same five technical controls but adds independent technical testing to verify that the controls are operating effectively in practice.

Cyber Essentials therefore provides baseline assurance through the assessment process, while Cyber Essentials Plus provides an additional level of technical verification.

The appropriate option depends on factors such as customer requirements, contractual obligations, organisational risk and the level of assurance required.

Certification should support ongoing security improvements

Cyber Essentials should not be treated as a checklist that is completed once and forgotten.

Although certification is valid for 12 months, the GOV.UK guidance makes clear that certification provides assurance at the time of testing. An organisation can become non-compliant during the certificate period if it fails to maintain appropriate security controls.

Businesses should therefore continue to:

  • Review user access.
  • Monitor security updates.
  • Remove unsupported software.
  • Review cloud services and configurations.
  • Maintain appropriate MFA.
  • Monitor changes to the IT environment.
  • Update security policies and procedures.
  • Review security risks following significant technology or organisational changes.

Employee awareness should also form part of the wider security programme. Businesses with remote or hybrid teams can review remote work security training to strengthen staff awareness around phishing, data protection and secure working practices.

Frequently asked questions

What are the five Cyber Essentials controls in 2026?

The five technical controls remain firewalls, secure configuration, security update management, user access control and malware protection.

What is the current Cyber Essentials version?

The current NCSC Requirements for IT Infrastructure are version 3.3, effective from 27 April 2026.

Is MFA mandatory for Cyber Essentials?

MFA is mandatory for cloud services where it is available under the updated scheme requirements. IASME states that failing to implement available MFA for applicable cloud services results in an automatic assessment failure.

How quickly must high-risk and critical security updates be installed?

The current requirements require relevant high-risk or critical security updates to be installed within 14 days of release. This also applies in circumstances where the vendor does not provide a vulnerability severity rating, as specified by the requirements.

How long does Cyber Essentials certification last?

Cyber Essentials certification is valid for 12 months, after which organisations need to recertify if they want to maintain a valid certificate.

Can small businesses achieve Cyber Essentials?

Yes. Cyber Essentials is designed for organisations of different sizes and provides a baseline approach to protecting systems against common internet-based threats.

Preparing for Cyber Essentials in 2026

The 2026 Cyber Essentials update does not replace the scheme’s five technical controls. Instead, version 3.3 provides updated requirements and greater clarity for modern environments, with particular attention needed around cloud services, MFA, scope and security update management.

Businesses preparing for certification should start by understanding exactly what is within scope, reviewing MFA across applicable cloud services, checking software support and patching processes, and assessing whether user access and system configurations meet the requirements.

Most importantly, Cyber Essentials should be treated as part of an ongoing security programme rather than an isolated annual exercise. Maintaining the five controls throughout the year helps organisations strengthen their baseline security while remaining better prepared for future certification.