Cyber Essentials 2026: What's Changed and What You Need to Do

‍ ‍

Cyber Essentials — the UK government-backed security certification — got its biggest update in years this April. If you're certified already, renewing soon, or thinking about getting certified for the first time, a few of the rules have genuinely changed, not just the paperwork.

‍ ‍

What actually changed

‍ ‍

The scheme is reviewed annually by the National Cyber Security Centre (NCSC) and IASME, but the April 2026 update (known as the "Danzell" question set, version 3.3) tightens several areas rather than just clarifying wording:

‍ ‍

●      MFA is now mandatory for all users, not just administrators, on any cloud service that offers it. Miss this and the whole assessment fails automatically, regardless of how strong everything else is.

‍ ‍

●      Patching has a hard deadline. Critical or high-risk security updates must be applied within 14 days of release. Miss the window and, again, it's an automatic fail.

‍ ‍

●      Cloud services can no longer be excluded from scope. Everything your business uses to access or store data now counts.

‍ ‍

●      Minimum password length has increased to 12 characters (up from 8), though where MFA is enforced the rules around this loosen slightly.

‍ ‍

●      Passkeys and security keys are now formally recognised as valid authentication methods.

‍ ‍

●      Certificates will show more detail, including every legal entity the certification actually covers.

‍ ‍

Does this affect you right now?

It depends on timing, not on whether you feel "ready":

‍ ‍

●      If your assessment account was created before 27 April 2026, you can still complete it under the old rules — but only until 27 October 2026. After that, any unfinished assessment has to restart under the new question set.

●      If you're starting fresh or renewing after that date, the new rules apply from day one.

‍ ‍

The most common gap we see

It's rarely the obvious things — firewalls, antivirus — that trip businesses up. It's usually a forgotten cloud tool nobody added MFA to, or a shared login (finance systems and CRMs are common culprits) that slipped through the cracks. Worth doing a quick audit of every cloud service in use before you start your assessment, not just the ones on your original list.

What to do next

If your certification is due for renewal, or you've been putting off getting certified at all, now's a sensible time to get your MFA coverage, patching process, and password policy in order before you start the assessment — not partway through it.

‍ ‍

We help businesses in Rickmansworth and the surrounding area get Cyber Essentials-ready without the stress. Get in touch if you'd like a hand.

Next
Next

Hosting WordPress and security