Cyber Essentials Changes Infographic - Tech Service Partner

Cyber Essentials 2026 Updates: What Organisations Need to Know

The Cyber Essentials scheme is updated each year to ensure organisations remain protected against evolving cyber threats. While the scheme’s five core security controls remain unchanged, the April 2026 updates introduce important changes designed to strengthen security practices and improve the certification process.

The updates were developed through collaboration between the National Cyber Security Centre and IASME Consortium following feedback from organisations, assessors, and cyber incident investigations.

The new requirements will apply to all Cyber Essentials assessment accounts created after 26 April 2026. Organisations that began their assessment before this date will have six months to complete certification under the previous requirements.

Stronger Cyber Security Requirements for Business

One of the most significant updates is the introduction of stricter marking criteria for key cybersecurity practices.

Multi-Factor Authentication (MFA) will now be mandatory for all cloud services that support it. If MFA is not enabled, whether it is free, included with the service, or available as a paid option, the organisation will automatically fail the Cyber Essentials assessment. This change reflects the important role MFA plays in protecting against phishing attacks and compromised credentials.

The scheme also introduces new auto-fail requirements for patch management. Organisations must ensure that high-risk or critical security updates are installed within 14 days of release. This applies to operating systems, router and firewall firmware, applications, and associated components. Delayed patching is one of the most common causes of cyber incidents, so this update reinforces the importance of timely updates.

Improved Cyber Essentials Certification Transparency

The 2026 updates also improve how organisations define the scope of their Cyber Essentials certification.

Organisations will now be able to provide more detailed scope descriptions, accessible via the digital certificate platform. They must also identify any systems excluded from scope and explain how those systems are segregated from certified infrastructure.

In addition, organisations must list all legal entities included in the certification, including company name, address, and company number. Separate certificates can also be issued for individual legal entities within a larger scope.

Changes to Cyber Essentials Plus

The Cyber Essentials Plus (CE+) assessment has also been strengthened. If an organisation fails the initial update management test during the technical audit, a retest will include both the original devices and a new random sample to confirm updates are applied across the entire environment.

Organisations will also no longer be able to modify their Verified Self-Assessment responses once CE+ testing has started, ensuring the integrity of the certification process.

Preparing for the Cyber Essentials Updates

Organisations planning to achieve or renew Cyber Essentials certification should review their security controls now. Enabling MFA, implementing effective patch management, and clearly defining the certification scope will help ensure a smoother assessment process while improving protection against modern cyber threats.

Ready for the April 2026 Cyber Essentials Changes?

The standards have shifted — and the gap between “we think we’re covered” and actually passing has just got wider.

If you’re unsure whether your business would pass under the new rules, now is the time to find out, before an audit, tender, or client requirement forces the issue.

Start with a quick, no-pressure check.
See where you stand, spot the gaps, and get clear, practical next steps.

👉 Take the Quick Cyber Readiness Assessment

Or, if you’d rather talk it through and get straight answers:

👉 Book a 30 minute Cyber Essentials Readiness Review
In just 30 minutes, our MD Carl will sense-check your setup, flag any risks around MFA, patching, and scope, and show you exactly what needs tightening.

You’ll leave with a clear action plan — no jargon, no hard sell, just practical guidance you can act on immediately.

Secure your slot now and move forward with confidence.