The Cyber Essentials scheme has been through its most significant update in years, with a revised set of requirements taking effect in April 2026. Cyber Essentials remains the UK Government-backed baseline for good cyber hygiene, and it is increasingly a condition of winning contracts, securing cyber insurance and satisfying funders. If your certification is due for renewal, the bar has moved — and in several places it has moved considerably.

Here is a plain-English summary of what has changed, and what each change means in practice.

1. Multi-factor authentication is now mandatory for cloud services

MFA is no longer a recommendation. Where a cloud service offers it — including everyday platforms such as Microsoft 365 and Google Workspace, and even where MFA sits behind a paid or upgraded tier — it must be enabled for every user and every administrator. Failing to do so now results in an automatic assessment failure. Relying on trusted or allowed IP address lists in place of proper user and device MFA no longer counts as compliant.

2. Scoping is stricter and clearer

Ambiguous terms such as “untrusted” and “user-initiated” have been removed to close loopholes. In practice, any internet-connected device or service that sends, receives or controls the flow of data is in scope by default — and that explicitly includes smartphones, laptops and home-working routers. If you want to exclude part of your estate, you now need a documented justification and evidence of proper network segregation. “It’s out of scope” is no longer something you can simply assert.

3. Cloud and web applications cannot be sidestepped

Cloud environments can no longer be excluded from an assessment, and publicly available commercial web applications are in scope by default. Where you develop your own applications, the rules now align with the UK Software Security Code of Practice — a clear signal that secure development is part of the baseline, not an optional extra.

4. Passwordless is encouraged, and backups matter more

The framework now actively encourages modern, passwordless methods such as biometrics and hardware security keys, reflecting the direction of travel across the industry. Alongside this, there is a heavier emphasis on holding reliable, tested recovery backups — not simply having a backup, but being able to prove that it restores.

5. Cyber Essentials Plus testing has tightened

For the hands-on Cyber Essentials Plus assessment, validation is stricter. Organisations can no longer alter their self-assessment answers once technical testing has begun, and any patching remediation must be applied across the whole environment — not just to the sample of devices the assessor happens to test. In short, you can no longer patch to pass.

What this means for you

None of these changes are unreasonable; they reflect how organisations actually work in 2026, with cloud services, mobile devices and home working now the norm rather than the exception. They do, however, mean that certification is harder to scrape through at the last minute. If you are due to renew, the worst time to discover a gap is the week of your assessment.

The sensible approach is to review your scope now, switch on MFA everywhere it is available, confirm that your backups genuinely restore, and address patching across every device rather than a chosen few. Get those fundamentals right and Cyber Essentials becomes a formality rather than a scramble.

Foresight helps organisations across Greater Manchester and the wider UK prepare for and pass Cyber Essentials and Cyber Essentials Plus — from an initial readiness review through to remediation and certification. If you would like to understand where you stand against the 2026 requirements, our team would be glad to help.