Cyber Essentials changes from April 2026: What this means for SMEs
13th March 2026

Cyber Essentials is undergoing one of its most significant updates from 27th April 2026. These changes are designed to reflect how modern organisations operate, with greater use of cloud services, remote working and hybrid IT environments. For SMEs, the updates raises the bar but it also provides a clearer framework for improving cyber resilience and reducing risk more effectively.
The April 2026 update introduces requirements for IT Infrastructure v3.3, delivered through the new Danzell question set. All assessment accounts created on or after 27th April 2026 will be assessed against v3.3. Organisations with an assessment account created before that date may continue under the previous version for up to six months, provided the account remains active.
What’s changing in Cyber Essentials from April 2026
The five technical controls remain the same, but the expectations behind them are becoming stricter, clearer and more evidence‑based.
Key changes include:
Multi-Factor Authentication (MFA) is now mandatory
If a system or cloud service supports MFA, it must be enabled for all users, not just administrators or privileged accounts. Failure to enable MFA where it is available is now an automatic fail. Previously, MFA gaps might have been raised as observations; under v3.3 this shifts from best practice to a hard requirement.
It’s also important to note that if MFA is available in any form, including as a paid or optional feature, it is considered available and must be enabled to meet the requirements.
Stronger enforcement of patching timelines
High‑risk and critical security updates must be applied within 14 days of release. While this requirement already existed, v3.3 introduces much stricter marking. If you cannot evidence that updates are consistently applied within 14 days, the assessment will fail.
Cloud services are fully in scope
Any cloud, SaaS, or identity platform that stores or processes organisational data and is accessed using a work or business account must now be included in the assessment scope. Cloud services can no longer be excluded.
This includes (but is not limited to):
- Microsoft 365
- Azure, AWS, Google Cloud
- Google Workspace
- Cloud‑hosted CRM, finance, HR and collaboration platforms
- Social media and other business‑critical cloud services
Organisations must also demonstrate an understanding of the shared responsibility model, including what security controls are managed by the provider and what must be configured and maintained by the organisation.
Stricter scoping and accountability
Stricter scoping applies throughout the certification process. Under the v3.3 (Danzell) update, any device or system that connects to the internet and accesses organisational data or services is expected to be in scope, unless exclusions can be clearly justified.
This includes:
- Remote and home‑working devices
- Contractor or third‑party equipment
- BYOD (Bring Your Own Device)
- Occasional or unmanaged devices that access work systems
The same principle applies across all legal entities included in the certification.
Organisations must now:
- Clearly define what is in scope
- Explain and justify any exclusions
- Declare all legal entities included in the certification
This clarity reduces ambiguity for both the assessor and the organisation and improves confidence in what the certification fully covers.
Additional changes for Cyber Essentials Plus
Cyber Essentials Plus assessments are also being tightened. If a device fails patching checks during the initial random sample, assessors must now test a second random sample. This ensures patching is consistently applied across the estate rather than to a small subset of devices.
If the second sample also fails:
- The Cyber Essentials Plus assessment fails
- The Cyber Essentials (Level 1) certificate is revoked
- The organisation must restart the certification process
There is no mandatory cool‑down period, but this can result in additional time, cost, and operational disruption.
There is also an important sequencing change: once technical testing begins, self‑assessment responses cannot be changed, reinforcing the need to be fully prepared before assessment starts.
What SMEs can do now
Enable MFA everywhere
This is the most common cause of automatic failure and often the quickest fix. Pay close attention to overlooked account types such as service accounts, shared mailboxes, administrator accounts, and legacy integrations.
Review cloud configuration (especially M365)
Check access controls, admin roles, conditional access, device compliance, and backup settings. Do not assume default cloud or SaaS configurations are sufficient. Even where the provider secures the platform, you remain responsible for how it is configured and used.
Maintain an accurate asset register
You must be able to identify every device, user, and cloud service that falls within scope, including occasionally used or personal devices.
Strengthen patching processes
Automate updates wherever possible and ensure patching applies across the entire estate, not just a subset of devices. Network segmentation alone does not remove patching obligations for in‑scope systems.
Treat Cyber Essentials as a continuous process
Cyber Essentials is no longer a “once‑a‑year” exercise. Policies, configurations, and technical controls should be monitored and reviewed throughout the year.
How Digital Origin can help
Digital Origin supports SMEs throughout the entire Cyber Essentials and Cyber Essentials Plus journey, from gap analysis to successful certification.
We can help you:
- Assess Cyber Essentials and Cyber Essentials Plus readiness
- Secure and optimise Microsoft 365 and cloud environments
- Implement MFA, conditional access, and device compliance
- Automate patching and monitoring
- Prepare clean, assessor‑ready evidence
- Manage Cyber Essentials Plus testing with confidence
Whether you are renewing in 2026 or certifying for the first time, we help you stay compliant and secure with minimal disruption to your business.
Key takeaways at a glance
- MFA everywhere – mandatory
- Cloud services – always in scope
- Patch within 14 days – automatic fail if missed
- Continuous compliance – not an annual task
- Review your controls – especially around BYOD and cloud
- Scoping must be clear, justified and defensible
You can read the full requirements for IT Infrastructure v3.3 via the NCSC website here:











