Cyber Essentials changes from April 2026: What this means for SMEs

13th March 2026

Cyber Essentials V3.3 1

Cyber Essentials is undergoing one of its most significant updates from 27th April 2026. These changes are designed to reflect how modern organisations operate, with greater use of cloud services, remote working and hybrid IT environments. For SMEs, the updates raises the bar but it also provides a clearer framework for improving cyber resilience and reducing risk more effectively.

The April 2026 update introduces requirements for IT Infrastructure v3.3, delivered through the new Danzell question set. All assessment accounts created on or after 27th April 2026 will be assessed against v3.3. Organisations with an assessment account created before that date may continue under the previous version for up to six months, provided the account remains active.

What’s changing in Cyber Essentials from April 2026

The five technical controls remain the same, but the expectations behind them are becoming stricter, clearer and more evidence‑based.

Key changes include:

Multi-Factor Authentication (MFA) is now mandatory

If a system or cloud service supports MFA, it must be enabled for all users, not just administrators or privileged accounts. Failure to enable MFA where it is available is now an automatic fail. Previously, MFA gaps might have been raised as observations; under v3.3 this shifts from best practice to a hard requirement.

It’s also important to note that if MFA is available in any form, including as a paid or optional feature, it is considered available and must be enabled to meet the requirements.

Stronger enforcement of patching timelines

High‑risk and critical security updates must be applied within 14 days of release. While this requirement already existed, v3.3 introduces much stricter marking. If you cannot evidence that updates are consistently applied within 14 days, the assessment will fail.

Cloud services are fully in scope

Any cloud, SaaS, or identity platform that stores or processes organisational data and is accessed using a work or business account must now be included in the assessment scope. Cloud services can no longer be excluded.

This includes (but is not limited to):

  • Microsoft 365
  • Azure, AWS, Google Cloud
  • Google Workspace
  • Cloud‑hosted CRM, finance, HR and collaboration platforms
  • Social media and other business‑critical cloud services

Organisations must also demonstrate an understanding of the shared responsibility model, including what security controls are managed by the provider and what must be configured and maintained by the organisation.

Stricter scoping and accountability

Stricter scoping applies throughout the certification process. Under the v3.3 (Danzell) update, any device or system that connects to the internet and accesses organisational data or services is expected to be in scope, unless exclusions can be clearly justified.

This includes:

  • Remote and home‑working devices
  • Contractor or third‑party equipment
  • BYOD (Bring Your Own Device)
  • Occasional or unmanaged devices that access work systems

The same principle applies across all legal entities included in the certification.

Organisations must now:

  • Clearly define what is in scope
  • Explain and justify any exclusions
  • Declare all legal entities included in the certification

This clarity reduces ambiguity for both the assessor and the organisation and improves confidence in what the certification fully covers.

Additional changes for Cyber Essentials Plus

Cyber Essentials Plus assessments are also being tightened. If a device fails patching checks during the initial random sample, assessors must now test a second random sample. This ensures patching is consistently applied across the estate rather than to a small subset of devices.

If the second sample also fails:

  • The Cyber Essentials Plus assessment fails
  • The Cyber Essentials (Level 1) certificate is revoked
  • The organisation must restart the certification process

There is no mandatory cool‑down period, but this can result in additional time, cost, and operational disruption.

There is also an important sequencing change: once technical testing begins, self‑assessment responses cannot be changed, reinforcing the need to be fully prepared before assessment starts.

What SMEs can do now

Enable MFA everywhere

This is the most common cause of automatic failure and often the quickest fix. Pay close attention to overlooked account types such as service accounts, shared mailboxes, administrator accounts, and legacy integrations.

Review cloud configuration (especially M365)

Check access controls, admin roles, conditional access, device compliance, and backup settings. Do not assume default cloud or SaaS configurations are sufficient. Even where the provider secures the platform, you remain responsible for how it is configured and used.

Maintain an accurate asset register

You must be able to identify every device, user, and cloud service that falls within scope, including occasionally used or personal devices.

Strengthen patching processes

Automate updates wherever possible and ensure patching applies across the entire estate, not just a subset of devices. Network segmentation alone does not remove patching obligations for in‑scope systems.

Treat Cyber Essentials as a continuous process

Cyber Essentials is no longer a “once‑a‑year” exercise. Policies, configurations, and technical controls should be monitored and reviewed throughout the year.

How Digital Origin can help

Digital Origin supports SMEs throughout the entire Cyber Essentials and Cyber Essentials Plus journey, from gap analysis to successful certification.

We can help you:

  • Assess Cyber Essentials and Cyber Essentials Plus readiness
  • Secure and optimise Microsoft 365 and cloud environments
  • Implement MFA, conditional access, and device compliance
  • Automate patching and monitoring
  • Prepare clean, assessor‑ready evidence
  • Manage Cyber Essentials Plus testing with confidence

Whether you are renewing in 2026 or certifying for the first time, we help you stay compliant and secure with minimal disruption to your business.

Key takeaways at a glance

  • MFA everywhere – mandatory
  • Cloud services – always in scope
  • Patch within 14 days – automatic fail if missed
  • Continuous compliance – not an annual task
  • Review your controls – especially around BYOD and cloud
  • Scoping must be clear, justified and defensible

You can read the full requirements for IT Infrastructure v3.3 via the NCSC website here:

Cyber Essentials Requirements for IT Infrastructure v3.3

star light 30
Call Us
Email Us
Connect With Us

Follow Us On:   LinkedIn Icon Pink

Similar posts