Update
Following the release of the Cyber Essentials Danzell question set, we’ve written a more detailed description of the changes to Cyber Essentials for 2026.
You can find this here:
Cyber Essentials Danzell – What’s New?
The Cyber Essentials scheme, developed by the National Cyber Security Centre and managed by IASME, is set to receive its next annual update in April 2026.The updated Requirements for IT Infrastructure document (version 3.3) introduces several refinements aimed at improving clarity and consistency. While most changes are minor, there are a few that organisations should be aware of, especially those in the education sector.
This article outlines the key updates and what they mean for small and medium-sized businesses preparing for Cyber Essentials certification.
Key Changes in Cyber Essentials v3.3
Multi-Factor Authentication (MFA) Enforcement
MFA has long been part of the Cyber Essentials framework. However, from April 2026, the marking criteria will change. If a cloud service offers MFA and it is not enabled for all users, the applicant will automatically fail the assessment.
This applies regardless of whether MFA is:
- Free or paid
- Built into the service or added via another tool (e.g. SSO with Microsoft 365)
MFA is a critical control that helps prevent unauthorised access. The updated marking criteria reflect its importance and encourage organisations to implement it wherever available.
Definition of Cloud Services
For the first time, the requirements document includes a formal definition of cloud services.
“A cloud service is an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials a cloud service will be accessed via an account (which may be credentials issued by your organisation, or an email address used for business purposes), and will store or process data for your organisation.
If your organisation’s data or services are hosted on cloud services, these services must be in scope. Cloud services cannot be excluded from scope.”
As with previous versions of Cyber Essentials, cloud services cannot be excluded from the assessment. If your organisation uses them, they must be in scope.
Updated Scoping Criteria
The terms ‘untrusted’ and ‘user-initiated’ have been removed from the scoping definitions to clarify the meaning of ‘internet connected’ devices. Now, any device that connects to the internet is considered in scope, whether it initiates or receives connections. The requirements apply to all devices and software in scope which meet any of the following conditions:
- Can accept incoming network connections from internet-connected devices
- Can establish outbound connections to devices via the internet
- Control the flow of data between any of the above devices and the internet
Additionally, where parts of your infrastructure are excluded, you must:
- Explain what is excluded
- Justify the exclusion
- Explain how it is segregated from the rest of your network
Application Development Guidance
The section previously titled ‘Web Applications’ is now called ‘Application Development’ and now references the UK Government’s Software Security Code of Practice.
Backup Guidance
Backup guidance now appears earlier in the document, highlighting its importance.
Emphasis on Passwordless Authentication
The updated user access control section promotes passwordless authentication methods such as:
- Passkeys (including FIDO2 authenticators)
- Biometric logins
- Security tokens
- One-time codes
These methods offer improved security and user experience compared to traditional passwords. The NCSC recommends adopting passkeys as the default authentication method where possible.
What Does This Mean for Your Organisation?
Evolve North has reviewed the planned changes and our conclusion is that for most small and medium-sized businesses, these changes will not require significant adjustments. The updates are primarily about improving clarity, removing ambiguity, and reinforcing best practices.
However, some organisations, especially those in the education sector, may need to review their MFA implementation to ensure compliance – it is worth highlighting here that IP allowlisting is no longer an accepted form of multifactor authentication.
Looking Ahead
While the 2026 update is relatively minor, there are hints that more substantial changes may be on the way. The repositioning of backup guidance to a more prominent place in the document could be a subtle indication that resilience and recovery will take on greater importance in future versions of the scheme.
We also anticipate that Bring Your Own Device (BYOD) may be reworked in the 2027 update. At present, BYOD can be challenging for many organisations to implement within the Cyber Essentials framework. As remote and hybrid working continue to evolve, clearer expectations around BYOD are likely to become necessary.
Stay Informed
To keep up with the latest developments:
- Visit the IASME website
- Check Evolve North’s Resources page
- Or sign up to our newsletter for updates and guidance
At Evolve North, we do not expect these changes to have a major impact on our existing customers. That said, we are ready to support those who may need to make adjustments, particularly around MFA. As always, we will continue to monitor the scheme and provide timely advice as further updates are announced.
Want to know more? Get in touch with our expert team today at Want to know more? Get in touch with our expert team today at 01748 905 002 or info@evolvenorth.com. We’re here to make Cyber Essentials achievable and to help you stay protected.
