Cyber Essentials Willow: What you Need to Know

The Cyber Essentials scheme is changing again. From 28th April 2025, a new version – Cyber Essentials Willow – will replace the current Montpellier version. If you’re planning to apply for Cyber Essentials or Cyber Essentials Plus after this date, here’s what you need to know.

Why is there an update?

The National Cyber Security Centre (NCSC) and IASME regularly review and update the Cyber Essentials scheme to keep pace with evolving cyber threats. The last major update (Montpellier) was in April 2023, so this refresh is timely to reflect new security challenges and best practices.

What’s changing?

This update is more about clarity than major overhauls. Most changes refine the wording, improve definitions, and add useful resources. Here are the key adjustments:

  • Clearer terminology: For example, ‘plugins’ will now be referred to as ‘extensions,’ and ‘home workers’ will be ‘home and remote workers.’
  • Passwordless authentication: This increasingly common method will be formally recognised. It’s now defined alongside multi-factor authentication (MFA) as any method that doesn’t rely on a user’s knowledge (like a password) to verify identity.

Vulnerability fixes: The requirement to apply security updates for high and critical vulnerabilities is expanding. You’ll now need to deploy any vendor-approved fix for a critical or high vulnerability within 14 days – whether it’s a patch, registry tweak, configuration change, or script.

What about Cyber Essentials Plus?

The Cyber Essentials Plus assessment process remains largely the same, but there is one notable tweak. If your assessment scope covers a specific part of your organisation (i.e. a sub-set, and not the entire business), your assessor will need to test that these sub-sets are properly separated.

What should you do next?

If you’re planning to renew or apply for Cyber Essentials or Cyber Essentials Plus after April 2025, it’s a good idea to familiarise yourself with the updated requirements now.

Need help? We’ve got you.

Our team is ready to guide you through the changes and make the process simple. Get in touch at info@evolvenorth.com or call us on 01748 905 002.

Previous ArticleNext Article