Cyber Essentials April 2026 changes: what your business needs to know
The annual update to the government-backed Cyber Essentials scheme goes live on 27 April 2026. Here's what's changing, and how to get ready.
5-minute read
The government-approved Cyber Essentials scheme centres on five technical controls that protect organisations from the most common cyber attacks. The Requirements for IT Infrastructure document sets out what you need to meet under each control.
As technology advances and threats evolve, those requirements are reviewed each year by experts at the National Cyber Security Centre (NCSC) and IASME so the scheme stays relevant and effective. The next update, Cyber Essentials Requirements for IT Infrastructure v3.3, goes live on 27 April 2026. It applies to all assessment accounts created after that date; any assessment set up beforehand continues under the previous version.
What's changing?
Most of the changes are about clearer definitions and greater consistency, and for most organisations they won't significantly affect compliance. One change stands out, though: multi-factor authentication (MFA) is now enforced more strictly, and failing to implement it where it's available will result in an automatic failure.
MFA is now mandatory: no exceptions
MFA was already required under Cyber Essentials, but the expectation has changed significantly. Where a cloud service has MFA available (whether it's free, included in the service, connected through another service, or offered as a paid option), not implementing it now means an automatic failure.
This underlines how important MFA has become in protecting systems, and it's a shift that could have a substantial impact on compliance for many organisations. We'd strongly recommend reviewing every cloud service your business uses and enabling MFA across the board before the April deadline.
- MFA must be enabled on every cloud service where it is available.
- Not implementing available MFA results in an automatic failure.
- This applies whether MFA is free, bundled, or a paid option.
- FIDO2 authenticators and passkeys count as MFA.
- Review and enable MFA across all services before 27 April.
Cloud services are now clearly defined
For the first time, the requirements include a formal definition of a cloud service: an on-demand, scalable service, hosted on shared infrastructure and accessible via the internet, accessed through an account, that stores or processes data for your organisation. The aim is to remove any ambiguity about whether a particular tool or feature qualifies.
If your organisation's data or services are hosted on cloud services, they are in scope. There is now a definitive statement that cloud services cannot be excluded from scope.
Improved scoping requirements
The scoping criteria have been updated to remove the terms 'untrusted' and 'user-initiated' as qualifiers for internet connections. That simplifies the requirements: any device connected to the internet that meets the criteria is in scope. Where networks are excluded, applicants now need to explain which parts of their infrastructure are excluded, why, and how they've been segregated from other networks.
A device is in scope if it meets any of these conditions:
- It can accept incoming network connections from internet-connected devices.
- It can establish outbound connections to devices via the internet.
- It controls the flow of data between those devices and the internet.
Other notable updates
The 'web applications' section has been renamed 'application development' and now refers to the UK Government's Software Security Code of Practice; publicly available commercial web applications remain in scope by default. Guidance on backups has been moved earlier in the document, immediately after the definitions and before the scope overview, to emphasise how important recovery is after an incident.
The user access control section now places greater emphasis on passwordless authentication and MFA. Passkeys, including FIDO2 authenticators, are highlighted as an easier, faster and more secure way to log in. The NCSC would like passkeys to become the default authentication recommendation.
Key dates
- 27 April 2026: updated Cyber Essentials v3.3 goes live for all new assessment accounts.
- Before 27 April: assessments started earlier continue under the previous version.
- Within six months: applicants have six months from account creation to complete their assessment.
