Last updated: 3 October 2026
Short answer: from 27 April 2026, the new Cyber Essentials question set (Danzell, version 3.3) treats missing multi-factor authentication on cloud services and late patching of critical or high-risk updates as an automatic fail. Check both before you apply or renew.
What has changed in Cyber Essentials from April 2026?
The five technical controls are the same: firewalls, secure configuration, user access control, malware protection and security update management. What has changed is how strictly two of them are marked, plus some tightening of scope and testing.
| Area | What is now expected | What to do |
|---|---|---|
| Multi-factor authentication | Required on all cloud services (SaaS, IaaS and PaaS). If a service offers MFA and you have not enabled it, you fail. | List every cloud service, then switch on MFA for every account, admins first. |
| Patching | Critical and high-risk updates installed within 14 days. Missing the deadline is now an automatic fail. | Automate updates for Windows, Mac, apps, routers and firewall firmware, and keep proof. |
| Cloud definition | Cloud means on-demand, scalable services on shared infrastructure, reached over the internet. | Check that Microsoft 365, accounting and CRM apps are all on your list. |
| Scope | Describe your scope in full, name each legal entity and justify any exclusion. | Write the scope down before you start the questionnaire. |
| Cyber Essentials Plus | Assessors can test new random samples, and your self-assessment answers are locked during testing. | Make sure every device in scope is patched, not just a sample. |
Does the change affect my existing certificate?
Assessments taken after the change are marked against the new requirements, so treat your next renewal as the first test. Ask your certification body or IT provider how your renewal date is handled, and leave time to fix gaps before it.
How do I get ready for the new rules?
- List your cloud servicesMicrosoft 365, Google Workspace, accounting, CRM, file sharing and anything staff log in to with a work email.
- Turn on MFA everywhereUse the authenticator app option where you can, and protect admin accounts first.
- Fix your patchingSet automatic updates and check that devices have restarted. Retire anything that can no longer be updated.
- Write your scopeName the company, its sites, the devices and the cloud services you are including.
- Run a readiness checkTest yourself before the assessor does, so you can fix gaps first.
Can ABCOM help us pass?
Yes. ABCOM is an NCSC Assured Service Provider and a Cyber Advisor (Cyber Essentials). We check you against the latest requirements, fix any gaps and guide you through assessment. Start with our free Cyber Essentials readiness quiz or read about our Cyber Essentials service.
Sources and further reading
Want this looked after for you?
ABCOM has supported Sussex businesses and charities since 1996 and is an NCSC Assured Service Provider – Cyber Advisor (Cyber Essentials). Talk to a real person about your IT.
Also read
How ABCOM can help
Talk to a real person at our Burgess Hill office. We are an NCSC Assured Service Provider and have supported Sussex businesses since 1996.