Cyber Essentials Requirements 2026: Full Guide

No Data, No Party.

Cyber Essentials requirements have evolved with the introduction of the April 2026 v3.3 question set. New mandatory controls around cloud services, MFA, and patch management mean organisations need to understand what’s changed before starting their assessment.

This guide covers everything you need to know about the Cyber Essentials certification requirements, from the five core security controls to certification tiers, scope, costs, and the latest updates.

What is Cyber Essentials?

Cyber Essentials is a UK government-backed certification scheme developed by the National Cyber Security Centre (NCSC) and delivered through IASME-accredited certification bodies. It provides a baseline set of technical controls that help organisations defend against common cyber threats by reducing exploitable security weaknesses and improving overall cyber resilience.

Most successful cyber attacks exploit basic, preventable weaknesses rather than sophisticated techniques. Cyber Essentials helps organisations address those risks through five essential security controls covering firewalls, secure configuration, user access control, malware protection, and security update management.

Organisations can achieve certification through either Cyber Essentials, a verified self-assessment reviewed by an accredited certification body, or Cyber Essentials Plus, which includes independent technical testing. Both certifications are valid for 12 months and require annual renewal.

The Five Cyber Essentials Technical Controls Explained

These five control areas have defined the scheme since its launch. The v3.3 update sharpens some of the requirements within them, but the structure stays consistent.

1. Firewalls

Every device that connects to the internet needs a firewall configured to block unauthorised inbound connections. This applies at the network boundary and at the device level. Default firewall rules that permit unnecessary inbound traffic must be removed, and any exceptions must be documented and justified.

2. Secure Configuration

Devices and software should be configured to reduce the attack surface from the outset. That means changing default passwords, removing or disabling software and services that aren’t needed, and ensuring accounts are set up with the minimum permissions required. Leaving factory defaults in place is one of the most common reasons organisations fail their assessment.

3. User Access Control

Accounts should be limited to what each user genuinely needs to do their job. Administrative privileges deserve particular attention: they should be tightly controlled, regularly reviewed, and never used for routine tasks like browsing the web or reading email. Separate admin accounts for administrative tasks are expected.

4. Malware Protection

Active, up-to-date anti-malware software is required on devices within scope, or application allowlisting must be in place as an alternative. The key word is “active.” Software that is installed but not running, or running with old definitions, does not meet this requirement.

5. Security Update Management

Software and firmware must be kept current. Under v3.3, high-risk and critical updates must be applied within 14 days of release, and this is now an auto-fail condition. If your organisation can’t demonstrate that critical patches are being applied within that window, the assessment will fail at questions A6.4 and A6.5 regardless of how well everything else is configured.

Cyber Essentials vs Cyber Essentials Plus: Which Certification Is Right for You?

Cyber Essentials and Cyber Essentials Plus are built on the same five technical controls, but they differ in how compliance is verified. Choosing the right certification depends on your organisation’s security requirements, customer expectations, and any contractual obligations.

Cyber Essentials is a verified self-assessment. Your organisation completes the online questionnaire, and an IASME-accredited certification body reviews your responses before issuing certification. It’s the most common option for organisations looking to demonstrate a baseline level of cyber security.

Cyber Essentials Plus includes everything required for Cyber Essentials but goes a step further with an independent technical assessment. Rather than relying solely on your answers, an assessor tests your security controls to verify they are operating effectively in practice.

Cyber Essentials vs Cyber Essentials Plus: Key Differences

Feature Cyber Essentials Cyber Essentials Plus
Assessment Method Verified self-assessment Self-assessment plus technical audit
Who Conducts It Certification body reviews answers Independent auditor tests controls
Starting Cost From £320 +VAT Higher – includes audit fees
Suitable For Most organisations; baseline compliance Higher-value contracts; sensitive data
Government Contract Requirement Required for many central government contracts Required for some higher-value contracts
Verification Depth Questionnaire review Hands-on technical testing

For many organisations, Cyber Essentials provides the level of assurance needed to meet customer requirements and qualify for government contracts. However, organisations working with highly sensitive data, operating in regulated industries, or bidding for contracts that require additional assurance may need Cyber Essentials Plus.

Before choosing a certification level, review any contractual or regulatory requirements that apply to your organisation. Most UK central government contracts require a valid Cyber Essentials certificate, while some higher-value or higher-risk contracts specifically require Cyber Essentials Plus. If you’re unsure which level applies, check your procurement documentation or speak with the contracting authority.

What Changed in the April 2026 v3.3 Update?

The v3.3 update, using the Danzell question set, applies to all assessment accounts created after 26 April 2026. If your account was created before that date, you’ll complete the previous question set. This distinction is important. The trigger is your account creation date, not your certification date.

The changes make the scheme sharper and more aligned with how organisations actually operate today. Four areas are worth your attention.

MFA is Now Mandatory for Cloud Services

Multi-factor authentication (MFA) is now required for all cloud services that support it. This isn’t a recommendation. Failure to enforce MFA on cloud accounts is an automatic fail. Given how many organisations now run significant parts of their operations through cloud platforms, this change addresses a real-world gap that previous versions of the scheme didn’t cover as directly.

14-Day Patching is an Auto-Fail Condition

Questions A6.4 and A6.5 introduce automatic fail conditions for patch management. High-risk and critical updates must be installed within 14 days of release. If your patching cadence runs longer than that, even by a few days, you won’t pass. This is worth reviewing with your IT team or managed service provider before you start your assessment.

Cloud Services Are Fully In Scope

All cloud services that process organisational data are now in scope and cannot be excluded from the assessment. This is a meaningful change for organisations that previously carved out cloud platforms from their certification boundary. If your organisation uses Software as a Service (SaaS) tools, cloud storage, or hosted applications, those services need to meet the same control requirements as your on-premise infrastructure.

Director Declaration Required

A director must now sign a declaration confirming that the organisation will maintain compliance throughout the certification period, not just at the point of assessment. This shifts accountability upward and makes Cyber Essentials a board-level commitment rather than purely an IT exercise.

What's In Scope for Your Assessment?

Your Cyber Essentials assessment scope covers all devices, systems, and software that can access organisational data or internet-facing services. That includes laptops, desktops, servers, mobile devices, and, under v3.3, cloud services that process organisational data.

Defining your certification boundary before you begin the assessment is essential. A common reason organisations run into difficulties is discovering partway through the process that cloud services or unmanaged devices should have been included in scope. Taking the time to complete a scoping exercise before opening the questionnaire can save significant rework and help ensure a smoother certification process.

Why Cyber Essentials Matters Beyond the Certificate

For many organisations, Cyber Essentials is more than a certification—it’s a business requirement. Many UK central government contracts involving sensitive or personal data require suppliers to hold a valid Cyber Essentials certificate, and its importance within supply chain security continues to grow. Cyber insurance providers are also increasingly considering certification status when assessing eligibility and premiums.

The benefits extend beyond compliance. Going through the certification process encourages organisations to review and strengthen their security controls, helping to reduce exposure to common cyber threats. In fact, 85% of Cyber Essentials users say the scheme has improved their understanding of cyber security risks. That makes it a valuable framework for building stronger security practices, not just achieving certification.

How to Get Certified and What It Costs

Cyber Essentials certification starts at £320 +VAT, with pricing based on organisation size in line with NCSC guidance. To become certified, you’ll apply through an IASME-accredited certification body and complete the online self-assessment questionnaire. If you’re pursuing Cyber Essentials Plus, you’ll first need to pass the self-assessment before moving on to the independent technical audit.

The certification process can take anywhere from a few days to several weeks, depending on how prepared your organisation is before submitting the assessment. Organisations with well-established security controls often complete the process quickly, while those identifying gaps for the first time may need additional time to remediate issues before certification.

Cyber Essentials as the Foundation for Higher-Assurance Environments

Cyber Essentials is the floor, not the ceiling. Organisations in regulated sectors, defence supply chains, or environments where IT and operational technology (OT) networks intersect typically build further controls on top of it. The five-control framework establishes the baseline that more specialised assurance requirements extend.

For organisations managing cross-domain data flows or operating in multi-classification environments, Cyber Essentials certification is where the conversation starts. The controls it requires are necessary but not sufficient for those environments. Get the baseline right, then build upward.

Frequently Asked Questions

What are the Cyber Essentials requirements for 2026?

The five technical controls, firewalls, secure configuration, user access control, malware protection, and security update management, remain the core requirements. The April 2026 v3.3 update adds mandatory MFA for cloud services, 14-day patching as an auto-fail condition, full cloud services scope, and a director compliance declaration.

What changed in Cyber Essentials v3.3?

The Danzell question set, effective for accounts created after 26 April 2026, introduces auto-fail questions A6.4 and A6.5 for patching, mandatory MFA for cloud services, full inclusion of cloud services in scope, and a director sign-off requirement.

How long does Cyber Essentials certification take?

For organisations with controls already in place, the process can complete within days. Where remediation is needed, a few weeks is typical. Cyber Essentials Plus adds time for the independent technical audit stage.

Is Cyber Essentials mandatory for government suppliers?

Most UK central government contracts require suppliers to hold a valid Cyber Essentials certificate, particularly where the contract involves handling sensitive or personal data.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a verified self-assessment reviewed by a certification body. Cyber Essentials Plus adds an independent technical audit where an assessor tests your controls hands-on. Both are valid for 12 months.

How much does Cyber Essentials certification cost in the UK?

Cyber Essentials starts at £320 +VAT, with pricing scaled by organisation size. Cyber Essentials Plus carries additional cost to cover the independent technical audit.

Connecting The Disconnected
Copyright © 4Secure Ltd.
All rights reserved

Company

About
Clients
News
Insights
Privacy Policy

Solutions

Components
Software
Cross-Domain
Solutions
Consulting

Contact

[email protected]
0800 043 0101

Follow us