惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
罗磊的独立博客
雷峰网
雷峰网
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
B
Blog RSS Feed
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
D
Docker
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
博客园 - 聂微东
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
小众软件
小众软件
人人都是产品经理
人人都是产品经理
云风的 BLOG
云风的 BLOG
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
I
InfoQ
S
SegmentFault 最新的问题

Latest from TechRadar in Pro

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… I tried 7 free MTD software – now I've ranked my top picks as a freelancer Jackery McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… The new engineering playbook: how AI design copilots are reshaping product development Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts Europe wants tech sovereignty but is this realistic? Enterprise AI governance cannot live in a prompt. So where is the safety net? Why 2026 is the year of flexibility without friction: solving the multi-platform crisis OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap LaLiga uses AI to fight illegal streaming that costs its clubs $800m a year Intel and Google expand long-term chip partnership to power AI systems 'Chatbots respond not just to what you ask, but how you ask it': Report finds AI agents might be sucking up to… 'Smartphones have physical limitations': Report explains why AI is kickstarting a billion-dollar hardware arms… 'I’m pretty sure actually we really do not need to work for five days' Zoom CEO calls for end of traditional work schedules — says 3-day working week should become the norm 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these…
Cyber Essentials update could put your public sector cont...
Jonathan Kra · 2026-05-01 · via Latest from TechRadar in Pro

From 27 April 2026, any organization that holds Cyber Essentials certification and has not switched on login verification across every cloud service it uses is looking at an automatic assessment failure.

Not a non-conformity to address gradually. Not a remediation point. An immediate fail with no second chance within that certification cycle.

Article continues below

Founder and Head Assessor at Forensic Control.

The specific change is this: if a cloud service offers Multi-Factor Authentication (MFA) and an organization has not enabled it for all users, the assessment fails immediately.

This applies even where the feature is only available through a paid upgrade to an existing plan. Under the previous version of the scheme, non-compliant answers on this point were survivable. That route is now closed.

For most organizations, resolving this is a straightforward technical project. But in my assessments this year I have encountered a specific category of organization for which it is anything but. The gap between what v3.3 now requires and what they can actually deliver is significant, and the scheme update does not address it.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The problem the guidance does not resolve

The pressure points I see consistently appear in environments built around shared access, rapid task switching, and frequent staff or volunteer turnover.

These are organizations where people need to get onto systems quickly, where devices are shared across shifts, or where managing individual login credentials for a constantly rotating workforce creates a genuine operational burden.

Think of a station operations room where multiple staff rotate through shared terminals across shifts, needing to access time-critical information in seconds.

Or a nationally known charity with hundreds of high street locations and a large volunteer workforce on short shifts, for whom managing individual authentication at scale is a real practical problem.

In both cases, the relevant cloud services offer the required verification feature. In both cases it has not been enabled, not out of carelessness, but because the operational reality makes standard approaches genuinely difficult to deploy.

Under the previous version of the scheme that position was survivable. Under v3.3 it becomes an automatic fail.

That does not make stronger authentication unnecessary. If anything it makes it more important. But it does mean that some organizations have supported the principle while delaying the harder work of designing how it will actually function day to day. That distinction matters much more under v3.3.

This is a workflow design problem, not a policy problem

The organizations that will navigate v3.3 well are not the ones with the most sophisticated security policies. They are the ones that have done the practical work of making stronger authentication usable in the environments where it is hardest to deploy.

That means mapping every in-scope cloud service and establishing exactly where verification features are available, including where they require a paid upgrade, because v3.3 makes no distinction. It means reviewing whether current authentication approaches are suitable for fast-moving operational environments.

And it means looking seriously at options such as FIDO2 security keys, passkeys, badge-linked identity workflows, and context-aware access controls that can reduce friction without reducing assurance.

NCSC's own guidance has increasingly reflected the value of phishing-resistant approaches over codes and prompts, and v3.3 moves in the same direction.

Cyber Essentials now makes cloud services unambiguously part of scope where they store or process organizational data. Organizations can no longer assume that awkward operational exceptions will remain tolerable.

The bar is rising. The organizations that will meet it are the ones treating authentication as a design challenge, not a compliance checkbox.

Start now, not at renewal

The businesses most likely to struggle with Cyber Essentials v3.3 are not the ones that disagree with stronger authentication. They are the ones that have postponed the practical work of making it usable everywhere the standard now expects it to be.

This should not be left until renewal. Rolling out new authentication methods, adjusting processes for joiners and leavers, and getting users comfortable with a new access model all take time. If verification features are available on your cloud services but not yet enabled, 27 April is closer than it appears.

Cyber Essentials v3.3 is not just a tougher compliance checkpoint. It is a prompt to make sure that how your organization verifies who can access its systems actually works in the real world, especially in the environments where getting that right is hardest.

We've featured the best encryption software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit