惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
J
Java Code Geeks
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
B
Blog RSS Feed
MongoDB | Blog
MongoDB | Blog
G
Google Developers Blog
Engineering at Meta
Engineering at Meta
量子位
S
SegmentFault 最新的问题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
About on SuperTechFans
P
Proofpoint News Feed
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
腾讯CDC
I
InfoQ
F
Fortinet All Blogs
Hugging Face - Blog
Hugging Face - Blog
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
爱范儿
爱范儿

Latest from TechRadar

Quordle hints and answers for Monday, April 13 (game #1540) NYT Strands hints and answers for Monday, April 13 (game #771) NYT Connections hints and answers for Monday, April 13 (game #1037) Morbid Metal developer explains why he ditched an origami art direction in favor of gritty sci-fi — 'It worked, but it didn't really feel like me' '71% of US households get routers from ISPs': Why new FCC rules could leave millions stuck with outdated,… 'The CPU is the system’s executive layer': Intel joins SambaNova as both face existential threat from… ‘More bang for your buck’: 7 easy ways to boost your MacBook Neo’s performance for free DJI Romo P vs Roborock Saros 10R — which robot vacuum comes out on top when it comes to dodging obstacles? I put… I spent 6 hours with Genshin Impact on the Galaxy S26 Ultra, and I can't believe how far mobile gaming has come What is the release date for The Testaments episode 4 on Hulu and Disney+? I reviewed the LG G6 for 3 weeks, and it's a fantastic OLED TV that's the new best option for brighter rooms Is your bird feeder camera doing more harm than good? 3 tips for using it safely as RSPB issues urgent disease warning Chelsea vs Man City Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news How to watch Alcaraz vs Sinner for FREE: TV Channels for Monte-Carlo Masters Final Sunderland vs Tottenham Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news Are these the best-designed workout headphones ever? I used them for a month to find out How to watch Snooker 900 John Virgo online (it's free) – stream O'Sullivan vs Higgins anywhere I've only just discovered the Walk With Frodo app on Garmin's Connect IQ store — and as as a huge LOTR nerd, it's going to make the next 1,800 miles fly by 'Just not sustainable': Why your monthly £25 broadband internet bill could soon hit £45 How to watch Paris-Roubaix 2026: Free Streams & TV Info as Tadej Pogacar chases third Monument How to watch Euphoria season 3 online – stream Zendaya & Sydney Sweeney drama from anywhere today '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… There's a sneaky way to watch UFC 327 really cheap... NYT Connections hints and answers for Sunday, April 12 (game #1036) NYT Strands hints and answers for Sunday, April 12 (game #770) Quordle hints and answers for Sunday, April 12 (game #1539) Amazon's Ring cameras are the perfect solution to secure your home on a budget — shop today's best deals… I've tested every iPhone since the iPhone 12, and Ceramic Shield 2 is the first iPhone glass I fully trust UFC 327 live stream: how to watch Procházka vs Ulberg, start time, preview, full card We're officially getting the DJI Pocket 4 on April 16, but here's how Insta360 could beat it
Cyber Essentials update could put your public sector cont...
Jonathan Kra · 2026-05-01 · via Latest from TechRadar

From 27 April 2026, any organization that holds Cyber Essentials certification and has not switched on login verification across every cloud service it uses is looking at an automatic assessment failure.

Not a non-conformity to address gradually. Not a remediation point. An immediate fail with no second chance within that certification cycle.

Article continues below

Founder and Head Assessor at Forensic Control.

The specific change is this: if a cloud service offers Multi-Factor Authentication (MFA) and an organization has not enabled it for all users, the assessment fails immediately.

This applies even where the feature is only available through a paid upgrade to an existing plan. Under the previous version of the scheme, non-compliant answers on this point were survivable. That route is now closed.

For most organizations, resolving this is a straightforward technical project. But in my assessments this year I have encountered a specific category of organization for which it is anything but. The gap between what v3.3 now requires and what they can actually deliver is significant, and the scheme update does not address it.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The problem the guidance does not resolve

The pressure points I see consistently appear in environments built around shared access, rapid task switching, and frequent staff or volunteer turnover.

These are organizations where people need to get onto systems quickly, where devices are shared across shifts, or where managing individual login credentials for a constantly rotating workforce creates a genuine operational burden.

Think of a station operations room where multiple staff rotate through shared terminals across shifts, needing to access time-critical information in seconds.

Or a nationally known charity with hundreds of high street locations and a large volunteer workforce on short shifts, for whom managing individual authentication at scale is a real practical problem.

In both cases, the relevant cloud services offer the required verification feature. In both cases it has not been enabled, not out of carelessness, but because the operational reality makes standard approaches genuinely difficult to deploy.

Under the previous version of the scheme that position was survivable. Under v3.3 it becomes an automatic fail.

That does not make stronger authentication unnecessary. If anything it makes it more important. But it does mean that some organizations have supported the principle while delaying the harder work of designing how it will actually function day to day. That distinction matters much more under v3.3.

This is a workflow design problem, not a policy problem

The organizations that will navigate v3.3 well are not the ones with the most sophisticated security policies. They are the ones that have done the practical work of making stronger authentication usable in the environments where it is hardest to deploy.

That means mapping every in-scope cloud service and establishing exactly where verification features are available, including where they require a paid upgrade, because v3.3 makes no distinction. It means reviewing whether current authentication approaches are suitable for fast-moving operational environments.

And it means looking seriously at options such as FIDO2 security keys, passkeys, badge-linked identity workflows, and context-aware access controls that can reduce friction without reducing assurance.

NCSC's own guidance has increasingly reflected the value of phishing-resistant approaches over codes and prompts, and v3.3 moves in the same direction.

Cyber Essentials now makes cloud services unambiguously part of scope where they store or process organizational data. Organizations can no longer assume that awkward operational exceptions will remain tolerable.

The bar is rising. The organizations that will meet it are the ones treating authentication as a design challenge, not a compliance checkbox.

Start now, not at renewal

The businesses most likely to struggle with Cyber Essentials v3.3 are not the ones that disagree with stronger authentication. They are the ones that have postponed the practical work of making it usable everywhere the standard now expects it to be.

This should not be left until renewal. Rolling out new authentication methods, adjusting processes for joiners and leavers, and getting users comfortable with a new access model all take time. If verification features are available on your cloud services but not yet enabled, 27 April is closer than it appears.

Cyber Essentials v3.3 is not just a tougher compliance checkpoint. It is a prompt to make sure that how your organization verifies who can access its systems actually works in the real world, especially in the environments where getting that right is hardest.

We've featured the best encryption software.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit