












Over the past year, Cyber Essentials has introduced some of the most significant changes to the standard since it was first launched, and the requirements have evolved for achieving this certification.
As you have attained Cyber Essentials in previous years, it is important to understand that renewing your certification is no longer simply a case of completing the annual questionnaire.
Many organisations will now need to review and improve parts of their security posture before they are able to achieve certification again.
These changes are not intended to make certification more difficult, they are designed to ensure businesses have appropriate protection against the increasingly sophisticated cyber attacks that organisations face every day.
The new requirements place a much greater emphasis on understanding and actively managing your technology estate, including:
One of the biggest changes is the expectation that organisations actively identify and remediate vulnerabilities across their IT estate.
This means organisations must now be able to identify software and devices with known critical vulnerabilities and ensure they are remediated within the required timescales. Waiting until annual reviews or relying solely on Windows Updates is no longer sufficient.
Examples include:
Many organisations will now require a formal vulnerability management process, together with regular reporting to demonstrate compliance.
Another significant change is the requirement to consider the cloud applications and online services your organisation relies upon to process business information.
This goes far beyond Microsoft 365. Examples include:
To ensure your assessment is accurate, we will need to understand which cloud applications your organisation uses, who uses them, whether they support Multi-Factor Authentication, and whether they store or process business data.
Under the April 2026 marking criteria, failing to use MFA for a cloud service where it is available results in an automatic assessment failure.
The new standards also place greater emphasis on personally owned devices used to access company systems or data.
Where staff use their own laptops, tablets or mobile devices to access company email, files or cloud services, appropriate security controls must now be in place to protect organisational data.
This may include device management, application protection policies, access controls and other security measures depending on how those devices are used.
In short: Your users will be required to have the same security controls on their personal devices if they are used to access your business data.
For many businesses, achieving Cyber Essentials will now involve more preparation than in previous years.
Before your renewal, we may need to:
In some cases, organisations may already meet these requirements. Others may require changes before they are able to pass the assessment.
Our objective is not simply to complete a Cyber Essentials renewal but to help ensure your organisation genuinely meets the latest security standard.
Where additional work is required, we will explain exactly what has changed, why it is required under the updated Cyber Essentials standard, and work with you to implement the necessary improvements in the most practical and cost-effective way.
Over the coming weeks, we will be contacting customers whose Cyber Essentials certification is due for renewal to begin this review process.
If your renewal is approaching and you would like to discuss the new requirements, please get in touch with your Account Manager, who will be happy to arrange a review.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。