Cyber Essentials
We certified last year. Will we pass Cyber Essentials renewal?
Probably not, not without some work first. Assessment accounts created on or after 27 April 2026 are marked against Requirements for IT Infrastructure v3.3, and multi-factor authentication is now mandatory on every cloud service that offers it. Miss it on one service and you fail the whole assessment.
The short answer is probably not, and the reason is one line in the requirements.
Cyber Essentials certificates last twelve months. When yours comes up you don’t renew the old assessment, you open a new one. If that new assessment account is created on or after 27 April 2026, it’s marked against Requirements for IT Infrastructure v3.3, which is a stricter document than the one you were marked against last year. Nobody writes to tell you. You log in expecting last year’s questions and get this year’s.
What changed in Cyber Essentials on 27 April 2026?
Multi-factor authentication became mandatory on every cloud service that offers it, and missing it on a single service is an automatic fail rather than a mark against you.
The same update leans harder on passwordless sign in and passkeys, gives cloud services a formal definition so there’s less argument about what sits in scope, and simplifies the scoping rules.
Source: IASME, changes to the Cyber Essentials scheme, April 2026. IASME is the NCSC’s delivery partner for the scheme.
Assessment accounts opened before 27 April 2026 carry on against the previous version until that assessment closes. That’s the part that catches people, because it means the change doesn’t arrive on the day it’s announced. It arrives at renewal, months later, when you’ve stopped thinking about it.
Why does MFA fail so many renewals?
Because Microsoft 365 is the one everybody switched on years ago, and it’s the other nine services that nobody has looked at since the day they were set up.
The ones we find switched off, over and over:
- The accounting package. Xero, Sage, QuickBooks, whichever it is.
- The payroll portal, which is usually a separate login from accounting.
- File sharing that grew up outside Microsoft 365. Dropbox is the common one.
- The CRM or practice management system.
- The domain registrar and the hosting control panel, which between them can redirect your email.
- The backup console. Worth thinking about what an attacker does first if they get into that one.
- The password manager, which is the account that opens every other account.
- Remote access and support tools.
I’ll give you the version of this that still surprises me. We take over IT environments for a living, and some of the worst setups we walk into belong to businesses turning over £10m. Not startups counting pennies. Established, profitable, well run companies in every respect except this one. No MFA. Not patchy MFA, not MFA missing on a few accounts. None at all, and in some cases not even on the global admin account that controls the entire Microsoft tenant.
That isn’t a budget decision, because switching MFA on is free. What’s happened is that years ago someone found the path of least resistance, nobody questioned it, and it became the business process.
Which systems count as cloud services?
If your business reaches it over the internet, someone signs into it, and it holds business data, assume it’s in scope until somebody tells you otherwise.
The v3.3 definition exists precisely because this used to be arguable. The practical test that will save you an argument at assessment: if losing control of that login would be a bad day for the business, it’s in scope.
What does an automatic fail actually mean?
It means there’s no partial credit. Cyber Essentials is a verified self-assessment, so you answer the questions and a board member signs a declaration that your answers are true. If MFA is missing on one service in scope, the honest answer to that question is no, and no is a fail regardless of how good everything else is.
The declaration itself has teeth now. Under the current version, a board member has to state that compliance is maintained through the certification period, not just that it was true on the day you submitted.
How long before renewal should we start?
Six to eight weeks, and the time goes on finding things rather than fixing them.
Switching MFA on across a set of services you already have a list of is days of work, not weeks. Building that list is the slow part, and it’s slow because no single person in most businesses knows every system in use. What helps:
- Find your renewal date first. Everything else hangs off it.
- Ask finance what the business pays for. The card statement and the direct debits are a more honest inventory than anyone’s memory.
- Ask each team what they log into. You will find at least one system nobody in management knew existed.
- Check MFA on every one of them, including the admin accounts, which are usually the ones exempted for convenience years ago.
- Check nothing in scope is out of support, because unsupported software is its own fail.
Is the certificate worth having if it’s a tick-box exercise?
Yes, and it is a tick-box exercise. Both things are true, and I say that as someone whose company gets clients certified.
The certificate tells you that on the day you were assessed, you met the controls. It doesn’t tell you whether somebody set up a forwarding rule on your finance inbox this morning. It doesn’t tell you whether a scheduled task has been sitting on your domain controller since 2019. We have found exactly that, on a network that had antivirus installed and scanning daily, because nobody was reading what it found.
The thinking behind the scheme is still good. MFA, patching, endpoint protection, restricted admin access, a proper joiners and leavers process. If every UK SME did those five things consistently, the national picture would look dramatically different.
So my actual view, in three lines:
- If you need the badge for a contract, a tender or a regulator, get it. It isn’t hard, depending on how much technical debt you’re carrying.
- If you don’t need the badge, you still need the controls. Don’t wait for somebody to mandate what you should be doing anyway.
- Don’t treat the certificate as the finish line. You’ve got another 364 days to stay compliant, and the declaration you signed says you will.
The badge was never the goal. The goal is the thing the badge is supposed to prove.
What to do next
If you’re certified already, find your renewal date and start the list. If you’re not, and a client or a tender has started asking, the Cyber Essentials page sets out the five controls, both levels, and how we take businesses through it. What it costs to have us do it sits on the pricing page alongside everything else, because we publish our rates.
If you want a straight answer on whether your current setup would pass, ask us. It’s a short conversation and you’ll get a real answer, including if the answer is that you’re fine as you are.
Questions
The questions people ask us about this
Does MFA on email count on its own?
No. Email is one cloud service. The requirement covers every cloud service in scope, which for most businesses is somewhere between six and fifteen of them.
What if one of our systems can’t do MFA?
If a service offers MFA in any form, treat it as available and turn it on. If you believe a service genuinely cannot do it, raise that with your certification body before you submit rather than after, and be ready to explain what compensates for it.
It is also worth asking whether a business system that cannot offer multi-factor authentication in 2026 is a system you want holding your data.
Our assessment account was opened in February 2026. Are we affected?
Not for that assessment. Accounts opened before 27 April 2026 carry on against the previous version until they close. You meet the new question set at your next renewal, which is exactly why it catches people out.
Do we have to be a support client to get certified with you?
No. We take businesses through certification whether or not we look after their IT day to day. If we do support you, most of the controls are already in place because we put them there.