Cyber Essentials is the UK Government-backed baseline for protecting organisations against the most common cyber attacks. In April 2026, the scheme introduced its biggest update in years. If you hold Cyber Essentials, or you’re planning to certify, the Cyber Essentials 2026 changes are worth understanding now, because some requirements that used to be flagged as “improvements” are now an automatic fail.

Key takeaways
- MFA is now mandatory on every cloud service that offers it.
- Critical and high-risk updates must be installed within 14 days.
- Every legal entity in scope must be listed, and exclusions explained.
- Cyber Essentials Plus now tests a fresh random sample of devices.
What changed in Cyber Essentials 2026?
From 27 April 2026, assessments use a new question set, known as “Danzell”. The headline changes are:
- MFA on every cloud service. Multi-factor authentication must be switched on for every cloud service that offers it. That includes email, Microsoft 365 or Google Workspace, finance and HR systems, CRM platforms and remote access tools. If it’s available and not enabled, the assessment fails.
- 14-day patching, strictly enforced. High-risk and critical security updates must be installed within 14 days of release. This applies to operating systems, applications and the firmware on routers and firewalls. Missing the deadline is no longer just a note on your report.
- Clearer scope. Organisations now need to list every legal entity included in the assessment and explain anything that is excluded, and why.
- Tougher Cyber Essentials Plus testing. Assessors check a fresh, random sample of devices to confirm updates have been applied consistently, and you can no longer change your self-assessment answers once testing starts.
You can read the official requirements on the NCSC Cyber Essentials pages.
Why the changes matter
Stolen passwords and unpatched software remain two of the most common ways attackers get into small organisations. The UK Government’s Cyber Security Breaches Survey 2026 found that 43% of businesses identified a breach or attack in the last year, rising to 65% of medium-sized businesses. Making MFA and timely patching mandatory targets exactly those weaknesses.
Cyber Essentials is also increasingly a commercial requirement. Many public sector contracts, larger clients, funders and cyber insurers expect it, so failing a renewal can have consequences well beyond IT.
What you should do now
- List your cloud services. Include the free and low-cost tools teams have signed up to themselves. You can’t enable MFA on a service you don’t know about.
- Turn on MFA everywhere it’s offered. Prioritise email, admin accounts and anything holding personal or financial data.
- Automate updates. Use central device management so patches are deployed and reported on automatically, rather than relying on staff to click “restart”.
- Check your firewall and router firmware. Network equipment is easy to forget, and it’s now firmly in scope.
- Replace unsupported software. Anything no longer receiving security updates, including Windows 10 without Extended Security Updates, is a problem for certification.
- Plan your renewal early. Give yourself time to fix gaps before the assessment, not during it.
How ready are you?
Our free SME cyber security checklist includes 40 practical checks, with every Cyber Essentials requirement clearly marked. It’s a quick way to see where you stand before your next assessment.
LevelUp Networks holds Cyber Essentials and helps organisations prepare for and maintain certification as part of our cyber security services. If you’d like help getting ready for Cyber Essentials 2026, get in touch.