There are some big changes coming to the Cyber Essentials certification this year. The government-approved scheme protects businesses across the country from the most common cyber attacks.
As technology continues to progress, so do cyber threats, which means the Cyber Essentials certification must stay up to date to remain effective and maintain its standards of safety.
The changes are due to come into effect on 27th April 2026. Here are the most significant you can expect to see in Cyber Essentials v3.3:
1. Compulsory MFA (Multi-Factor Authentication)
Perhaps the biggest change is the enforcement of mandatory multi-factor authentication.
While MFA is already expected with Cyber Essentials using cloud services―be it paid, free, or provided―it must now be enabled for all users. After 27th April, if a company has not implemented MFA for cloud service access, it will result in an automatic fail.
This shows the shift in priorities when it comes to MFA. In previous years, it was only recommended. With the rising pressure of evolving cyber threats, however, it has become more of an essential part of cyber security.
2. Scoping Rules Outlined
The rules and expectations for scoping must now be clearly outlined with no exceptions. This includes the removal of word limits on descriptions, details becoming visible on the digital certification platform, and mentioning all legal entities involved.
Any scope exclusions must be reasonably justified and explicitly detailed in writing. The exclusion details won’t be made public, but they must be outlined.
3. Password-free Access
While not currently mandatory, v3.3 will heavily encourage passwordless means of access to digital accounts. This includes the likes of passkeys, FIDO2 authenticators and other secure alternatives to passwords.
As cyber threats continue to persist, it has become evident over the years that passwords are becoming increasingly outdated in protecting sensitive data. This is why passwordless approaches to security are now being considered as an alternative.
If you want to hear our thoughts on the subject, read our blog post on the case for passwordless security.
4. Cloud Services in Scope
Going forward, any cloud service used to store or process data within an organisation must be included in scoping. This means that SaaS or any such service can no longer be excluded in your assessment.
5. Web Application Expectations
In prior years, the Cyber Essentials certification included the criteria of “Web Applications” within its assessment. Now, that is being expanded to include Application Development, maintaining consistency with government guidelines.
This change puts emphasis on secure coding and patching, which is more in line with the Software Security Code of Practice.
6. Robust Recovery Strategies
The guidance on backup strategies will see an update to ensure compliance with government guidelines.
Half the reason cyber attacks are so effective is down to the organisation failing to integrate an effective recovery plan to minimise damage that a breach can incur.
Therefore, Cyber Essentials v3.3 are hoping to encourage more companies to take it more seriously.
7. Before the Deadline
The government is encouraging UK companies to prepare for these changes now to ensure their compliance will be met by the deadline.
This must include reviewing current practices, making sure MFA is enabled where possible, all scoping is transparent and extensive, and all relevant systems are software are accounted for.
Cyber Essentials v3.3 shows a large shift in the framework which aims to improve cybersecurity practices overall.
Get Cyber Essentials Certified with bSecured
Feeling overwhelmed with your business’ cybersecurity concerns? Unsure where to start? With bSecured, you can get all the best cybersecurity solutions all in one package.
From dark web monitoring to next-gen antivirus solutions, you can quickly and effectively gain robust IT support from our expert team and secure your sensitive data against the most common cyber threats.
If you want to learn how Bells IT Support can help your business be more secure, visit our contact page to get in touch and learn more by speaking to one of our team.