Client Portal

Need Help? Get Support

Cyber Essentials Changes April 2026: What’s New and How to Prepare

Cyber Essentials Changes April 2026

May 1, 2026

The Cyber Essentials scheme is updated annually to ensure it continues to reflect current cyber threats and improves clarity across assessments.

The April 2026 update introduces important changes to assessment rules, marking criteria, and Cyber Essentials Plus (CE+) testing. While the five core controls remain unchanged, organisations preparing for certification or renewal should understand what has been updated to avoid unexpected failures.

This guide outlines the key changes and what they mean for your organisation.

What’s changing in Cyber Essentials in April 2026?

The April 2026 update focuses on improving consistency in assessments and strengthening enforcement of key security controls.

These changes apply to all new assessment accounts created after 26 April 2026. Organisations with existing applications before this date will have a transition period to complete certification under the previous requirements.

1. Stricter marking criteria and automatic failures

Several key security controls are now enforced more strictly, with some requirements treated as automatic pass/fail conditions.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication is now required for all cloud services where it is available.

If MFA is not enabled for cloud services within scope, the assessment will automatically fail.
This change reinforces the importance of protecting accounts against compromised credentials and unauthorised access.

Security updates within 14 days
Two new requirements strengthen expectations around patch management:

  • High-risk or critical updates for operating systems, routers, and firewalls must be applied within 14 days
  • High-risk or critical updates for applications (including associated files and extensions) must also be applied within 14 days

Failure to meet either requirement will result in automatic failure of the assessment.

2. Improved clarity around cloud services and scope

The definition of cloud services has been clarified to reduce ambiguity during assessments.

A cloud service is defined as:

An on-demand, scalable service hosted on shared infrastructure and accessible via the internet, used to store or process organisational data.

If a service stores or processes business data, it must now be included within the scope of the assessment.
This includes services such as email platforms, file storage systems, and cloud-based business applications.

Previously, some organisations attempted to reduce scope by excluding certain cloud services. The updated guidance makes it clear that exclusions must be justified, and services handling organisational data are generally in scope.

You can view how we help organisations with scope and certification here:
https://eventura.com/cyber-essentials-certification/

3. Cyber Essentials Plus (CE+) changes

Cyber Essentials Plus assessments have been updated to improve testing consistency and prevent selective remediation.

Updated testing approach

If an organisation fails an initial technical test, assessors will:

  • Re-test the original failed sample
  • Test an additional random sample of devices

If both fail, the organisation must remediate issues and undergo further testing.

This ensures that security fixes are applied across the entire environment, not just individual test devices.

No changes during CE+ assessment

Organisations will no longer be able to modify their self-assessment responses during CE+ testing.

This improves the integrity and reliability of the certification process.

4. Improved scope transparency and certification clarity

Several updates improve how assessment scope is defined and reported:

  • More detailed scope descriptions are now permitted
  • Excluded systems must be clearly documented and justified
  • All legal entities within scope must be identified
  • Additional certificates can be issued for individual entities within a group structure

These changes improve transparency and reduce ambiguity across assessments.

5. Additional technical updates

The April 2026 update also includes several clarifications:

Point-in-time certification

Certification now explicitly reflects compliance at the point the certificate is issued.

Backups guidance

Greater emphasis has been placed on maintaining secure backups to support recovery after cyber incidents.

Modern authentication

Guidance now supports modern authentication methods such as passkeys and FIDO2-based password less authentication.

Application development scope

Clarification has been added that publicly available web applications are generally in scope, while bespoke components may vary depending on deployment.

How to prepare for Cyber Essentials 2026

To reduce the risk of failing certification, organisations should review:

  • MFA is enabled across all cloud services
  • Security updates are applied within 14 days
  • Cloud services are correctly included in scope
  • Backup and recovery processes are in place
  • Cyber Essentials Plus readiness

Use our Cyber Essentials checklist to assess your readiness:
https://eventura.com/cyber-essentials/checklist/


How Eventura can help

Preparing for Cyber Essentials certification can be complex, especially with evolving requirements.

We support organisations through every stage of the process, including:

  • Cyber Essentials readiness reviews
  • Gap analysis against requirements
  • Support with remediation and security controls
  • Assistance with Cyber Essentials and Cyber Essentials Plus certification

Learn more about our Cyber Essentials certification support:
https://eventura.com/cyber-essentials-certification/

Final thoughts

The April 2026 Cyber Essentials update does not change the core principles of the scheme, but it does tighten enforcement around key areas such as authentication, patch management, and assessment scope.

Organisations should not assume that previous compliance guarantees success under the updated requirements.

Early preparation is the best way to ensure a smooth certification process.

Request a NetSuite Pricing Quote
Pricing Form - NetSuite
Get In Touch
Get In Touch - Sage - NetSuite - Cyber Security
Request a Demo
Request a Demo - Sage - NetSuite

Request a Call Back

Request a Call Back

Submit your CV

[gravityform id="7" title="on" description="on" ajax="false" ]