The Cyber Essentials scheme is updated annually to ensure it continues to reflect current cyber threats and improves clarity across assessments.
The April 2026 update introduces important changes to assessment rules, marking criteria, and Cyber Essentials Plus (CE+) testing. While the five core controls remain unchanged, organisations preparing for certification or renewal should understand what has been updated to avoid unexpected failures.
This guide outlines the key changes and what they mean for your organisation.
What’s changing in Cyber Essentials in April 2026?
The April 2026 update focuses on improving consistency in assessments and strengthening enforcement of key security controls.
These changes apply to all new assessment accounts created after 26 April 2026. Organisations with existing applications before this date will have a transition period to complete certification under the previous requirements.
1. Stricter marking criteria and automatic failures
Several key security controls are now enforced more strictly, with some requirements treated as automatic pass/fail conditions.
Multi-Factor Authentication (MFA)
Multi-Factor Authentication is now required for all cloud services where it is available.
If MFA is not enabled for cloud services within scope, the assessment will automatically fail.
This change reinforces the importance of protecting accounts against compromised credentials and unauthorised access.
Security updates within 14 days
Two new requirements strengthen expectations around patch management:
- High-risk or critical updates for operating systems, routers, and firewalls must be applied within 14 days
- High-risk or critical updates for applications (including associated files and extensions) must also be applied within 14 days
Failure to meet either requirement will result in automatic failure of the assessment.
2. Improved clarity around cloud services and scope
The definition of cloud services has been clarified to reduce ambiguity during assessments.
A cloud service is defined as:
An on-demand, scalable service hosted on shared infrastructure and accessible via the internet, used to store or process organisational data.
If a service stores or processes business data, it must now be included within the scope of the assessment.
This includes services such as email platforms, file storage systems, and cloud-based business applications.
Previously, some organisations attempted to reduce scope by excluding certain cloud services. The updated guidance makes it clear that exclusions must be justified, and services handling organisational data are generally in scope.
You can view how we help organisations with scope and certification here:
https://eventura.com/cyber-essentials-certification/
3. Cyber Essentials Plus (CE+) changes
Cyber Essentials Plus assessments have been updated to improve testing consistency and prevent selective remediation.
Updated testing approach
If an organisation fails an initial technical test, assessors will:
- Re-test the original failed sample
- Test an additional random sample of devices
If both fail, the organisation must remediate issues and undergo further testing.
This ensures that security fixes are applied across the entire environment, not just individual test devices.
No changes during CE+ assessment
Organisations will no longer be able to modify their self-assessment responses during CE+ testing.
This improves the integrity and reliability of the certification process.
4. Improved scope transparency and certification clarity
Several updates improve how assessment scope is defined and reported:
- More detailed scope descriptions are now permitted
- Excluded systems must be clearly documented and justified
- All legal entities within scope must be identified
- Additional certificates can be issued for individual entities within a group structure
These changes improve transparency and reduce ambiguity across assessments.
5. Additional technical updates
The April 2026 update also includes several clarifications:
Point-in-time certification
Certification now explicitly reflects compliance at the point the certificate is issued.
Backups guidance
Greater emphasis has been placed on maintaining secure backups to support recovery after cyber incidents.
Modern authentication
Guidance now supports modern authentication methods such as passkeys and FIDO2-based password less authentication.
Application development scope
Clarification has been added that publicly available web applications are generally in scope, while bespoke components may vary depending on deployment.
How to prepare for Cyber Essentials 2026
To reduce the risk of failing certification, organisations should review:
- MFA is enabled across all cloud services
- Security updates are applied within 14 days
- Cloud services are correctly included in scope
- Backup and recovery processes are in place
- Cyber Essentials Plus readiness
Use our Cyber Essentials checklist to assess your readiness:
https://eventura.com/cyber-essentials/checklist/
How Eventura can help
Preparing for Cyber Essentials certification can be complex, especially with evolving requirements.
We support organisations through every stage of the process, including:
- Cyber Essentials readiness reviews
- Gap analysis against requirements
- Support with remediation and security controls
- Assistance with Cyber Essentials and Cyber Essentials Plus certification
Learn more about our Cyber Essentials certification support:
https://eventura.com/cyber-essentials-certification/
Final thoughts
The April 2026 Cyber Essentials update does not change the core principles of the scheme, but it does tighten enforcement around key areas such as authentication, patch management, and assessment scope.
Organisations should not assume that previous compliance guarantees success under the updated requirements.
Early preparation is the best way to ensure a smooth certification process.



