The Cyber Essentials scheme received several important updates earlier this year.
IASME, working closely with the National Cyber Security Centre (NCSC), reviews the scheme annually to ensure it continues to address modern cyber threats and reflects feedback from assessors, organisations and audit findings.
The 2026 updates focus on improving clarity, strengthening assurance and refining how assessments are carried out.
For organisations looking to certify or renew their Cyber Essentials certification, understanding these changes is essential. This article explains the key updates, why they matter and what they mean for your business.
What Changed in Cyber Essentials During 2026?
Although the five core technical controls of Cyber Essentials remain unchanged, several operational elements were updated for all assessment accounts created after 26 April 2026.
Organisations with accounts created before that date were given a six-month transition period to complete certification against the previous version of the scheme.
Is Multi-Factor Authentication (MFA) Now Mandatory for Cyber Essentials?
One of the most significant updates is the introduction of an automatic failure if MFA is not enabled on any cloud service where it is available. This applies even if MFA requires an additional licence or fee.
IASME introduced this requirement to strengthen identity security and reduce the risk of account compromise.
How Has the Cyber Essentials Assessment Methodology Changed?
IASME has updated the assessment framework, marking criteria and question set to improve consistency and reduce ambiguity.
These updates are designed to create a more predictable and transparent assessment experience for both organisations and assessors.
How Have Audit Findings Influenced the Cyber Essentials Scheme?
While the Requirements for IT Infrastructure document itself has not changed since its 2025 update, IASME’s ongoing audit work has informed improvements in how the scheme operates.
These refinements help ensure Cyber Essentials continues to reflect real-world risks and modern security challenges.
What Are the New Cyber Essentials Scope Requirements?
Scope descriptions on certificates can now include more detail, allowing organisations to provide a clearer picture of what is covered by certification.
Where parts of an infrastructure are excluded, organisations must describe those exclusions and explain how they are separated from systems that remain within scope.
This improved transparency helps customers, suppliers and stakeholders better understand exactly what a certification covers.
Why Are the 2026 Cyber Essentials Changes Important?
While these updates may appear modest at first glance, they address some of the most common challenges encountered during assessments and strengthen the overall assurance provided by the scheme.
Why Is MFA So Important for Cyber Security?
Account compromise remains one of the leading causes of cyber incidents.
Making MFA mandatory across all eligible cloud services significantly strengthens baseline security and helps prevent unauthorised access to business systems and data.
Why Are Cloud Services Receiving Greater Focus?
Cloud services are now used by almost every organisation.
Ensuring they are properly secured and assessed provides a more accurate representation of an organisation’s overall cyber security posture and helps address risks associated with modern working practices.
How Do the New Assessment Rules Improve Consistency?
Updated marking guidance and refinements to the assessment methodology help reduce uncertainty and ensure that certification bodies apply the scheme requirements consistently.
This creates a fairer and more predictable experience for organisations seeking certification.
How Do More Detailed Scope Descriptions Benefit Organisations?
More detailed scope information helps organisations communicate more clearly what their certification covers.
This increased transparency can help build trust with customers, suppliers and partners while reducing the risk of misunderstandings.
How Should Organisations Prepare for Cyber Essentials Certification?
If you are planning to achieve or renew Cyber Essentials certification, there are several practical steps you should consider:
- Enable MFA across all cloud services without exception.
- Review your cloud service inventory to ensure nothing has been overlooked.
- Strengthen your process for applying high-risk and critical security updates promptly.
- Prepare supporting evidence in line with the latest marking criteria.
- Review any scope exclusions and ensure they are fully documented and justified.
Taking these steps in advance can make the certification process smoother and reduce the likelihood of delays or non-compliance findings.
Do the 2026 Cyber Essentials Changes Affect Existing Certifications?
Existing Cyber Essentials certificates remain valid until their expiry date.
However, organisations renewing certification will be assessed against the current version of the scheme. Reviewing your systems, controls and certification scope before beginning the renewal process can help avoid unexpected issues during assessment.
Need Help Achieving Cyber Essentials Certification?
The updates introduced during 2026 do not fundamentally change Cyber Essentials, but they do reinforce several areas that have become increasingly important within today’s threat landscape.
Understanding these requirements and preparing appropriately can help make certification simpler, smoother and more successful.
We are an IASME-accredited Cyber Essentials Certification Body, supporting organisations throughout the entire certification process. Whether you’re renewing an existing certification or applying for the first time, our assessors can guide you through the latest requirements and help you achieve certification with confidence.
We can also help identify potential gaps through a cyber security audit before certification begins, giving you greater visibility of your current security posture and helping you prepare for a successful assessment.
If you’d like support with Cyber Essentials certification or would like to discuss a cyber security audit, get in touch with our team today.










