Cyber Essentials has long been the UK Government’s baseline standard for cyber security. It helps organisations protect themselves against the most common cyber attacks and is often a requirement for winning contracts or working in regulated supply chains.

In April 2026, Cyber Essentials went through its most significant update in several years. While the headline controls remain the same, the way they are assessed and enforced has changed dramatically.

If you’ve passed Cyber Essentials before, this update matters…

This article explains what’s different between the old and new versions, in plain English.


The Big Picture: From “Best Effort” to “Must Be Enforced”

Under the old scheme, many organisations technically met the Cyber Essentials requirements, but with flexibility. Some controls could be partially implemented, with plans to improve them later.

The updated Cyber Essentials removes much of that flexibility.

The new version focuses far more on proving that security controls are actually switched on and being used, not just written down in policy documents.

In short:
If a security feature exists, you are now expected to use it.


1. Multi‑Factor Authentication (MFA) Is No Longer Optional

Before

Previously, organisations could still pass Cyber Essentials even if:

  • MFA wasn’t enabled everywhere, or
  • MFA was planned but not yet fully deployed

Failing to use MFA was seen as a gap — but not always a deal‑breaker.

Now

From April 2026:

  • MFA must be enabled on all cloud services where it is available
  • This applies to all users, not just administrators
  • If MFA exists and isn’t turned on, the assessment automatically fails

Cost, licensing tier, or convenience are no longer considered valid reasons to avoid MFA.

What this means in practice:
If your staff log into Microsoft 365, email, CRM systems, HR platforms, accounting software, or other online tools, MFA must be enforced everywhere.


2. Cloud Services Are Defined Much More Broadly

Before

“Cloud services” were often interpreted narrowly, typically limited to large platforms like Microsoft 365 or Google Workspace.
Smaller apps were sometimes missed or excluded by mistake.

Now

The definition has been tightened:

  • Any service accessed using a business account or email address counts as a cloud service
  • Free tools, niche apps, and SaaS platforms are all in scope
  • These services cannot simply be excluded from the assessment


What this means:

Organisations must genuinely understand every online service their business uses, not just the “big obvious ones”.


3. Faster Patch and Update Expectations

Before

Security updates were required, but enforcement was more forgiving and evidence‑light.

Now

The updated scheme introduces strict time limits:

  • Critical and high‑risk security updates must be installed within 14 days
  • This applies to:
    • Computers and servers
    • Firewalls and routers
    • Key business applications
  • Missing these deadlines can now trigger an automatic failure


What this means:

Manual, ad‑hoc patching approaches are much more likely to fail an assessment.


4. Stronger Evidence Requirements

Before

Cyber Essentials leaned heavily on self‑attestation. Written answers and general explanations were often sufficient.

Now

Assessors expect:

  • Clear, specific answers
  • Evidence that controls are consistently applied, not “in theory”
  • Accurate scoping, with proper justification for any exclusions

This applies to both Cyber Essentials and Cyber Essentials Plus, with Plus becoming more hands‑on and technical in its testing.


5. From Willow to Danzell: A New Question Set

The old self‑assessment question set, known as Willow, has been retired.

It has been replaced with Danzell, which:

  • Removes ambiguous wording
  • Eliminates grey areas
  • Introduces automatic‑fail questions for critical controls
  • Aligns answers more closely with real‑world security behaviour

This means there is less room for interpretation — and fewer ways to “just about pass”.


What Hasn’t Changed

It’s worth stressing:

  • The five core Cyber Essentials controls remain the same
  • There are no brand‑new security concepts to learn
  • This update is about enforcement, clarity, and consistency, not complexity

Why This Matters for UK Organisations

For businesses that rely on Cyber Essentials for:

  • Government contracts
  • Supply chain compliance
  • Client reassurance

…this update raises the bar significantly.

Organisations that previously passed with last‑minute fixes or partial controls may now:

  • Fail assessments
  • Delay renewals
  • Lose eligibility for certain contracts

Final Thoughts

Cyber Essentials has quietly shifted from a tick‑box exercise to a practical security baseline.

For organisations that already take cyber security seriously, this update simply formalises good practice.
For others, it’s a clear signal that minimum standards are no longer minimal.

If you haven’t reviewed your Cyber Essentials readiness since this update, now is the time.

To find out more about Cyber Essentials please reach out to us via the normal channels.

Each asset has an associated cost, and you want to maximize any investment by ensuring that equipment is being used properly by the right people. Asset management is also a key component of overall risk management as it ensures that your business only uses supported and compliant devices.

Single Order Generic Ethernet Access, or SOGEA for short, is a type of broadband internet connection that provides a dedicated Ethernet connection directly from a customer’s premises to the internet service provider’s (ISP) network.

SOGEA allows customers to connect to the internet using only a single order, which includes both the broadband service and the telephone line rental. This means that customers can use the same telephone line for both voice calls and internet access, without the need for a separate Openreach phone line.

One of the benefits of SOGEA is that it can provide a faster and more reliable connection than traditional broadband options such as ADSL, which rely on copper telephone lines. SOGEA is also a good option for customers who don’t need a traditional phone service, but still require high-speed internet access.

SOGEA is currently available in the United Kingdom, and it’s expected to become a more widely used broadband option as more internet service providers adopt it.

Starlink internet is a revolutionary new way to connect to the internet that is fast, reliable, and available virtually anywhere in the world.

With Starlink, you can say goodbye to slow, unreliable internet connections and hello to high-speed internet that delivers download speeds of up to 100 Mbps. Best of all, Starlink uses advanced satellite technology to provide internet access to areas that are traditionally underserved or completely without internet access. Whether you’re living in a rural area, traveling on the road, or just tired of slow internet speeds, Starlink has the solution you’ve been looking for.

Our leased line product is a dedicated, private telecommunications circuit that provides a direct and continuous connection between two points, typically used for internet access, voice communications, or data transfer.

One of the main benefits of a leased line is the reliability and consistency it offers, as it guarantees a fixed bandwidth and symmetric upload and download speeds, without sharing with other users. This makes it ideal for businesses that require high levels of connectivity and bandwidth, such as those that use cloud services or require large file transfers. Additionally, our leased lines offer improved security, as they are not vulnerable to interference or hacking from external sources, unlike shared broadband connections. Lastly, leased our lines come with a service level agreements (SLAs), which provide guarantees for uptime and response times, ensuring a high level of customer service and support.

Ethernet First Mile (EFM) is a technology that enables high-speed, dedicated internet access over traditional copper-based infrastructure. Specifically, EFM refers to the use of Ethernet technology to provide connectivity from a customer’s premises to the service provider’s network.

In traditional broadband access, a customer’s connection to the provider’s network typically involves a shared medium such as cable or DSL. With EFM, the customer’s connection is dedicated, meaning that they have a direct, uncontended connection to the provider’s network.

EFM is often used to provide high-speed internet access to small and medium-sized businesses, as well as remote or underserved areas. It can offer speeds of up to 35 Mbps over distances of up to 10 kilometers, depending on the quality of the copper infrastructure.

Overall, EFM is a cost-effective solution for businesses that require reliable, high-speed internet connectivity but cannot access fiber-based solutions due to geographical or economic limitations.

FTTC stands for Fiber to the Cabinet, which is a type of internet broadband technology. It involves running a high-speed fiber optic cable from the internet service provider (ISP) to a street cabinet, which is usually located on the side of a road or a pavement, and then using the existing copper telephone lines to connect homes and businesses to the cabinet.

The distance between the cabinet and the property can affect the speed of the internet connection. The closer the property is to the cabinet, the faster the internet speed.

FTTC can provide faster internet speeds compared to ADSL (Asymmetric Digital Subscriber Line) technology, which uses copper telephone lines for both download and upload data. FTTC can offer download speeds of up to 80 Mbps (megabits per second) and upload speeds of up to 20 Mbps, depending on the quality of the copper telephone lines and the distance between the property and the cabinet.

FTTC is often used as an interim solution while ISPs work on providing full fiber connections to homes and businesses.