Cyber Essentials has long been the UK Government’s baseline standard for cyber security. It helps organisations protect themselves against the most common cyber attacks and is often a requirement for winning contracts or working in regulated supply chains.
In April 2026, Cyber Essentials went through its most significant update in several years. While the headline controls remain the same, the way they are assessed and enforced has changed dramatically.
If you’ve passed Cyber Essentials before, this update matters…
This article explains what’s different between the old and new versions, in plain English.
The Big Picture: From “Best Effort” to “Must Be Enforced”
Under the old scheme, many organisations technically met the Cyber Essentials requirements, but with flexibility. Some controls could be partially implemented, with plans to improve them later.
The updated Cyber Essentials removes much of that flexibility.
The new version focuses far more on proving that security controls are actually switched on and being used, not just written down in policy documents.
In short:
If a security feature exists, you are now expected to use it.
1. Multi‑Factor Authentication (MFA) Is No Longer Optional
Before
Previously, organisations could still pass Cyber Essentials even if:
- MFA wasn’t enabled everywhere, or
- MFA was planned but not yet fully deployed
Failing to use MFA was seen as a gap — but not always a deal‑breaker.
Now
From April 2026:
- MFA must be enabled on all cloud services where it is available
- This applies to all users, not just administrators
- If MFA exists and isn’t turned on, the assessment automatically fails
Cost, licensing tier, or convenience are no longer considered valid reasons to avoid MFA.
What this means in practice:
If your staff log into Microsoft 365, email, CRM systems, HR platforms, accounting software, or other online tools, MFA must be enforced everywhere.
2. Cloud Services Are Defined Much More Broadly
Before
“Cloud services” were often interpreted narrowly, typically limited to large platforms like Microsoft 365 or Google Workspace.
Smaller apps were sometimes missed or excluded by mistake.
Now
The definition has been tightened:
- Any service accessed using a business account or email address counts as a cloud service
- Free tools, niche apps, and SaaS platforms are all in scope
- These services cannot simply be excluded from the assessment
What this means:
Organisations must genuinely understand every online service their business uses, not just the “big obvious ones”.
3. Faster Patch and Update Expectations
Before
Security updates were required, but enforcement was more forgiving and evidence‑light.
Now
The updated scheme introduces strict time limits:
- Critical and high‑risk security updates must be installed within 14 days
- This applies to:
- Computers and servers
- Firewalls and routers
- Key business applications
- Missing these deadlines can now trigger an automatic failure
What this means:
Manual, ad‑hoc patching approaches are much more likely to fail an assessment.
4. Stronger Evidence Requirements
Before
Cyber Essentials leaned heavily on self‑attestation. Written answers and general explanations were often sufficient.
Now
Assessors expect:
- Clear, specific answers
- Evidence that controls are consistently applied, not “in theory”
- Accurate scoping, with proper justification for any exclusions
This applies to both Cyber Essentials and Cyber Essentials Plus, with Plus becoming more hands‑on and technical in its testing.
5. From Willow to Danzell: A New Question Set
The old self‑assessment question set, known as Willow, has been retired.
It has been replaced with Danzell, which:
- Removes ambiguous wording
- Eliminates grey areas
- Introduces automatic‑fail questions for critical controls
- Aligns answers more closely with real‑world security behaviour
This means there is less room for interpretation — and fewer ways to “just about pass”.
What Hasn’t Changed
It’s worth stressing:
- The five core Cyber Essentials controls remain the same
- There are no brand‑new security concepts to learn
- This update is about enforcement, clarity, and consistency, not complexity
Why This Matters for UK Organisations
For businesses that rely on Cyber Essentials for:
- Government contracts
- Supply chain compliance
- Client reassurance
…this update raises the bar significantly.
Organisations that previously passed with last‑minute fixes or partial controls may now:
- Fail assessments
- Delay renewals
- Lose eligibility for certain contracts
Final Thoughts
Cyber Essentials has quietly shifted from a tick‑box exercise to a practical security baseline.
For organisations that already take cyber security seriously, this update simply formalises good practice.
For others, it’s a clear signal that minimum standards are no longer minimal.
If you haven’t reviewed your Cyber Essentials readiness since this update, now is the time.
To find out more about Cyber Essentials please reach out to us via the normal channels.