Publish Date: February 17, 2026
Categories: Cyber Essentials, Industry Insights
The Cyber Essentials scheme is updated annually to ensure it remains aligned with evolving cyber threats. While the scheme’s five core technical controls remain unchanged, the April 2026 updates introduce important refinements designed to enhance clarity, consistency, and overall effectiveness.
This blog outlines the latest updates to the Requirements for IT Infrastructure document, which the standard organisations must meet to achieve Cyber Essentials certification. It also explains significant changes to the assessment framework, marking criteria, and the Cyber Essentials Plus (CE+) methodology that will take effect in April 2026.
If your organisation is preparing for certification or recertification, understanding these changes is essential.
Background: How the Scheme Evolves
Each year, IASME works closely with the National Cyber Security Centre (NCSC) to review feedback from across the scheme. This review process includes:
- Analysis of breach investigations
- Findings from IASME-led audits
- Feedback from Assessors and certified organisations
These insights inform updates to the scheme requirements, assessment question set, methodology, and marking criteria. The goal is to implement improvements as early as possible, giving organisations sufficient time to prepare.
In November 2025, updates were published to the Requirements for Infrastructure document, including the introduction of an ‘auto-fail’ policy for not implementing Multi-Factor Authentication (MFA) where it is available. Since then, additional operational refinements have been identified through IASME’s audit processes. While these have not changed the technical requirements further, they have resulted in important updates to how the scheme operates.
When Do the Changes Apply?
The April 2026 updates will apply to:
- All assessment accounts created after April 26, 2026
Organisations with active assessment accounts created before this date will have a six-month transition period to achieve certification under the previous version of the requirements.
Key Changes to the Scheme
Stricter Marking Criteria for Critical Practices
One of the most significant updates is the introduction of stricter marking criteria for questions addressing critical cyber security practices. In key areas, failure to meet required standards will now result in an automatic failure, regardless of performance in other sections.
This approach aligns the scheme more closely with NCSC-recommended best practice and reinforces the importance of fundamental security controls.
Mandatory Multi-Factor Authentication (MFA)
MFA will now be a mandatory requirement for all cloud services where it is available.
This applies whether MFA is:
- Free
- Included within an existing subscription
- Offered as a paid option
If an organisation fails to implement MFA for cloud services where it is available, the assessment will result in automatic failure.
This change underscores the critical role MFA plays in protecting systems from unauthorised access and reflects the increasing threat landscape targeting cloud-based environments.
New Auto-Fail Questions on Security Updates
Two new questions related to update management have been designated as auto-fail:
A6.4 : Are all high-risk or critical security updates and vulnerability fixes for operating systems and router and firewall firmware installed within 14 days of release?
A6.5 : Are all high-risk or critical security updates and vulnerability fixes for applications (including associated files and extensions) installed within 14 days of release?
Failure to comply with either question will result in automatic failure of the assessment.
These changes address situations where delays in applying critical updates leave systems exposed to exploitation. The 14-day timeframe establishes a clear expectation for timely remediation.
Improved Scope Definition and Certification Transparency
Defining the scope of a Cyber Essentials assessment has historically been challenging, particularly for larger organisations with complex structures. The April 2026 updates introduce several measures to improve clarity and transparency.
Unlimited Scope Descriptions
Organisations will no longer be limited to a short scope description on their certificates. Instead, they will be able to provide a detailed scope description, accessible via the digital certificate platform.
Out-of-Scope Areas
Organisations must now describe any areas of their infrastructure excluded from scope. This information will not be made public but ensures greater clarity during assessment.
Legal Entity Identification
All legal entities included within the scope must be clearly specified, including:
- Entity name
- Address
- Company number
All in-scope legal entities will be visible on the digital certificate platform.
New Certificate Types
Organisations will be able to request individual Cyber Essentials certificates for each legal entity certified as part of a wider scope. These certificates will clearly state that they form part of a broader certification. A small additional charge will apply.
Together, these updates aim to reduce ambiguity and ensure that the scope of certification is clearly defined and accurately represented.
Clarification of “Point in Time”
Cyber Essentials is described as a “point in time” assessment, but there has been confusion regarding what this means.
The April 2026 update clarifies that the “point in time” refers specifically to the date the certificate is issued.
Organisations must ensure their systems are supported and compliant on that certification date.
Signed Declaration and Ongoing Compliance
The declaration signed by a board member or director as part of the verified self-assessment (VSA) process will now include explicit acknowledgement that the organisation is responsible for maintaining compliance with all Cyber Essentials controls throughout the certification period.
This reinforces leadership accountability and emphasises that certification is not a one-day exercise but an ongoing commitment.
Changes to Cyber Essentials Plus (CE+)
The Cyber Essentials Plus (CE+) assessment provides a higher level of assurance by including a technical audit. The April 2026 updates strengthen this process in two significant ways.
Enhanced Verification of Update Management
Recent audits identified cases where organisations applied updates only to the devices selected in CE+ testing, rather than across their full scope. This practice allowed some organisations to pass CE+ despite broader vulnerabilities remaining unaddressed.
To prevent this:
- If an organisation fails the initial random sample test, it must remediate the issues.
- During retesting, Assessors will:
- Recheck the original sample
- Test a new random sample of devices
This ensures compliance is demonstrated across the entire CE+ scope.
A second failure will result in revocation of the verified self-assessment certificate.
No Post-Testing Adjustments to the VSA
To protect the integrity of certification, organisations will no longer be permitted to amend their verified self-assessment responses after CE+ testing begins.
The scheme’s Terms and Conditions will require that the VSA be completed, finalised, and remain unchanged before CE+ testing commences.
Updates to the Requirements for IT Infrastructure v3.3
The v3.3 document includes several refinements designed to improve clarity and guidance.
Clear Definition of Cloud Services
A formal definition of cloud services has been introduced:
A cloud service is an on-demand, scalable service hosted on shared infrastructure and accessible via the internet. It is accessed via an account and stores or processes organisational data.
Importantly:
- Cloud services cannot be excluded from scope.
- If organisational data or services are hosted in the cloud, those services must be included.
Improved Scoping Requirements
The terms “untrusted” and “user-initiated” have been removed as qualifiers for internet connections, simplifying the scoping criteria.
Organisations must now justify any exclusions and explain how excluded networks are segregated from in-scope systems.
Application Development Updates
The “web applications” section has been renamed “Application Development” and now references the UK Government’s Software Security Code of Practice.
- Publicly available commercial web applications are in scope by default.
- Bespoke and custom components remain out of scope.
Emphasis on Backups
Guidance on backups has been repositioned earlier in the document to emphasise their importance in enabling rapid recovery from cyber incidents.
User Access Control Enhancements
The user access control section now highlights passwordless authentication methods, such as passkeys, as a more secure alternative to traditional passwords.
Preparing for April 2026
While the five core controls remain unchanged, the April 2026 updates significantly strengthen how those controls are implemented, verified, and enforced.
Organisations preparing for certification should:
- Ensure MFA is implemented across all applicable cloud services
- Establish processes to apply high-risk or critical updates within 14 days
- Review and clearly define assessment scope
- Confirm legal entity information is accurate
- Reinforce board-level accountability for ongoing compliance
These updates reflect the scheme’s continued evolution focusing not on adding complexity, but on improving clarity, consistency, and real-world security effectiveness.
By reviewing and implementing these changes early, organisations can ensure a smooth transition and maintain confidence in their Cyber Essentials certification.
Prepare for the April 2026 Cyber Essentials Changes with Shonsys
The April 2026 updates introduce stricter marking criteria, mandatory MFA for cloud services, new auto-fail patch management requirements, and important changes to Cyber Essentials Plus. Preparing early is critical to avoid automatic failure under the new rules.
Start your Cyber Essentials journey with Shonsys, an NCSC Assured Service Provider and IASME Licensed Certification Body. We guide you through the entire assessment process, helping you understand the updated requirements, strengthen your controls, and help you by providing guidance to resolve any issues that could lead to failure especially under the new auto-fail criteria.
Whether you are applying for the first time or renewing your certification, our experts ensure your organisation is fully aligned with the updated Cyber Essentials requirements, including the April 2026 changes, before submission.
Book your free readiness call:
https://calendly.com/shonsys/cyber-essentials-call
SHONSYS supports organisations across Edinburgh, Glasgow, Scotland, and the UK to achieve Cyber Essentials and Cyber Essentials Plus with confidence, clarity, and full compliance under the updated 2026 framework.