Cyber Essentials 2026: What Is Changing and Why It Matters
From April 27, 2026, the Cyber Essentials scheme will introduce its most significant set of changes in years. Organisations currently certified -- or planning to achieve certification -- need to understand what is changing, why it matters, and how to prepare.
The National Cyber Security Centre (NCSC) and IASME review the scheme annually to ensure it remains relevant against modern threats. This year's update reflects how cloud services, multi-factor authentication, and passwordless technologies have evolved. Six months' notice has been provided to give applicants time to adapt.
The most impactful change involves multi-factor authentication for cloud services. Where cloud services have MFA available -- whether free, included in the service, connected through another service, or behind a paywall -- and it is not implemented, this will result in an automatic failure.
Previously, if a cloud service required a licence upgrade or additional cost to enable MFA, organisations were not required to pay for it to pass Cyber Essentials. From April 2026, MFA must be enabled regardless of cost or complexity. This closes a significant gap that attackers have exploited for years.
For the first time, the scheme now includes a formal definition of what qualifies as a cloud service. This removes ambiguity about whether certain features, services, or tools fall under cloud service requirements. Expect clearer guidance on which systems require MFA, secure configuration, and regular patching.
The user access control section has been updated to place greater emphasis on passwordless authentication methods, particularly passkeys. The NCSC is actively encouraging organisations to adopt passkeys as the default authentication method, as they offer faster, easier, and more secure access than traditional passwords combined with MFA.
Guidance on backups has been repositioned earlier in the requirements document -- immediately following definitions and before the scope overview. This signals the importance of having tested, accessible backups in place, particularly in the context of ransomware and destructive cyber incidents. The message is clear: backups are not optional.
Organisations should act now. If you are planning to achieve Cyber Essentials certification, assess whether you can meet the updated requirements or whether it makes sense to complete certification under the current framework before April 27, 2026. If you are already certified, review your cloud services and MFA implementation to ensure you will remain compliant when your certificate comes up for renewal.
For most organisations, the changes are achievable -- but they will require planning, budget approval, and potentially licence upgrades. Leaving it until the last minute will create unnecessary risk and delays.
At STG, we help organisations navigate Cyber Essentials requirements, implement the technical controls, and prepare for both self-assessment and Cyber Essentials Plus audits. If you need clarity on what the 2026 changes mean for your organisation, now is the time to talk.
