Reliable Networks | Managed IT and Cyber Security Experts

The Cyber Essentials “Auto-Fail” Updates You Need to Know

If your Cyber Essentials renewal is coming up, there’s an important update you shouldn’t overlook.

Every year, the National Cyber Security Centre (NCSC) reviews and updates the document that sets out exactly what’s required to achieve Cyber Essentials certification. Known as the Requirements for IT Infrastructure, it evolves alongside the changing cyber threat landscape, helping to clarify existing requirements and introduce new ones where needed. The latest version, 3.3, was published in April this year, and while the overall framework will feel familiar to anyone who’s completed Cyber Essentials before, there are a couple of absolutely critical changes that deserve your attention.

What’s changed?

The good news is that the core areas of Cyber Essentials remain exactly the same. Your assessment will still focus on secure configuration, user access controls, malware protection, security update management and firewalls. However, the way some of the requirements are assessed is different.

A few of the controls that were previously treated as best practice, or were highly recommended but not mandatory for certification, have become non-negotiable. That means failing to meet them can now result in an automatic failure, even if every other part of your assessment is strong.

Here’s what to be aware of:

1. Multi-factor authentication (MFA) for cloud services is now essential. Wherever a cloud service supports MFA, it now has to be switched on. It doesn’t matter whether the feature is included as standard or available as an optional extra that you pay for; if the service offers it, you must use it. 

2. Critical and high-risk patches for operating systems, business applications, firewalls and routers now need to be installed within 14 days of becoming available. Leaving serious vulnerabilities unpatched beyond that window is no longer something assessors are able to overlook.

What this means for you

It’s easy to assume that because you’ve passed Cyber Essentials before, renewing will simply be a case of ticking the same boxes again. But with the scheme continuing to evolve, the measures that met the standard last year may not meet it today, which means it’s important to double-check things. 

Before it’s time for your renewal, take a look at any devices or systems that are no longer supported. If they can’t receive security updates anymore, they either need to be upgraded or isolated from the rest of your network. Unfortunately, leaving them in place could jeopardise your entire assessment.

Also be sure to spend some time reviewing every cloud service your business uses to check that multi-factor authentication is enabled wherever it’s available. It’s one of the simplest ways to reduce the risk of unauthorised access, and it’s now an essential part of achieving certification.

If you’re unsure whether your systems are ready, having a second set of eyes take a look over your systems and settings before renewal time is never a bad idea. After all, even the smallest oversight could cost you your certification, put your reputation at risk, and potentially affect customer confidence. With the right support, though, staying compliant is usually far simpler than many businesses expect, so get in touch with us here at Reliable for tailored advice and recommendations.

How Secure Is Your Business?
Get a Clear View of Your Biggest Cyber Risks

Find out where you’re exposed, what’s protected, and the practical steps to reduce risk without slowing your team down.

Picture of Gregory Olczyk

Gregory Olczyk

Latest articles

The Cyber Essentials “Auto-Fail” Updates You Need to Know

Why Small Businesses Are a Cybercriminal’s Dream

How Secure Is Your Business?

Fill in the form below to Check your security.