If your Cyber Essentials certification renewal is coming up, there’s an important update you shouldn’t overlook.
Every year, the National Cyber Security Centre (NCSC) reviews and updates the document that sets out exactly what’s required to achieve Cyber Essentials certification. Known as the Requirements for IT Infrastructure, it evolves alongside the changing cyber threat landscape, helping to clarify existing requirements and introduce new ones where needed.
The latest version, 3.3, goes live in April 2026, transitioning to a new assessment question set known as ‘Danzell’. While the overall framework will feel familiar to anyone who’s completed Cyber Essentials before, there are a couple of absolutely critical changes that deserve your attention.
What’s changed?
The good news is that the core areas of Cyber Essentials remain exactly the same. Your assessment will still focus on secure configuration, user access controls, malware protection, security update management, and firewalls.
However, the way some of the requirements are assessed is different. A few of the controls that were previously treated as best practice, or were highly recommended but not mandatory for certification, have become non-negotiable. That means failing to meet them can now result in an automatic failure, even if every other part of your assessment is strong.
Here’s what to be aware of:
-
Multi-factor authentication (MFA) is now mandatory. Wherever a cloud service supports MFA, it now has to be switched on for all users. It doesn’t matter whether the feature is included as standard, delivered through a third party, or available only as a paid optional extra; if the service offers it, you must use it. Not enabling MFA when available will result in an automatic assessment failure.
-
Strict 14-day patching rules. All critical and high-risk security updates for operating systems, business applications, router firmware, and firewalls must be installed within 14 days of release. Leaving serious vulnerabilities unpatched beyond that window is no longer something assessors are able to overlook. This specifically applies to anything fixing a vulnerability rated critical or high by the vendor, or anything with a CVSS v3 score of 7.0 or above.
What this means for you
It’s easy to assume that because you’ve passed Cyber Essentials before, renewing will simply be a case of ticking the same boxes again. But with the scheme continuing to evolve, the measures that met the standard last year may not meet it today, which means it’s important to double-check things.
Before it’s time for your renewal, take a look at any devices or systems that are no longer supported. When software reaches the end of its support lifecycle, it can no longer receive security updates. It must either be removed from the environment entirely or isolated in a sub-set that genuinely blocks all internet traffic. Leaving unsupported software in place could jeopardise your entire assessment.
Also, be sure to spend some time reviewing every cloud service your business uses to check that multi-factor authentication is enabled wherever it’s available. It’s one of the simplest ways to reduce the risk of unauthorised access, and it is now an essential part of achieving certification.
🛡️ Ensure Your 2026 Certification is Secure
If you’re unsure whether your systems are ready for the v3.3 updates, having a second set of eyes take a look over your systems and settings before renewal time is never a bad idea. After all, the UK Government reports that organisations implementing Cyber Essentials controls make 92% fewer cyber insurance claims.
Even the smallest oversight could cost you your certification, put your reputation at risk, and potentially affect customer confidence. With the right support, staying compliant is usually far simpler than many businesses expect.
Don’t risk an automatic assessment failure. Get in touch with us at Reliable Networks for a comprehensive IT Security Health Check to ensure your cloud environments, endpoints, and access policies meet the strict new standards.
How Secure Is Your Business?
Get a Clear View of Your Biggest Cyber Risks
Find out where you’re exposed, what’s protected, and the practical steps to reduce risk without slowing your team down.

