OneClickComply
    Back to BlogCyber Security Updates

    Upcoming Changes to Cyber Essentials in 2026

    Finn O’Brien
    24 November 2025

    Cyber Essentials is getting its annual update, and the April 2026 version (Requirements for IT Infrastructure v3.3) includes some meaningful refreshes. For any assessment account created from 27 April 2026, v3.3 will apply, and organisations will have six months from account creation to complete their certification.

    The core of Cyber Essentials remains the same. It still centres on the same five technical controls: implementing firewalls, securing device and system settings, keeping software up to date, controlling user access, and protecting against malware. What has changed is how the scheme expects these to be applied in a modern business environment, especially one that relies heavily on cloud services and software development.

    If your business plans to certify or renew around that date, it’s worth understanding these upcoming changes now, because some of them may alter what sits in scope and what evidence you’ll need to provide.


    1. Cloud services can no longer be excluded from scope

    This is the most significant change in v3.3. The updated requirements specify that cloud services cannot be excluded from Cyber Essentials scope. Put simply, if your organisation uses cloud services to store or process business data, they are automatically in scope.

    Cloud services are things like Microsoft 365, Google Workspace, Salesforce, HubSpot, Xero, AWS, Azure, GCP, online file storage, hosted applications, and many other web-based tools that many businesses now depend on to operate. In previous versions, some organisations scoped these out, sometimes unintentionally, sometimes to keep the assessment smaller. Under v3.3, this approach is no longer acceptable.

    The core impact of this change is that you will now need to inventory those cloud services, show they meet the five Cyber Essentials controls, and collect evidence to prove it. If you’re going for Cyber Essentials Plus (which includes independent testing), any in-scope cloud services may fall within the testing approach depending on how they meet your scope. This can significantly increase the number of in-scope assets, and the amount of evidence you need, particularly if you rely on a wide range of SaaS tools.

    v3.3 also tightens the rules around multi-factor authentication (MFA) for cloud services.

    Under the refreshed marking guidance, if a cloud service you use offers MFA in any form (whether free, built-in, through a connected service, or even as a paid add-on) and you haven’t enabled it, the assessment will automatically fail. In previous versions, there was more room for interpretation, whereas this updated version draws a line in the sand. Where MFA is available for an in-scope cloud service, it must be enabled.

    What to do now is fairly straightforward, even if it’s a bit of extra legwork. Start by building a full list of cloud services you use, then update your scope and asset register to include them. Lastly, map each cloud service to the relevant controls, especially strong access settings like MFA, secure configuration of storage and identities, and evidence that the service is being managed safely.


    2. A formal definition of “cloud services” is now included

    To avoid potential grey areas, v3.3 introduces a clear definition of what counts as a cloud service. This matters because many businesses use services that feel like “hosting” or “managed IT,” but still behave like cloud systems in practice.

    Under the new definition, if a service is delivered over the internet, is managed or hosted externally, and holds or processes your data, it should be treated as cloud and included in scope.

    This change doesn’t add new controls on its own, but it removes ambiguity and potential confusion. If something fits the definition, it must be covered.

    The best course of action here is to review the definition carefully and reclassify any services that are currently sitting a ‘grey area.’ Doing this early will prevent a last-minute scope adjustment when you are halfway through an assessment.


    3. A Software Security Code of Practice is introduced for development

    v3.3 introduces a Software Security Code of Practice within the Software Development section. This affects organisations that build software, either as a product, or internally for their own operations.

    If you’re not a software producer, this section may not change much for you. But if you do develop software, the scheme is now more explicit about what “secure development” means. The Code of Practice sets out expectations such as using secure coding standards, managing software dependencies safely, testing for vulnerabilities, and having a clear way to patch and fix issues once software is launched.

    Put more simply, Cyber Essentials is moving beyond the “protect your IT” approach, and is starting to reflect the reality that insecure software can also become a supply-chain risk. If you build applications, an assessor may want evidence that you develop and maintain them responsibly, not just that the laptops you use are secure.

    To prepare for this upcoming change, review the Code of Practice and compare it against how you build software today, and then formalise what you already do. That could include documenting secure coding rules, showing how you track and fix vulnerabilities, and providing evidence from your development pipeline or security testing processes.


    4. Scoping language has changed to remove confusion

    v3.3 removes reference to “untrusted connections” in the scope guidance. It also removes the term “user-initiated.” Together, these changes move Cyber Essentials away from slightly vague labels and towards explicit definitions of what is connected, what is in scope, and why.

    The scheme is now much clearer: any internet-connected device or service that meets the scope definitions is considered in scope, regardless of whether it initiates a connection outwards or receives one inwards. Most organisations were already applying controls this way, but v3.3 makes the expectation clearer and reduces room for interpretation.

    If your scope currently relies on “trusted/untrusted” or “user-initiated” language, you’ll want to rework it into something more concrete.


    5. Passwordless authentication guidance now includes FIDO2 (and what that means)

    v3.3 updates its definition of passwordless authentication to include FIDO2. If this acronym means nothing to you, here’s an explanation.

    FIDO2 covers passkeys and hardware-based logins that don’t rely on a password. You might have seen these already on personal accounts, such as logging into an app using Face ID, a fingerprint, a phone prompt, or a physical security key. The Cyber Essentials scheme is now confirming that these methods count as compliant forms of passwordless authentication, as long as they’re managed properly.

    For businesses already moving away from passwords, this is helpful clarity, but it doesn’t remove the need for strong access control. You still need good processes for registering devices, recovering access if someone loses their phone or key, and ensuring only the right people can use these login methods. But this change addresses the uncertainty about whether passwordless approaches are acceptable under the scheme. Good news - they are.


    6. Backups and Zero Trust guidance are being emphasised

    v3.3 puts stronger emphasis on backups as a ransomware and resilience control. This isn’t a brand-new requirement, but it does suggest increased assessor focus. The scheme is reminding organisations that it isn’t enough to say you back up data, you should be able to show that backups take place, are protected, and tested regularly.

    If your backups haven’t been tested for a while, now is the time to fix that. Evidence likely to help includes a documented backup policy, logs that show backups completing, and proof of regular restore testing.

    The update also includes more guidance around Zero Trust. Zero Trust is a security approach built on the principle “never trust, always verify.” Rather than assuming something inside your network is safe, it treats every access request as something that should be validated through identity checks, least-privilege access, and segmentation. The guidance here is advisory rather than prescriptive, but it reflects expectations around access and networking.


    What this means for your 2026 plan

    If you’re renewing early in 2026, you may still be able to certify under v3.2 depending on when your assessment account is created. But any assessment starting after late April 2026 will fall under v3.3 by default.

    The businesses most affected by these changes are those with significant SaaS usage, cloud-heavy environments, and software development activity. None of the updates are unreasonable, but they do require earlier planning, especially around cloud scoping, MFA enforcement, and evidence.

    Now that this guidance has been released, a sensible move now is to treat the remainder of 2025, and the beginning of 2026 as preparation time. Get a full cloud inventory in place, confirm MFA coverage across those services, and make sure your technical hygiene is strong. If software development applies to you, start mapping the Code of Practice into your processes early so it’s not a sudden scramble later on.


    How OneClickComply helps you get ahead of v3.3

    In total, these changes are mostly about visibility. You need to know what tools and services you use, whether they’re secured properly, and whether your controls stay in place over time.

    OneClickComply is designed to make that easier.

    We run automatic technical gap analysis across your environment, including cloud services that are now mandatory for scope. That means you can see where Cyber Essentials controls are missing or misconfigured, and fix them automatically in a single click, with Continuous Monitoring monitoring in the background to ensure that these settings remain in place at all times.

    On the governance side, OneClickComply includes built-in ISMS tools like asset registers, incident logs, and vendor risk tracking, making it easier to evidence what the scheme expects without building everything from scratch.

    Finally, our device vulnerability management feature continuously detects outdated software and known security flaws, helping you stay aligned with patching and secure configuration requirements not just at audit time, but throughout the entire year.

    In short, we help you understand what v3.3 will expect, close gaps quickly, and keep everything on track continuously.

    Want to see OneClickComply in action?

    Book a demo and see how we automate compliance for organisations like yours.

    Book a Demo