Cyber Essentials has had one of its biggest updates in years
if you’re certified (or planning to be), there are two major changes you need to act on now:
These aren’t “nice-to-haves” anymore in some cases, they’re pass/fail criteria. Let’s break down what’s changed, why it matters, and what you should do next.
1. Multi-Factor Authentication (MFA) is now mandatory on cloud services
Under the April 2026 Cyber Essentials update, MFA is no longer optional. If a cloud service supports MFA and it’s not enabled, your assessment can automatically fail:
Key takeaway:
If your team can log in with just a password, you’re exposed — and potentially non-compliant.
Why MFA matters (In Simple Terms)
MFA works by combining:
Even if a password is stolen, attackers still can’t get in without the second factor.
2. Password rules have shifted: Length over complexity
Another key update is the move toward longer passwords (12+ characters). Instead of forcing complex rules (symbols, uppercase, etc.), Cyber Essentials now prioritises:
The updated guidance recognises three approaches, including:
In Practice, If MFA is enabled, password length can be shorter. If MFA is not available, 12+ characters becomes critical
3. What about existing certifications?
If you were certified before April 2026, you’re not immune to the changes. There’s a six-month transition window to move onto the new standard. That means, You will need to update your controls as waiting until renewal is risky as you will be leaving Gaps (especially MFA) and could delay recertification.
Common pitfalls we’re already seeing
Common Pitfalls We’re Already Seeing
These are exactly the kinds of gaps that now lead to automatic failures.
Final Thoughts
Cyber Essentials hasn’t just “changed”, it’s raised the bar. And rightly so.
With cloud services now at the centre of how businesses operate, identity security (who can access what) is the new frontline.
If MFA isn’t everywhere yet, now’s the time.
