Phone 0333 880 0000
Locate Find an Office
Status Remote Support
Network Service Status

Cyber Essentials: What’s Changed and Why It Matters

Cyber Essentials and Cyber Essentials Plus are the UK’s benchmark for cyber security. Recently, the standard was strengthened to address evolving cyber threats. These changes mean tighter assessment, stronger evidence, and more rigorous enforcement. 

For businesses, this wasn’t just a compliance update – it’s about embedding security as a continuous process rather than a once-a-year exercise. 

Why the update? 

Cyber Essentials remains the baseline, but recent cyberattacks highlighted where previous checks missed real-world risks. The new requirements close those gaps, reduce ambiguity, and demand proof, not promises. 

What’s changed? 

MFA is now mandatory on all cloud services 

Multi-factor authentication (MFA) is no longer optional. If a cloud application supports MFA and it is not enforced for every user, you will fail certification. This includes: 

  • Email platforms
  • SaaS applications (CRM, HR, finance systems) 
  • Admin and remote access tools 

Critical patches must be applied within 14 days 

Operating systems, apps, firewalls, and routers must be updated within two weeks of a critical or high-risk patch release. If you miss the window, you fail the assessment, and there are no longer grace periods.  

Scope must be clear and complete 

Every tool that stores or processes your data, including cloud services, is in scope. You now need: 

  • A full inventory of systems 
  • Explicit inclusion/exclusion rationale 
  • Transparency on legal entities 

Proof over declarations 

Assessors want evidence, not tick-box statements. You must show that security controls are enforced across your entire environment, not just on a sample device.  

Why businesses are getting caught out 

  • MFA enabled in some places, not all  
  • SaaS platforms outside IT control  
  • Patch practices inconsistent across teams 
  • Security settings loosened between annual reviews 
  • Responsibilities unclear between internal teams and suppliers 

Cyber Essentials is still a baseline – but it now demands a new level of discipline 

Cyber Essentials remains the UK’s baseline for cyber security. However, recent update raises the bar significantly. Controls that once passed on trust now require evidence, and what was “best practice” is quickly becoming “minimum requirement”. 

For many organisations, this means proving a level of discipline and consistency that hasn’t been needed before. 

Cyber Essentials is no longer a once-a-year exercise  

Certification is still assessed at a single point in time, but the new requirements make it harder to treat Cyber Essentials as a once-off annual tick-box. Identity controls, patching, configuration, and visibility now need to be right all year round – not just in the days before an audit. 

If your business relies on Cyber Essentials certification for contracts, tenders or supplier assurance, the commercial risk of failing – or losing certification mid-term – is higher than ever. 

Board-level accountability for ongoing compliance 

The declaration signed during the Verified Self-Assessment (VSA) is changing. It will now explicitly confirm the organisation’s responsibility to uphold compliance throughout the full 12-month certification period – not only at the point of submission. 

This reinforces continuous adherence and places clear accountability at board level. Cyber Essentials is moving from a compliance milestone to a governance obligation. 

What this means in practice 

Certification is no longer about whether controls exist on paper; it’s about proving they work day-to-day. Businesses that build security into routine operations – rather than annual preparation – will be better placed for uninterrupted certification. 

In practical terms, this means: 

  • Continuous readiness, not “audit week mode”. 
  • MFA, patching, and asset controls monitored and enforced consistently. 
  • Stronger governance of SaaS and cloud tools. 
  • More automation for patch management. 
  • Clear accountability between in-house teams and external partners. 

Informal approaches that once passed assessment will no longer hold up. Evidence must reflect reality, not last-minute fixes. Success now depends on confidence that, at any point in time, your environment would meet the standard. 

How razorblue can help 

We’ll help you prepare, comply and stay compliant, including: 

  • Readiness assessments and gap analysis 
  • MFA configuration and enforcement across all apps  
  • Automated patch management for consistent delivery  
  • Ongoing monitoring for year-round compliance  
  • Advisory support for scope definition and board sign-offs 

For you, this helps provide full peace of mind that your business remains secure, audit-ready and certification-approves.  

Talk to us today about the Cyber Essentials changes

Related Articles