Cyber Essentials and Cyber Essentials Plus are the UK’s benchmark for cyber security. Recently, the standard was strengthened to address evolving cyber threats. These changes mean tighter assessment, stronger evidence, and more rigorous enforcement.
For businesses, this wasn’t just a compliance update – it’s about embedding security as a continuous process rather than a once-a-year exercise.
Why the update?
Cyber Essentials remains the baseline, but recent cyberattacks highlighted where previous checks missed real-world risks. The new requirements close those gaps, reduce ambiguity, and demand proof, not promises.
What’s changed?
MFA is now mandatory on all cloud services
Multi-factor authentication (MFA) is no longer optional. If a cloud application supports MFA and it is not enforced for every user, you will fail certification. This includes:
- Email platforms
- SaaS applications (CRM, HR, finance systems)
- Admin and remote access tools
Critical patches must be applied within 14 days
Operating systems, apps, firewalls, and routers must be updated within two weeks of a critical or high-risk patch release. If you miss the window, you fail the assessment, and there are no longer grace periods.
Scope must be clear and complete
Every tool that stores or processes your data, including cloud services, is in scope. You now need:
- A full inventory of systems
- Explicit inclusion/exclusion rationale
- Transparency on legal entities
Proof over declarations
Assessors want evidence, not tick-box statements. You must show that security controls are enforced across your entire environment, not just on a sample device.
Why businesses are getting caught out
- MFA enabled in some places, not all
- SaaS platforms outside IT control
- Patch practices inconsistent across teams
- Security settings loosened between annual reviews
- Responsibilities unclear between internal teams and suppliers
Cyber Essentials is still a baseline – but it now demands a new level of discipline
Cyber Essentials remains the UK’s baseline for cyber security. However, recent update raises the bar significantly. Controls that once passed on trust now require evidence, and what was “best practice” is quickly becoming “minimum requirement”.
For many organisations, this means proving a level of discipline and consistency that hasn’t been needed before.
Cyber Essentials is no longer a once-a-year exercise
Certification is still assessed at a single point in time, but the new requirements make it harder to treat Cyber Essentials as a once-off annual tick-box. Identity controls, patching, configuration, and visibility now need to be right all year round – not just in the days before an audit.
If your business relies on Cyber Essentials certification for contracts, tenders or supplier assurance, the commercial risk of failing – or losing certification mid-term – is higher than ever.
Board-level accountability for ongoing compliance
The declaration signed during the Verified Self-Assessment (VSA) is changing. It will now explicitly confirm the organisation’s responsibility to uphold compliance throughout the full 12-month certification period – not only at the point of submission.
This reinforces continuous adherence and places clear accountability at board level. Cyber Essentials is moving from a compliance milestone to a governance obligation.
What this means in practice
Certification is no longer about whether controls exist on paper; it’s about proving they work day-to-day. Businesses that build security into routine operations – rather than annual preparation – will be better placed for uninterrupted certification.
In practical terms, this means:
- Continuous readiness, not “audit week mode”.
- MFA, patching, and asset controls monitored and enforced consistently.
- Stronger governance of SaaS and cloud tools.
- More automation for patch management.
- Clear accountability between in-house teams and external partners.
Informal approaches that once passed assessment will no longer hold up. Evidence must reflect reality, not last-minute fixes. Success now depends on confidence that, at any point in time, your environment would meet the standard.
How razorblue can help
We’ll help you prepare, comply and stay compliant, including:
- Readiness assessments and gap analysis
- MFA configuration and enforcement across all apps
- Automated patch management for consistent delivery
- Ongoing monitoring for year-round compliance
- Advisory support for scope definition and board sign-offs
For you, this helps provide full peace of mind that your business remains secure, audit-ready and certification-approves.