What Is Cyber Essentials and Why Did It Get Harder to Pass?

For many businesses, Cyber Essentials is a certificate you earn, file away, and renew each year without giving it much thought, and for many, they thought this was fine. 

In 2026, this isn’t an attitude any business can take. The scheme has gotten harder to pass, and plenty of businesses who sailed through last time are in for a surprise at their next renewal. 

This is because the five critical technical controls Cyber Essentials asks of you haven’t changed, but the way they’re marked has. If you miss a critical security update by more than a fortnight or leave multi-factor authentication switched off on a cloud service that offers it, you now fail automatically. 

What this means is that Cyber Essentials is becoming a condition of doing business, with clients asking for it, tenders demanding it, and insurers looking for it. As cyber security evolves into a board-level responsibility rather than something left to whoever manages the IT, you can’t afford to simply assume that you’re covered. 

So here’s what Cyber Essentials actually covers, what changed in 2026, and why it’s worth knowing where your business stands before a client or a tender asks the question for you. 

So, What Is Cyber Essentials? 

Cyber Essentials is the UK’s government-backed baseline for cyber security. It isn’t a heavyweight framework like ISO 27001, and it isn’t trying to be. It sets out five basic controls that, done properly, shut the door on the overwhelming majority of everyday attacks: the opportunistic stuff that goes looking for whoever’s left a window open. The National Cyber Security Centre puts it well: most attacks are basic, the digital equivalent of a thief trying your front door to see if it’s unlocked. These five controls keep it locked. 

Those five controls sit at the heart of the Cyber Essentials requirements: 

  • Firewalls: a secure barrier between your networks and the internet. 
  • Secure configuration: setting devices and software up safely, rather than leaving factory defaults and unused features in place. 
  • User access control: making sure people can only reach what their role needs, and admin rights aren’t handed out freely. 
  • Malware protection: keeping anti-malware in place and up to date across your devices. 
  • Security update management: applying updates and patches promptly, especially the critical ones. 

None of that sounds overly dramatic, and it isn’t meant to, which is exactly why it’s easy to assume you’ve already got it covered. The numbers suggest otherwise: only 24% of UK businesses actually have all five controls in place, and just 17% are even aware the scheme exists. 

Self-Assessment or Cyber Essentials Plus? 

Cyber Essentials comes in two tiers. The basic level is self-assessed: you complete a questionnaire confirming your controls are in place, and a certification body reviews your answers. Cyber Essentials Plus is the same five controls, independently tested. An assessor carries out a hands-on audit, including a vulnerability scan, rather than taking your word for it. 

That difference matters commercially. Self-assessment is enough for plenty of situations, but Cyber Essentials Plus is the version larger clients and public sector buyers increasingly want to see. 

Why It Got Harder to Pass 

Here’s what changed in 2026. The scheme’s technical requirements were updated, along with the questions you’re marked against (the new question set is known as Danzell). The five controls stayed exactly the same. The big changes are how strictly two of them are now marked and the auto-fail they attract. 

An auto-fail does what it says on the tin. Get one of these two things wrong and you fail the whole assessment, no matter how solid everything else is. 

The first is multi-factor authentication on cloud services. If you use a cloud service that offers MFA, Microsoft 365 being the obvious example, and you haven’t switched it on, that alone now fails you. It doesn’t matter that turning it on is usually free and takes minutes. Leaving it off is no longer something the scheme is willing to overlook. 

The second is patching. High-risk and critical security updates now must be applied within 14 days of release. Miss that window on your operating systems, your applications, or your firewalls, and again, it’s an automatic fail. For any business that patches “when we get round to it” rather than on a schedule, that’s a real shift. 

None of this is designed to catch people out. The controls haven’t moved. But the scheme has stopped giving credit for “mostly”. If your MFA and patching are genuinely tight, you’ve little to worry about. If they’ve been just about good enough to scrape through before, that’s exactly where the new rules will find you. 

Which raises the obvious question: would your business actually pass today? 

Why It’s Worth Passing 

So the bar’s higher. Is it worth clearing? For a growing number of businesses, the honest answer is that they don’t really get a choice, because Cyber Essentials has quietly become a condition of winning and keeping work. 

Here’s where it shows up: 

  • Winning tenders and contracts: Public sector buyers have required Cyber Essentials for years, and private-sector clients are catching up fast. On plenty of bids now, no certificate means you don’t make the shortlist. 
  • Supplying bigger businesses: If you sell to larger organisations, expect them to ask whether you hold it, often as a straight yes or no on a supplier form. It’s becoming part of onboarding, sitting alongside references and financial checks. 
  • Winning trust: Certification is a simple, recognised signal that you take security seriously. For a prospect weighing you up against a competitor, “we’re Cyber Essentials certified” does quiet, useful work. 

Then there’s insurance, and this one cuts both ways. Insurers increasingly expect to see the basics the scheme covers, MFA and prompt patching, among them, before they’ll offer sensible terms. But certification also comes with something concrete: any UK business with a turnover under £20m that certifies its whole organisation is entitled to £25,000 of cyber liability insurance, included with the certificate, plus access to a 24-hour incident response line if the worst happens. For a smaller business, that’s a real safety net attached to a certificate you were being nudged towards anyway. 

And here’s the part that makes all of this worth acting on sooner rather than later: hardly anyone has it yet. Only 5% of UK businesses currently hold Cyber Essentials, up from 3% a year earlier, and among small businesses specifically the figure has more than doubled, from 5% to 12%. It’s still rare enough that holding it sets you apart, and becoming common enough that not holding it is starting to get noticed. That gap won’t stay open forever. 

Would You Pass? There’s Only One Way to Know 

The tougher marking isn’t a reason to panic. For plenty of businesses, the five controls are closer to being met than they’d assume, and the gap is a couple of fixable things rather than a wholesale overhaul. 

But “we think we’d be fine” and “we’ve checked” are two very different positions to be in when a client, a tender or an insurer asks the question. The businesses that get caught out are the ones who took last year’s certificate as proof this year’s setup would sail through. 

If you’re an Essex business that supplies bigger clients, bids for work, or simply wants to know it’s genuinely covered, the sensible first step is to find out where you actually stand against the current requirements before someone else does it for you. 

That’s exactly what our Cyber Essentials support is built to help with. No pitch, no pressure. Speak to us about it today to get a clear picture of where your business sits today and what it would take to pass. 

FAQs 

What is Cyber Essentials, in plain terms? 
Cyber Essentials is the UK’s government-backed baseline for cyber security. It sets out five basic technical controls that, done properly, protect against the most common online attacks. It’s the minimum standard the NCSC recommends for organisations of any size, and it comes in two levels: self-assessed and the independently tested Cyber Essentials Plus. 

What are the five Cyber Essentials controls? 
Firewalls, secure configuration, user access control, malware protection, and security update management. Between them they cover the practical basics: keeping a barrier between your network and the internet, setting things up safely, controlling who can access what, keeping malware out, and applying updates promptly. 

What changed in Cyber Essentials in 2026? 
The five controls stayed the same, but the marking got stricter, and two things became automatic fails. If a cloud service offers multi-factor authentication and you haven’t switched it on, that now fails the whole assessment. And if you don’t apply high-risk or critical security updates within 14 days of release, that fails it too. So a business that passed comfortably last year can fail this year without changing a thing. 

What’s the difference between Cyber Essentials and Cyber Essentials Plus? 
Both cover the same five controls. The basic level is self-assessed: you complete a questionnaire and an assessor marks it. Cyber Essentials Plus adds an independent, hands-on technical audit that verifies the controls are actually in place rather than taking your word for it. Plus is the version larger clients and public sector buyers increasingly want to see. 

How do I know if my business would pass? 
The honest answer is that you don’t, until you’ve checked against the current requirements. Most businesses are closer than they think, but the two auto-fail areas, MFA and 14-day patching, are where good intentions often fall short. A quick review against today’s rules tells you where you stand and what, if anything, needs fixing. 

Looking for something specific?