Cyber Essentials has evolved.
The National Cyber Security Centre (NCSC) has introduced updates to Cyber Essentials designed to strengthen baseline cyber security and better reflect how organisations operate today. While the five core controls remain the same, the latest changes place greater emphasis on identity security, cloud services and patch management.
The key changes
Multi-factor authentication is now mandatory
If a cloud service offers multi-factor authentication (MFA), it must be enabled for all users. Organisations that fail to implement MFA where it's available could automatically fail their assessment. Password less authentication methods, such as passkeys and hardware tokens, are also encouraged.
Cloud services cannot be excluded
Cloud platforms, collaboration tools and business applications are now formally within scope. Organisations remain responsible for these services, even when managed by a third-party provider.
Stronger patching requirements
Critical and high-risk updates for operating systems, applications and network devices must be applied within 14 days. Failure to do so could result in an automatic failure.
Clearer scoping rules
The updated requirements make it harder to exclude devices, users or systems that could create cyber risk, helping organisations gain a more accurate view of their environment.
Why it matters
These are positive and long overdue improvements that address well-known gaps in the scheme. At Solis, we regularly see incidents where compromised identities, missing patches or overlooked systems have created opportunities for attackers.
The updated Cyber Essentials requirements help organisations strengthen these areas and demonstrate good cyber hygiene. However, certification should be viewed as the starting point, not the finish line. Cyber Essentials is a point-in-time assessment, and effective security requires continuous monitoring and enforcement.
Cyber threats continue to evolve, and security controls need to evolve with them.
Contact our team today at ask@solissecurity.com and we'll be happy to tell you more about how we can protect your business.