In 2026, Cyber Essentials and Cyber Essentials Plus remain the UK’s leading government-backed cybersecurity certifications. Backed by the National Cyber Security Centre (NCSC) and delivered through IASME, these schemes help organisations of all sizes protect against the most common cyber threats. With updated requirements under version 3.3 (the Danzell question set) effective from 27 April 2026, understanding Cyber Essentials and Cyber Essentials Plus has never been more important.
This guide covers everything you need to know about Cyber Essentials and Cyber Essentials Plus in 2026, including the key differences, the five technical controls, major 2026 updates, and how to achieve certification.
What Is Cyber Essentials?
Cyber Essentials is a UK government scheme that sets a baseline standard of cybersecurity. It focuses on five technical controls proven to block the majority of common internet-based attacks. Organisations complete a self-assessment questionnaire, which is independently reviewed and verified by a licensed Certification Body. A senior person (usually a board member or equivalent) must sign off the answers.
Cyber Essentials certification is valid for 12 months and is widely required for UK government contracts, supply-chain assurance, and by many private-sector clients. It also unlocks free cyber liability insurance for eligible organisations (typically those with turnover under £20 million when the whole organisation is certified).
What Is Cyber Essentials Plus?
Cyber Essentials Plus builds on the same five technical controls as standard Cyber Essentials, but adds independent technical verification. Instead of relying only on the questionnaire, an approved assessor performs hands-on testing. This includes vulnerability scanning, device sampling, checks on malware protection, and verification that controls actually work in practice.
You can pursue Cyber Essentials Plus without holding a separate Cyber Essentials certificate first (the process incorporates the self-assessment). However, once basic Cyber Essentials is certified, you normally have a three-month window to complete Cyber Essentials Plus.
Cyber Essentials Plus is increasingly demanded for higher-assurance contracts, including many NHS supplier requirements and larger enterprise tenders.
Cyber Essentials vs Cyber Essentials Plus: Key Differences in 2026
| Aspect | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Controls assessed | Same five technical controls | Same five technical controls |
| Assessment method | Verified self-assessment questionnaire | Self-assessment + independent technical testing |
| Testing | Questionnaire review only | Device sampling, vulnerability scans, live checks |
| Time pressure | Annual renewal | Usually within 3 months of basic certification |
| Assurance level | Good baseline | Higher, independently verified |
| Typical use cases | First certification, many contracts | Government/NHS tenders, enterprise clients |
Both levels assess the identical technical requirements. The difference is purely in the depth of verification.
The Five Technical Controls of Cyber Essentials and Cyber Essentials Plus
Every Cyber Essentials and Cyber Essentials Plus assessment is built around these five controls:
- Firewalls – Boundary and host-based firewalls must be correctly configured to restrict unnecessary inbound and outbound traffic.
- Secure Configuration – Devices and services must be hardened: default passwords changed, unused accounts and services disabled, auto-run restricted.
- Security Update Management – High-risk and critical patches (including firmware) must be applied promptly.
- User Access Control – Least-privilege access, unique accounts, strong authentication, and proper management of administrator privileges.
- Malware Protection – Effective anti-malware or equivalent controls on all in-scope devices.
These controls apply across all in-scope systems, including cloud services, remote-working devices, and network equipment.
Major Cyber Essentials and Cyber Essentials Plus Changes in 2026
The biggest update for 2026 is the move to Requirements for IT Infrastructure version 3.3 and the Danzell question set, effective for assessment accounts created from 27 April 2026 (with transitional arrangements for earlier accounts).
Key changes affecting both Cyber Essentials and Cyber Essentials Plus include:
- Mandatory MFA for all users – Multi-factor authentication must be enabled on every cloud service that offers it. Failure is now an automatic fail. This applies to all users, not just administrators.
- 14-day patching as an auto-fail – High-risk or critical security updates for operating systems, applications, and firmware (routers, firewalls, etc.) must be installed within 14 days of release. Missing this is an automatic failure.
- Expanded scope for cloud services – All organisational cloud services that store or process data are in scope, with clearer shared-responsibility guidance.
- Remote and home-working devices – Any device that accesses organisational data is in scope, regardless of location.
- Firmware updates – Explicit requirement to keep network device firmware current.
- Password policy refinements – Minimum lengths adjusted in line with MFA usage; no forced periodic password changes.
For Cyber Essentials Plus specifically, 2026 rules are stricter:
- If the initial device sample fails, the retest includes both the original sample and a new random sample.
- A second failure can revoke the underlying verified self-assessment certificate.
- Self-assessment answers must be finalised before technical testing begins and cannot be amended afterwards.
These changes close previous loopholes and raise the practical bar for both Cyber Essentials and Cyber Essentials Plus certification.
Why Cyber Essentials and Cyber Essentials Plus Matter More Than Ever in 2026
- Procurement requirements – Many public-sector contracts and increasing numbers of private-sector tenders mandate Cyber Essentials or Cyber Essentials Plus.
- Supply-chain pressure – The Cyber Resilience Pledge and related initiatives encourage large organisations to require Cyber Essentials from suppliers.
- Insurance and trust – Certification demonstrates due diligence and can support cyber insurance applications.
- Threat landscape – Common attacks still succeed by exploiting the exact weaknesses these five controls address. Achieving Cyber Essentials or Cyber Essentials Plus remains one of the most cost-effective ways to reduce risk.
How to Achieve Cyber Essentials and Cyber Essentials Plus Certification in 2026
- Determine your scope carefully (all devices and cloud services that process organisational data).
- Implement the five controls, paying special attention to MFA and 14-day patching.
- Use the free readiness tools and download the current self-assessment questions from official sources.
- Choose a licensed Certification Body (or go self-led via IASME).
- Complete the verified self-assessment for Cyber Essentials.
- For Cyber Essentials Plus, arrange the independent technical assessment within the required timeframe.
- Maintain the controls throughout the 12-month certificate period.
Preparation is critical under the 2026 rules. Automatic-fail questions mean there is little room for incomplete implementation.
Final Thoughts on Cyber Essentials and Cyber Essentials Plus in 2026
Cyber Essentials and Cyber Essentials Plus continue to provide a clear, practical, and nationally recognised standard for UK organisations. The 2026 updates (Danzell / v3.3) have strengthened the scheme by making multi-factor authentication universal where available and enforcing timely patching more rigorously. Whether you need the baseline assurance of Cyber Essentials or the independently verified confidence of Cyber Essentials Plus, achieving certification remains one of the most effective steps an organisation can take to protect itself and meet client and contractual expectations.
Start by reviewing the current NCSC Requirements for IT Infrastructure (v3.3) and the latest Danzell question set. With the right preparation, Cyber Essentials and Cyber Essentials Plus certification in 2026 is both achievable and highly valuable.
✅ Get certified for Cyber Essentials
✅ Get certified for Cyber Essentials
✅ Cyber Essentials + Cyber Essentials Plus combined package
Get Help Preparing for the New Standard
As an IASME-accredited certification body, we can help you review your infrastructure against the new v3.3 requirements, identify gaps before you apply, and guide you through certification under the Danzell question set — with no jargon and no surprises during assessment.
📧 Get in touch: mailto:info@cybercompliance.org.uk