Cyber Essentials 2026: What Changed, and Why So Many Businesses Are Failing Renewal
Cyber Essentials got noticeably stricter in 2026. If you’re renewing — or certifying for the first time — under the new question set (v3.3, nicknamed “Danzell”, in force from 27 April 2026), a few changes are catching businesses out, including ones that passed comfortably last year. Here’s the plain-English rundown.
1. Two-factor authentication is now a hard pass-or-fail
This is the big one. Every account that accesses your business data and can have multi-factor authentication (MFA) turned on now must have it — and that means everyone, not just admins. A single account without MFA now fails the entire user-access section automatically. There’s no partial credit and no warning.
The catch most businesses miss: it’s rarely that they have no MFA — it’s that they missed it somewhere. A shared mailbox. The company social media logins. A finance tool someone set up years ago. (We cover this in detail in the MFA guide.)
2. Patching is now on a strict 14-day clock — and it’s auto-fail too
High-risk and critical security updates must be applied within 14 days of the vendor releasing them, across operating systems, applications, browsers and firmware. Miss it, and that’s an automatic fail. The trap: the clock starts when the vendor publishes the fix, so the common “we update everything once a month” routine can quietly miss the window.
3. Out-of-date software is a straight fail
If a device in scope is running an operating system that’s no longer supported — the obvious example being Windows 10 after its October 2025 end of support, without paid extended updates — that’s a categorical fail. The only fix is to update, replace, or formally remove the device.
4. You can’t quietly leave your cloud tools out
Microsoft 365, Google Workspace, your accounting software, your CRM, file storage — even business social media accounts — all count, and you can no longer exclude them to make the assessment easier. How you’ve configured them (especially their MFA settings) is your responsibility.
5. Your devices — including personal phones — are in scope
A scope that leaves out laptops, desktops, tablets and phones isn’t acceptable. And a personal phone counts if it’s used for work email or files (it’s only exempt if it’s purely for calls, texts, or receiving login codes).
The pattern behind all of this
The rules are stricter and the questionnaire still assumes you have an IT team. That combination is why renewal failures are rising — and why “what passed last year” is no longer a safe assumption. The single most avoidable mistake is working from last year’s understanding instead of the current rules.
What to do about it
- Work from the current question set, not last year’s.
- List every online tool your team uses, and check MFA is on for each — including the accounts nobody thinks about.
- Check no device is on unsupported software.
- Switch on automatic updates everywhere, so the 14-day rule looks after itself.