24.07.26 Megan Kaye

Important Changes to Cyber Essentials

Cyber Essentials renewals in 2026 may require more preparation than in previous years. Organisations will need greater visibility of their devices, software, cloud applications and personal devices, alongside stronger processes for security updates, vulnerability management and Multi-Factor Authentication. Before renewing, businesses may need to review their current controls and address any gaps that could prevent certification.

Over the past year, Cyber Essentials has introduced some of the most significant changes to the standard since it was first launched, and the requirements have evolved for achieving this certification.

As you have attained Cyber Essentials in previous years, it is important to understand that renewing your certification is no longer simply a case of completing the annual questionnaire.

Many organisations will now need to review and improve parts of their security posture before they are able to achieve certification again.

These changes are not intended to make certification more difficult, they are designed to ensure businesses have appropriate protection against the increasingly sophisticated cyber attacks that organisations face every day.

What Is Changing in Cyber Essentials in 2026?

The new requirements place a much greater emphasis on understanding and actively managing your technology estate, including:

  • Continuous vulnerability management
  • Faster remediation of critical security vulnerabilities
  • Better visibility of cloud services and business applications
  • Stronger controls around personal devices (BYOD)
  • Improved management of authentication and Multi-Factor Authentication (MFA)
  • Greater evidence that security controls are actively managed rather than simply configured once

Vulnerability Management and the 14-Day Update Requirement

One of the biggest changes is the expectation that organisations actively identify and remediate vulnerabilities across their IT estate.

This means organisations must now be able to identify software and devices with known critical vulnerabilities and ensure they are remediated within the required timescales. Waiting until annual reviews or relying solely on Windows Updates is no longer sufficient.

Examples include:

  • Critical Microsoft security updates
  • Firewall firmware vulnerabilities
  • Network switch vulnerabilities
  • Wireless access point firmware
  • Server operating systems
  • Third-party software
  • Browsers and productivity applications
  • Security appliances
  • Network infrastructure

Many organisations will now require a formal vulnerability management process, together with regular reporting to demonstrate compliance.

AAG IT Services engineer working on a physical server

Cloud Applications and Online Services Are in Scope

Another significant change is the requirement to consider the cloud applications and online services your organisation relies upon to process business information.

This goes far beyond Microsoft 365. Examples include:

  • Customer portals
  • Supplier ordering portals
  • Finance systems such as Xero, Sage or Business Central
  • CRM platforms such as HubSpot or Salesforce
  • HR systems
  • Payroll services
  • Document management systems
  • Project management platforms
  • File sharing services
  • Industry-specific line-of-business applications
  • Legal or healthcare practice management systems
  • Manufacturing or ERP platforms
  • Remote support platforms

To ensure your assessment is accurate, we will need to understand which cloud applications your organisation uses, who uses them, whether they support Multi-Factor Authentication, and whether they store or process business data.

Multi-Factor Authentication Is Mandatory Where Available

Under the April 2026 marking criteria, failing to use MFA for a cloud service where it is available results in an automatic assessment failure.

What Cyber Essentials Means for Personal Devices and BYOD

The new standards also place greater emphasis on personally owned devices used to access company systems or data.

Where staff use their own laptops, tablets or mobile devices to access company email, files or cloud services, appropriate security controls must now be in place to protect organisational data.

This may include device management, application protection policies, access controls and other security measures depending on how those devices are used.

In short: Your users will be required to have the same security controls on their personal devices if they are used to access your business data.

What the 2026 Cyber Essentials Requirements Mean for Your Organisation

For many businesses, achieving Cyber Essentials will now involve more preparation than in previous years.

Before your renewal, we may need to:

  • Review your current security controls.
  • Confirm all cloud applications used across the business.
  • Review your vulnerability management process.
  • Verify that critical vulnerabilities are being addressed within the required timescales.
  • Confirm Multi-Factor Authentication is enabled wherever available.
  • Review any personal devices accessing company systems.
  • Identify any gaps that need addressing before certification.

In some cases, organisations may already meet these requirements. Others may require changes before they are able to pass the assessment.

How AAG IT Services Will Support Your Cyber Essentials Renewal

Our objective is not simply to complete a Cyber Essentials renewal but to help ensure your organisation genuinely meets the latest security standard.

Where additional work is required, we will explain exactly what has changed, why it is required under the updated Cyber Essentials standard, and work with you to implement the necessary improvements in the most practical and cost-effective way.

Over the coming weeks, we will be contacting customers whose Cyber Essentials certification is due for renewal to begin this review process.

If your renewal is approaching and you would like to discuss the new requirements, please get in touch with your Account Manager, who will be happy to arrange a review.

Looking for support on your Cyber Essentials Renewal?

If your renewal is approaching and you would like to discuss the new requirements, AAG IT Services are happy to support. Contact our team today.
Contact us today

Related stories

Browse more articles from our experts and discover how to make better use of IT in your business.

Business
News

Welcoming Debar to AAG

31 Jul, 2026

We're delighted to welcome Debar as a new partner of AAG, delivering IT support in Bradford for their growing manufacturing business. Read more

Business

IT Support Pricing Guide

14 Jul, 2026

This page explains our IT Support Prices, your levels of cover and what affects costs. Get a quote instantly with our IT Support Pricing Calculator. Read more

Business
News

Welcoming H Harrold & Sons to the AAG Family

26 Jun, 2026

AAG IT Services welcomes Sheffield security specialist H Harrold & Sons as a new managed IT support client, strengthening IT reliability, Microsoft 365 and cyber security. Read more