EXPLAINER

What Are the Cyber Essentials Requirements?

13 minutes

READ

Cyber Essentials requires an organisation to define its assessment scope and meet five technical controls across the devices, software, networks and cloud services within it. The controls cover firewalls, secure configuration, security update management, user access control and malware protection.

The scheme is the UK Government’s recommended minimum standard of cyber security for organisations of all sizes. Its purpose is focused: reducing exposure to the common internet-based attacks that succeed when systems are left with avoidable weaknesses. Cyber Essentials certification does not assess every aspect of governance, resilience or targeted-attack defence, but it creates a clear, independently verified baseline.

The current technical requirements are set out in Requirements for IT Infrastructure version 3.3, effective from 27 April 2026. Organisations preparing a new assessment should use that version and the current Danzell question set rather than older Willow material.

Scope comes before the five controls

Cyber Essentials should normally cover the whole IT infrastructure used to carry out the organisation’s business. A well-defined and separately managed subset can be certified when necessary, but the business unit, network boundary and physical location must be clear, the scope must be agreed with the certification body, and exclusions need a reason.

The requirements apply to in-scope devices and software that accept incoming network connections from internet-connected devices, establish outbound connections over the internet, or control the flow of data between those devices and the internet. A scope that excludes end-user devices is not acceptable.

Cloud services need particular attention. Under version 3.3, a cloud service is an on-demand, scalable service hosted on shared infrastructure, accessed through an account over the internet, and used to store or process organisational data. If organisational data or services are hosted in a cloud service, that service must be in scope. Microsoft 365, Google Workspace, hosted applications, identity platforms and cloud infrastructure cannot simply be omitted because the provider operates the underlying technology.

The organisation remains responsible for the parts of each control that it can configure and for confirming provider responsibilities. Trust-centre statements, contracts and shared-responsibility documentation may provide evidence for controls operated by the provider. Accounts owned by the organisation remain in scope when suppliers or managed service providers use them, and organisational devices loaned to third parties remain in scope.

Asset management is not one of the five named controls, yet weak inventory is a common cause of failure. An organisation cannot confirm supported software, patching, firewall coverage or account ownership if it does not know which assets and services are included.

The five Cyber Essentials controls

1. Firewalls

Every in-scope device must be protected by a correctly configured firewall or network device with firewall functionality. Boundary firewalls protect networks; software firewalls protect individual devices, including devices that connect through networks the organisation does not control. In cloud services, equivalent protection may be implemented through data-flow policies and provider controls.

Default administrative passwords must be changed to strong, unique passwords or remote administration must be disabled. Management interfaces must not be accessible from the internet unless there is a documented business need and the interface is protected by multi-factor authentication or a tightly restricted IP allow list combined with properly managed password authentication.

Unauthenticated inbound connections should be blocked by default. Every permitted inbound rule needs approval, documentation and a business reason, and unnecessary rules must be removed or disabled. The control is therefore about governance of exposure as well as the presence of a firewall product.

2. Secure configuration

Devices and services must be configured to reduce vulnerabilities and provide only the functions needed for their role. Organisations should remove or disable unnecessary user accounts, software, utilities and network services; change default or guessable passwords; disable unauthorised auto-run features; authenticate users before access; and apply appropriate device-locking controls.

For a device-unlock password or PIN that is used only to unlock a device, the minimum length is six characters. The authentication method must be protected against brute-force guessing through throttling or locking after no more than ten unsuccessful attempts where the vendor allows this. If the same credential is used for wider authentication, the full user-access password requirements apply.

Secure configuration needs to survive deployment and change. Standard builds, mobile-device management, cloud configuration policies and periodic checks can help an organisation demonstrate that settings remain consistent rather than being corrected only for the assessment sample.

3. Security update management

All software in scope must be licensed and supported. Unsupported software must be removed, or placed in a defined subset that prevents all traffic to or from the internet. Automatic updates should be enabled where possible.

Security updates and vulnerability fixes must be installed within 14 days of release when the vendor describes the issue as critical or high risk, when the vulnerability has a CVSS v3 base score of 7 or above, or when the vendor supplies no severity information for the vulnerabilities fixed by the update. If one bundled update fixes several issues and any one is critical or high risk, the full update must meet the 14-day requirement.

The 2026 marking rules make the high-risk and critical update questions automatic-failure items. This applies to operating systems, router and firewall firmware, applications and associated files and extensions. The requirement covers the complete scope, not only devices selected for a Cyber Essentials Plus test.

4. User access control

The organisation must control accounts and privileges used to access organisational data and services, including third-party support accounts. It needs a process to create and approve accounts, unique authentication credentials, timely removal or disabling of accounts that are no longer required, and removal of privileges when a person changes role.

Access should be limited to what a user needs. Administrative activity must use separate accounts that are not used for email, web browsing or ordinary work. This reduces the chance that malicious content opened during everyday activity gains administrative privileges.

Multi-factor authentication must be used where it is available, and authentication to cloud services must always use MFA. From April 2026, an organisation that does not enable MFA for a cloud service where it is available will automatically fail, whether the provider includes the feature free of charge, bundles it into the subscription or sells it separately.

Passwordless methods are supported. Version 3.3 explicitly recognises passkeys and FIDO2 authenticators, alongside biometrics, security keys, tokens and approved push methods. Where passwords are used, they need protection against brute-force attacks and a technical measure for password quality. This can be MFA, a minimum length of 12 characters, or a minimum of eight characters combined with automatic blocking of common passwords. The guidance advises against forced regular expiry and complexity rules, while promoting long, unique passwords and secure password storage.

5. Malware protection

A malware-protection mechanism must be active on every in-scope device. For Windows and macOS devices, anti-malware software can be used and must remain active, current and configured to stop malware, malicious code and connections to malicious websites. Application allow listing is an alternative across in-scope devices when only approved, validly signed applications can execute and users cannot install unapproved software.

The choice of mechanism should reflect the device and operating model. The assessment needs evidence that protection is active and managed across the scope, not merely that the organisation owns an endpoint-security licence.

What changed in April 2026

Cloud services can no longer be excluded

Version 3.3 added a clear cloud-service definition and a definitive statement that services hosting organisational data or services must be in scope. Organisations with partial scopes also need to justify exclusions and explain how excluded networks are segregated from in-scope systems.

MFA and critical patching can trigger an automatic failure

The assessment marking now treats missing MFA on cloud services where it is available, and failure to install high-risk or critical updates within 14 days, as automatic failures. Strong scores elsewhere do not compensate for these gaps.

The certificate is clearer about scope and timing

The scheme identifies the point in time as the date the certificate is issued, so systems need to be supported and compliant on that date. Legal entities within scope are identified more clearly, and the senior declaration acknowledges responsibility for maintaining the controls throughout the certification period.

Backups are strongly recommended but remain outside the five controls

Version 3.3 gives backups more prominence because they support recovery from loss, theft and ransomware. Backup is not a technical requirement for Cyber Essentials certification, so organisations should resist claiming that a Cyber Essentials certificate proves recovery arrangements. That capability needs separate design and testing.

Cyber Essentials and Cyber Essentials Plus

Both levels use the same five technical controls. Cyber Essentials is an independently verified self-assessment: the organisation submits answers, a board member or equivalent confirms their accuracy, and a qualified external assessor reviews them. The certificate is valid for 12 months.

Cyber Essentials Plus adds independent technical testing of a representative sample from the certified scope. It provides greater assurance that the controls described in the self-assessment are implemented. The Plus audit must be completed within three months of the underlying Cyber Essentials certification, or the two can be coordinated together.

The 2026 Plus process reinforces scope-wide remediation. If sampled devices fail update testing, the organisation must correct the problem and the assessor will test the original sample and a new random sample. Updating only the devices selected for the audit is not acceptable. The verified self-assessment also cannot be rewritten after Plus testing to match what the assessor found.

How to prepare for certification

1. Download the current documents

Use Requirements for IT Infrastructure v3.3 and the Danzell question set for assessments started from 27 April 2026. Reading only a third-party checklist risks missing the scheme’s precise definitions and scope rules.

2. Agree the scope before answering technical questions

Map the legal entities, business units, locations, networks, end-user devices, servers, cloud services and externally managed services. Identify any proposed exclusions, the reason for them and the technical segregation that supports the boundary. Discuss uncertain boundaries with the certification body early.

3. Build an asset and software view

Record in-scope devices, operating systems, applications, firmware, cloud services and responsible owners. Confirm support dates and identify anything that cannot meet the update requirements. This work drives several controls at once.

4. Check the automatic-failure areas first

Verify MFA across every in-scope cloud service and confirm that critical and high-risk updates can be deployed across the whole scope within 14 days. Fixing these areas early prevents an otherwise strong submission failing immediately.

5. Review administration and remote access

Separate privileged accounts from daily accounts, remove dormant access, review third-party support identities and restrict internet-facing management interfaces. Document the business reasons and approvals for necessary inbound firewall rules.

6. Test the answer against the environment

Sample devices, user accounts, cloud settings, update reports and firewall configurations before submitting. An answer based on intended policy can be inaccurate when older devices or business-unit exceptions are included in scope.

7. Keep the evidence and maintain the controls

Retain the records used to support the assessment and set ongoing reviews for assets, support dates, patches, firewall rules, accounts and MFA. The certificate is issued at a point in time, but the signed declaration recognises responsibility for maintaining compliance throughout the year.

Common reasons organisations struggle

Incomplete scope is a frequent starting point. Teams document laptops and servers but overlook SaaS platforms, mobile devices, remote workers, firmware, browser extensions, supplier accounts or devices held by a different business unit. Those gaps then appear again in patching, MFA and malware-protection answers.

Unsupported software and slow patching create another cluster of problems. A system may be operationally important and still fall outside vendor support. If it remains internet-connected within the scope, business importance does not override the requirement. The organisation needs an upgrade, replacement or a properly defined subset with no traffic to or from the internet.

MFA coverage can also look stronger than it is. Administrators may be protected while normal users, guest access, legacy protocols or secondary SaaS services are not. The current rule applies to cloud authentication wherever MFA is available, so coverage needs to be checked service by service and account type by account type.

Finally, self-assessment does not mean approximate assessment. The senior signatory is confirming that the responses are accurate. If the organisation cannot support an answer with settings, reports, inventories or records, it should investigate before submitting.

Frequently asked questions

Is Cyber Essentials mandatory?

Cyber Essentials is not mandatory for every UK organisation, although particular government contracts, customers, supply chains, grants or policies may require it. The NCSC recommends it as the minimum standard of cyber security for organisations of all sizes.

How long is a Cyber Essentials certificate valid?

A Cyber Essentials or Cyber Essentials Plus certificate is valid for 12 months from the date of issue. Renewal requires a new assessment against the requirements current at that time.

Can cloud services be excluded from Cyber Essentials?

No, not when they host organisational data or services. Version 3.3 states that these cloud services must be in scope. The organisation and provider may carry different responsibilities under the shared-responsibility model, but the service itself cannot be omitted.

Does Cyber Essentials require MFA?

MFA must be used where it is available, and authentication to cloud services must always use MFA. Under the April 2026 marking rules, failing to enable available MFA for a cloud service causes an automatic assessment failure.

Does Cyber Essentials require every update within 14 days?

The mandatory 14-day rule covers security updates and vulnerability fixes for issues the vendor rates critical or high risk, vulnerabilities with a CVSS v3 base score of 7 or above, and updates where the vendor gives no severity information. The NCSC strongly recommends applying all released updates within 14 days, but that broader position is guidance rather than the certification requirement.

Are backups part of Cyber Essentials?

Backups are strongly recommended in version 3.3 but are not one of the Cyber Essentials technical requirements. Organisations still need appropriate backup, recovery and testing arrangements as part of wider cyber resilience.

Does Cyber Essentials prove GDPR compliance?

No. The controls can support protection of personal data, but certification does not demonstrate compliance with the UK GDPR or Data Protection Act 2018. Data protection obligations extend beyond the five technical controls.

How Logiq can help

Logiq is an NCSC Assured Cyber Advisor Service Provider. The team helps organisations define scope, understand the current questions, identify gaps and implement the five Cyber Essentials controls without losing sight of the wider operating environment. This is particularly useful where cloud services, managed providers, remote working or public-sector supply-chain requirements make the assessment more complex than the label “basic cyber security” suggests.

Support can be used to prepare for Cyber Essentials or Cyber Essentials Plus and to build a more durable improvement plan after certification. Certification itself is assessed through an IASME-licensed certification body.