Skip to content

Cyber Essentials has got stricter. Here’s what’s catching people out

Cyber Essentials has got stricter. Here's what's catching people out

Cyber Essentials used to be something businesses got round to. It is now turning up as a condition of tendering, a clause in contracts and a question on insurance renewals. If you want to work with the public sector or with a large customer, you will probably need it.

The rules tightened this year. The updated version, which the scheme’s operator calls Danzell, came into force on 28 April 2026, and two things now fail an application outright rather than earning a note to fix afterwards.

Here is what we see catching businesses out.

1. Two step login missing somewhere

If a cloud service offers two step login and you are not using it, the application fails. Not a warning, not a conditional pass.

The usual culprit is not the main email system, which is normally covered. It is the accounts package, the file sharing tool somebody set up three years ago, or the administrator account that was left alone because turning it on felt fiddly.

2. Updates left longer than a fortnight

Security updates rated critical or high have to be applied within 14 days of release. That applies to laptops, phones, servers and the firmware in routers and firewalls.

Most businesses are fine on the laptops and lose points on everything else. Phones that staff never restart and network equipment nobody has logged into since installation are the two we find most often.

3. Assuming cloud services are out of scope

They are not. The updated rules define cloud services clearly and they have to be included. If your business uses it and business data goes into it, it counts.

This catches people who assume that because a system is somebody else’s software running on somebody else’s servers, it is somebody else’s responsibility. The account settings are still yours.

4. Leaving things out without saying why

You can exclude part of the business from an assessment, but it now has to be justified in writing and the excluded part has to be genuinely separated from the rest. A shared wireless network usually means it is not.

The honest version of this is that excluding things rarely saves the trouble it appears to save.

5. Forgetting how people work from home

Home working is in scope. That means the laptop, the way it connects and, in some circumstances, the router it connects through. Staff using their own equipment is where this gets complicated, and it is better dealt with before the application than during it.

One deadline worth knowing

If your business started an application before late April, you can still finish it under the previous rules, but only until 27 October 2026. After that everything moves to the updated requirements.

If there is a part completed application sitting in someone’s inbox, this is the month to deal with it.

Giving yourself the best chance

Most failures we see are not really security failures. They are record keeping failures. The protections exist, nobody has checked them recently and nobody can prove they are switched on.

A run through before you apply usually finds everything in an afternoon. We do this for clients across legal, charity and social care sectors where certification is increasingly expected, and it is part of how we approach business IT solutions generally.

If you are applying this year, or you have failed once already and would rather not repeat the experience, talk to us or call 0191 296 0111.

Back To Top