
Share This Article
Cyber Essentials is getting a major update in April 2026.
These changes will affect every UK business that wants to achieve or renew its Cyber Essentials Certification.
While the five core controls will remain the same, the National Cyber Security Centre (NCSC) and IASME will be introducing new rules in an attempt to strengthen security and remove any confusion.
As a top leading IT provider, we’re here to explain these updates in plain English, no technical jargon that might feel overwhelming.
We aim to help and prepare you ahead of your certification to ensure your business can achieve cyber essentials in 2026 with ease.
These changes apply to all assessment accounts created after 26 April 2026.
Multi‑Factor Authentication (MFA) is no longer optional for all cloud services.
It will now be a mandatory requirement for all cloud services, and failing to enable it will result in an automatic fail. The NCSC has introduced this because MFA is one of the most effective ways to stop cyber‑attacks.
“Multi‑factor authentication (MFA) will now be a mandatory requirement for all cloud services where it is available.”
If your business hasn’t rolled out MFA yet, now is the time.
We can help you implement it across your organisation with minimal disruption.
Two new “auto‑fail” questions have been added around security updates.
If your business doesn’t install high‑risk or critical updates within 14 days, you will automatically fail the assessment.
“Are all high‑risk or critical security updates… installed within 14 days of release?” (A6.4 & A6.5)
At Syn-Star we can run a compliance check during your online cyber security review and help you put the right processes in place to ensure your set-up is in-line ahead of your upcoming cyber essentials certification.
Monday 23rd of March at 14:00 pm
In this webinar Giles Cleverley will cover:
The rules around what must be included in your assessment have been tightened.
“Cloud services cannot be excluded from scope.”
If your business has multiple sites, departments, or cloud tools, we can help you define your scope correctly.
Cyber Essentials has always been a “point in time” assessment, but the definition is now clearer:
“The ‘point in time’ is the date the certificate is issued.”
This means your systems must be compliant on the day your certificate is issued, not just when you start the assessment.
We can help you stay compliant throughout the process so there are no last‑minute surprises.
If your business includes multiple legal entities, you can now request individual certificates for each one while still being part of a wider assessment.
“You will be able to request an individual Cyber Essentials certificate for every legal entity certified as part of a larger scope.”
This is useful for groups, franchises, or organisations with multiple trading names.
You must now clearly list all legal entities included in your assessment.
“Organisations will need to specify all legal entities included within the scope of the assessment.”
This improves transparency and ensures certificates accurately reflect who is covered.
If you’re unsure how to structure your assessment across multiple entities, we can guide you.
If you go for Cyber Essentials Plus, there are two important updates:
If you fail the first device sample test, you must fix the issues and undergo a retest.
The retest will include a new random sample to ensure updates were applied across your whole environment not just the tested devices.
This prevents businesses from “selectively updating only the tested devices.”
Once your Cyber Essentials begins, your Verified Self‑Assessment answers are locked in and can’t be adjusted.
These changes may feel overwhelming, but you don’t need to navigate them alone.
Whether you’re renewing or certifying for the first time, we’ll make the process smooth and stress‑free.
They apply to all assessment accounts created after 26 April 2026.
Not necessarily, but they do require better documentation, faster updates, and stronger authentication.
Yes. If MFA exists even as a paid add‑on you must enable it.
If it’s older than 14 days, it becomes an automatic fail.
Yes, but you must justify exclusions and explain how those areas are separated from in‑scope systems.
Absolutely. We can manage the entire process or support your internal team whatever works best for you.
Giles Cleverley founded Syn-Star in 2002 shortly after graduating from Portsmouth university with an honours degree in Business & Economics.
His extensive knowledge and experience in IT strategy and business technology solutions. He is passionate about driving innovation and delivering tailored IT support that helps UK small and medium size businesses thrive. Under his leadership, Syn-Star continues to provide cutting-edge managed IT services designed to meet the evolving needs of modern organisations.
Share this article
Sign up to our newsletter
Team Productivity:
You and your team are able to see where they are using their time and how productive they are actually being. Also they are able to clock in and out, so really good for flexi-working.
Team Monitoring:
If you would like to know what your team is doing and how productive they are being, we are able to monitor them and create screenshots of what they are working on. This can be run in normal or stealth mode.
Book a FREE fact finding session to discuss the different options.
We proactively seek opportunities to support good causes for our community.
From sponsoring local community football teams, to engaging with charity fundraiser days, we believe it’s important to continually strive to do good for the better of others.
We have members who volunteer with youth organisations, are engaged with the Round Table, run marathons and volunteer at events where we may be needed. Every charity receives a discounted IT and Telecoms service too.
Protecting your digital data is crucial for every business and this can start with the industry-leading security we offer. The Syn-Star specialists can help with identifying any vulnerabilities within your IT systems and act accordingly to ensure cyber-attacks and data breaches are mitigated.
Your business will never fall behind with its technology when you work with Syn-Star.
We understand IT and Telecoms for your business is an investment, but it’s important to use the best resources available to enable the growth of your business. Our IT Consultancy and Virtual IT Director Services are available to support you with how you use your business technology for years to come.
Syn-Star can conduct quick and easy phishing exercises to identify people within your team who need to improve on their knowledge around fraudulent emails and how they can be alerted to these threats.
At Syn-Star, our experts can proactively work to understand exactly what software you need to support with the business operations. Whether you need a listening ear on what software to choose, or would like to seek some specialist knowledge, we’re here to help where we can.
At Syn-Star, we keep Telecoms simple. There’s so much available to help UK companies with their communications. VoIP systems, fixed landline, cloud phone systems, SIP trunking and more. Contact us for further details.
Desk phones, cordless phones or conference phones, Syn-Star can provide you with whatever you need.
From conference calling facilities to the headsets which work best for your team, we’re able to provide all the equipment you need and complete any telecoms job from start to finish.
There is no need to be in the office to make and receive phone calls from your company’s number. Our market-leading Telecoms platform gives you the flexibility of desk phones, soft phones and mobile apps as standard.
Whether your team works remotely, or perhaps staff are on a business trip anywhere in the world, calls can still be made, and people are reachable via phone wherever they go.
With a range of products, our team can support you by installing exactly what you need for internet connectivity. We work with the very best products to provide speedy bandwidths which play a part in the increased productivity of your team.