Cyber Essentials Plus 2026 Changes: Are You Ready?
Skip to content
Funnel overlay image

Are you ready for the latest updates to Cyber Essentials Plus?

Anna Webb profile headshot

Anna Webb

Head of Global Security Operations

Published: 02 March 2026

Cyber Essentials Plus v3.3 takes effect in April 2026. Here’s what changes, how stricter multi-factor authentication (MFA) and cloud rules affect certification, and what you should review now to avoid disruption.

The Cyber Essentials and Cyber Essentials Plus requirements are being updated on 27 April 2026.

With identity now widely recognised as the primary control point in modern security, the v3.3 update tightens expectations around MFA, cloud services and access management.

If you’re planning to certify or renew after that date, your assessment will need to meet the updated standard, so it’s worth reviewing your current setup now.

The key date to plan around

The change takes effect on 27 April 2026, and the important detail is how assessments are counted. Any assessment accounts created on or after that date must meet the new v3.3 standard.

If your organisation is due to renew around this date, it’s worth checking your renewal window and deciding whether an early renewal is strategically sensible. In some cases, renewing earlier can allow for a further year under current rules. Leaving it late could mean extra remediation work before a renewal can take place.

The main changes in Cyber Essentials v3.3.

  • Mandatory MFA: MFA must be enabled wherever it is technically available. If it is supported and not enforced, certification is at risk.
  • No cloud exceptions: All cloud services storing or processing organisational data are now formally in scope, meaning SaaS platforms can no longer be excluded from assessment.
  • Stronger identity scrutiny: Identity protection and access control are treated as baseline requirements, with greater scrutiny on how consistently controls are applied.
  • Avoid shared accounts: Shared or generic accounts are strongly discouraged, with an expectation that each user has a unique identity and appropriate access rights.
  • Proof required: At Cyber Essentials Plus level, auditors will validate that identity and access controls are enforced in practice, not simply declared in policy.

What this means for organisations

The latest update is aimed at getting organisations to prove their controls are being enforced. This means removing long-standing expectations and tightening controls that would have previously been considered ‘good enough.’

If you rely heavily on cloud services, v3.3 brings every SaaS platform into scope. That means greater scrutiny of your identity and access controls.

If MFA is optional, inconsistently deployed or bypassed for certain apps and accounts, it is likely to result in certification failure.

And if shared accounts are still in use for administration, testing or third-party access, certification may be blocked until they are replaced.

This has commercial as well as operational repercussions. Cyber Essentials and Cyber Essentials Plus are frequently prerequisites for contracts, supplier frameworks, and many cyber insurance policies.

A failed or delayed renewal therefore has the potential to delay revenue, restrict market access, or even invalidate a breach claim.

Even when your overall security maturity is strong.

Action to take now

Priority should be given to the controls v3.3 explicitly tightens:

Ebony and green ticklist icon on transparent background

Audit every cloud service in use

Confirm which services store/process organisational data and document what falls in scope.

Ebony fingerprint icon on transparent background

Check MFA coverage properly

Confirm whether MFA is enforced across all supported services.

Ebony and green people connected icon on transparent background

Tidy up identity and account ownership

Replace shared accounts with unique users wherever possible.

Ebony and green bullseye arrow icon on transparent background

Review readiness for technical CE+ validation

If you are aiming for CE+, ensure you can demonstrate enforcement in practise.

Ebony and green 'brainbulb,' idea icon on transparent background

Decide whether early renewal is strategically sensible

If your renewal sits close to the April 2026 changeover, then it’s worth checking your timeline as assessments created after 27 April 2026 will need to meet v3.3 standards.

Support with certification and renewal

Kocho supports organisations preparing for Cyber Essentials and Cyber Essentials Plus under the new v3.3 requirements.

We can assess your current position against v3.3, help you close gaps that commonly lead to delays (MFA enforcement, cloud services in scope and shared or generic accounts) and guide you through what CE+ auditors will expect to see in practise.

For more detail on how we can help, please contact our team today.

A Cyber Essentials Plus success story

Discover how Kocho helped leading charity, WithYou, achieve Cyber Essentials Plus, enable simplified renewal processes, and strengthen long-term security posture.

tag icon

Great emails start here

Sign up for free resources and exclusive invites

Subscribe to the Kocho mailing list if you want:

  • Demos of the latest Microsoft tech
  • Invites to exclusive events and webinars
  • Resources that make your job easier
Butterfly overlay image
Anna Webb profile headshot

Author

Anna Webb

Head of Global Security Operations

Anna has over 20 years’ experience in operations management, major incident management, and cyber security. CISSP qualified, Anna is officially a Security Changemaker (Microsoft Security Excellence Awards).