23/04/2026
If your business holds Cyber Essentials certification — or is planning to get it — something important changes on Monday 27 April.
The NCSC and IASME have updated the scheme to v3.3. From that date, failing to enable multi-factor authentication on any cloud service that supports it is an automatic certification failure. No exceptions.
That means Microsoft 365, Google Workspace, your accounting software, your project tool, your CRM — if MFA is available and you haven't turned it on, you fail. Even if everything else is compliant.
There are also tighter rules on how quickly security updates must be applied, and the definition of which cloud services count as "in scope" has been expanded significantly.
For UK businesses that need Cyber Essentials to bid for government contracts or work with larger clients, this is worth checking before Monday.
We've published a full breakdown of what changed and why. Link in the first comment.