Let's break the ice

* required fields
We aim to respond within 48 hours
21 September 2026 Cyber Security

Cyber Essentials Explained: What It Covers and How to Get Certified

Cyber Essentials had its biggest shake-up in years this April, and if your business hasn’t looked at the scheme since before then, the rules you think you know have changed.

The five technical controls it covers close the gaps that account for many breaches SMEs actually suffer, and closing them properly is what keeps a business protected.

What’s changed is how seriously the scheme now takes the basics. Multi-factor authentication is no longer optional on the assessment, missing it is an automatic fail. So is leaving a critical security update unpatched for more than two weeks. If you’re due to recertify, or you’ve never looked at Cyber Essentials properly, here’s what it actually covers, what’s different now, and how to get certified.

What Cyber Essentials Actually Is

Cyber Essentials is the UK government’s baseline standard for cyber security, designed by the National Cyber Security Centre (NCSC) and assessed through IASME-accredited certification bodies, bzb IT included.

As the NCSC put it, Cyber Essentials is the minimum standard of cyber security recommended by the Government for organisations of all sizes, aligned to five technical controls designed to prevent the most common internet based cyber security threats. It’s five sensible, achievable technical areas that most well-run businesses are already halfway to meeting, and working with the right partner can get you all the way.

Businesses are also under increasing pressure to demonstrate it, not just to reduce risk, but to win work:

  • Supplier due diligence questionnaires.
  • Cyber insurance applications.
  • Public sector and larger private-sector tenders, some of which won’t let you bid without it.

The Five Controls

Strip away the acronyms and Cyber Essentials comes down to five things:

  • Firewalls – controlling what’s allowed in and out at your network boundary
  • Secure configuration – locking down the default settings attackers rely on
  • Security update management – patching known vulnerabilities before someone else finds them first
  • User access control – people only get access to what they actually need, not admin rights by default
  • Malware protection – stopping malicious software running on a device in the first place

If you’re on Microsoft 365 Business Premium and it’s configured properly, you likely already have most of this in place.

What Changed in April 2026 (and Why It Matters Now)

The scheme was updated on 26 April 2026, following IASME’s usual annual review. Each year, IASME collaborates closely with the NCSC to review feedback from across the scheme, analyse findings from breach investigations, and evaluate insights gained from audits conducted by the IASME team.

The changes tighten up exactly the areas that used to be easiest to gloss over:

  • Multi-factor authentication is now a mandatory requirement for all cloud services where it is available.
  • High-risk and critical security updates, including router and firewall firmware, now have to be applied within 14 days.
  • Scope has to be explicitly documented, including which parts of the business are in and out, and under which legal entity.

Miss either of the first two requirements and, as IASME states, non-compliance with either question results in an automatic failure of the assessment, regardless of performance in other areas.

If you registered before 26 April 2026, you get a six-month transition period under the old rules, but that window closes around October 2026, so very soon. If you’re due to recertify shortly, this is worth checking now.

Cyber Essentials or Cyber Essentials Plus? The Difference Matters More Than People Think

Cyber Essentials is a self-assessment. You answer the questions, an assessor reviews your answers, and you get a pass or fail.

Cyber Essentials Plus adds a technical audit on top. Someone actually checks that what you said is true.

For SMEs bidding for larger contracts, especially in finance, defence, or the public sector, Plus is increasingly the one that gets asked for. “It carries more weight because it’s independently verified, not just declared,” says Luke Nix, Technical Account Manager at bzb IT.

If you’re not sure which one your business needs, that’s usually a question worth asking before you start the process.

Why It’s Worth Doing, Not Just a Checkbox

A lot of SMEs still think improving cyber security means buying more products and licences. Often, it doesn’t. “That’s one of the reasons frameworks like Cyber Essentials are useful. They focus on getting the fundamentals right,” says Luke.

So when getting certified feels difficult, stressful, or unclear, it’s worth asking why. More often than not, it’s less about the technology itself, and more about whether security and operational practices have evolved consistently as the business has grown.

That’s also, increasingly, the whole point. As Luke puts it: “The strongest SME IT environments are usually the ones where security isn’t treated as a yearly exercise. It’s simply built into how the organisation operates.”

Why bzb IT

bzb IT is an IASME-accredited certification body, and a number of our team hold Cyber Essentials Advisor, Cyber Essentials Assessor and Cyber Essentials Plus Assessor statuses.

That means when you work with us, the team getting you certification-ready and the team carrying out the assessment are the same people. No handoff, no second supplier, no waiting on someone else’s availability.

How We Help

We help SMEs through the whole journey: an initial gap assessment against the five controls, fixing whatever needs fixing, and the certification assessment itself, whether that’s Cyber Essentials or Cyber Essentials Plus.

As Luke sums it up: “Cyber Essentials provides the baseline. A good MSP helps businesses maintain and build on it over time.”

If you’re due to recertify under the new rules, or you’ve never looked at Cyber Essentials properly, get in touch and we’ll talk you through where to start.

Sources

  • NCSC, Cyber Essentials overview
  • IASME, Important Update: Changes to Cyber Essentials for April 2026

Join our free Cyber Essentials webinar - Wednesday 28th October

Join us for our upcoming webinar, on Cyber Essentials. Luke Nix, Technical Account Manager here at bzb IT will be going through everything you need to know to get started or continue your cyber essentials journey. Online from midday until 1pm, see you there.

contents