If Cyber Essentials is on your radar — whether you’re certifying for the first time or renewing — the rules have changed, and not by a little. The April 2026 update to the scheme (overseen by the NCSC and IASME) brings the biggest tightening of the technical requirements in years, and the headline change is simple but far-reaching: multi-factor authentication is now mandatory on every cloud service where it’s available, and missing it is an automatic failure of the whole assessment.
For most UK businesses that’s a bigger deal than it first sounds, because “cloud services” now means a lot more than it used to.
What actually changed
Three changes matter most:
MFA is mandatory — with auto-fail. If a cloud service offers multi-factor authentication — free, included, or as a paid add-on — you must have it switched on. Leave it off on even one in-scope service and the entire certification fails. There’s no partial credit.
The definition of “cloud” got much wider. Any service accessed with a business email or account is now in scope — including free-tier SaaS accounts and the smaller tools teams sign up for without thinking of them as “IT”. Microsoft 365 and Google Workspace are obvious; so are the dozens of marketing, finance, design and project tools your staff log into every day.
Patching is now on the clock. High-risk and critical security updates for operating systems, applications and firmware must be applied within 14 days of release — and missing that window is also an auto-fail.
Existing assessment accounts created before the cut-over get a six-month window to certify against the old requirements, but anyone starting fresh is straight onto the new rules. In practice, the direction is one-way: this is where the baseline now sits.
Why this matters for your business
It matters for two reasons. First, risk. The government’s latest Cyber Security Breaches Survey found that around 43% of UK businesses suffered a cyber breach or attack in the past year — and the single most effective control against the most common attack (a stolen or reused password) is exactly the one the scheme now mandates: MFA. The update isn’t bureaucracy for its own sake; it’s closing the door attackers walk through most often.
Second, opportunity and obligation. Cyber Essentials is increasingly required to win contracts, especially in the public sector and larger supply chains. A lapsed or failed certification can quietly cost you work. Getting ahead of the new rules keeps you both protected and eligible.
The catch is the wider cloud scope. Most businesses genuinely don’t know every SaaS account their team uses, and MFA is often left off on the “minor” ones — which is precisely where a single weak login can undo everything else. An honest audit almost always turns up a few surprises.
What to do now
You don’t need to panic, but you do need a plan:
- Inventory your cloud and SaaS accounts — everything staff log into with a work email, not just the big platforms. You can’t protect what you haven’t listed.
- Turn on MFA everywhere it’s offered, prioritising email, Microsoft 365, finance and admin accounts — and roll it out in a way that’s secure without being painful for staff.
- Get patching under control so critical updates land inside the 14-day window automatically, not whenever someone gets round to it.
- Plan your certification against the new requirements rather than discovering a gap mid-assessment.
How Lumen MSP can help
This is exactly the kind of work we do for clients every week. We audit your cloud estate, switch on and configure MFA across Microsoft 365 and the rest of your services so it’s strong but not disruptive, get patching automated to meet the 14-day rule, and guide you through Cyber Essentials and Cyber Essentials Plus against the new 2026 standard — handling the technical detail so the badge reflects real protection.
If you’re due to renew, or want to certify for the first time under the new rules, the time to start is now. Talk to us about Cyber Essentials and MFA or call 0333 335 0170 for a straight, no-pressure assessment of where you stand.
Further reading: the official scheme and updated requirements at ncsc.gov.uk and iasme.co.uk.
