Sign up for our Newsletter
Keep up to date with the latest IT news, tips and guides from Dragon IS and sign up here:
Trusted and Proactive IT Support and Managed IT Services
Cyber Essentials has long provided a practical, accessible way for organisations to protect themselves against the most common cyber threats, while being a clear, public signal that a business takes cyber security seriously.
As cyber threats have grown more sophisticated and businesses have shifted toward cloud‑based and hybrid working, the standard has quietly been going through a period of modernisation to keep it aligned with current best practice.
From 27 April 2026, these strengthened Cyber Essentials requirements became the mandatory baseline for any organisation wishing to achieve or renew certification.
What is Cyber Essentials?
Cyber Essentials is a government‑backed cyber security standard designed to help organisations of all sizes protect themselves against the most common threats. It focuses on five key areas:
Cyber Essentials Plus takes this even further, including everything covered in the basic Cyber Essentials certification, but with one major difference: It is independently tested and verified by a qualified assessor.
For SMEs, Cyber Essentials has long been a trusted way to demonstrate good cyber hygiene, reassure customers and partners, meet supply‑chain expectations and reduce the risk of common cyberattacks. Increasingly, it also supports growth by helping businesses qualify for new opportunities. For example, Cyber Essentials is also becoming a common prerequisite in public sector procurement, with many government departments and agencies requiring certification for suppliers handling sensitive or personal data.
It is designed to be practical and achievable, even by small businesses with limited internal IT resource.
While the 2026 update hasn’t changed the purpose of Cyber Essentials, it has significantly raised the bar.
Why the standard needed an update
When Cyber Essentials launched in 2014, the threat landscape was far simpler. Today, SMEs face a very different set of challenges, including targeted phishing campaigns and ransomware. There are also some key vulnerabilities, such as around remote working, misconfigured cloud services, supply‑chain risk, and the use of mobile devices.
The National Cyber Security Centre (NCSC) has updated the standard to reflect these realities. The goal being to ensure Cyber Essentials remains relevant, practical, and effective.
Government data shows just how widespread cyber incidents have become. According to the UK’s Cyber Security Breaches Survey 2025, 43% of businesses experienced a cyber breach or attack in the past 12 months. The risk increases sharply with size, with 67% of medium‑sized businesses and 74% of large organisations reporting incidents over the same period.
What changes have been made to Cyber Essentials in 2026?
This is one of the most significant updates. Many SMEs rely on Microsoft 365, Google Workspace, AWS, and other cloud platforms, but historically, cloud responsibilities have often been misunderstood.
Under the new rules, organisations must demonstrate:
If your business uses cloud services – as most SMEs now do – this is a major area to review.
Compromised credentials remain one of the biggest causes of cyber breaches. The updated standard now requires:
Identity is now treated as a core security control, not an optional extra.
With the rise in hybrid working, the new standard places greater emphasis on:
Unmanaged laptops and mobiles, especially those used at home, are now a much bigger focus for assessors.
The new rules clarify what “good” looks like for network protection, including:
For SMEs with remote teams, this is particularly important.
The 2026 update also strengthens the assessment itself. Businesses can expect:
SMEs will need to be more organised and proactive when preparing for certification or renewal.
What does the Cyber Essentials 2026 update mean for SMEs?
The updated Cyber Essentials standard remains achievable, but it does require more preparation than before.
Here’s what SMEs should focus on now that the new rules are live:
Why these changes matter
Cyber Essentials has always been about reducing the risk of the most common cyber risks. The 2026 update strengthens that mission and ensures the standard remains relevant in a world where cyber threats evolve quickly.
For SMEs, this is an opportunity to modernise systems, improve resilience, and demonstrate a strong commitment to security to customers, partners, and regulators.
How Dragon can help
At Dragon, we work closely with SMEs, including those in the financial, legal and professional services, to help them meet the new Cyber Essentials requirements with confidence. But our support goes far beyond certification.
We help organisations build efficient, robust IT infrastructure, strengthen their cyber security posture, enable secure and productive remote working, and adopt AI tools safely and effectively. Whether you’re modernising your systems, tightening your defences, or exploring new technologies, we provide practical, tailored guidance that fits the realities of SME operations.
Whether you’re navigating the new Cyber Essentials rules for the first time or renewing under the updated framework, Dragon can help you stay secure, compliant, and ahead of the curve, while ensuring your technology supports your business, not the other way around.
Talk to us about Cyber Security-as-a-Service, an easy way to stay compliant and protected.
Get in touch to find out more – info@dragon-is.com
You may also be interested in: