Cyber essentials 2026 update

Cyber Essentials 2026 Update: What SMEs Need to Know

Cyber Essentials has long provided a practical, accessible way for organisations to protect themselves against the most common cyber threats, while being a clear, public signal that a business takes cyber security seriously.

As cyber threats have grown more sophisticated and businesses have shifted toward cloud‑based and hybrid working, the standard has quietly been going through a period of modernisation to keep it aligned with current best practice.

From 27 April 2026, these strengthened Cyber Essentials requirements became the mandatory baseline for any organisation wishing to achieve or renew certification.

 

What is Cyber Essentials?

Cyber Essentials is a government‑backed cyber security standard designed to help organisations of all sizes protect themselves against the most common threats. It focuses on five key areas:

  • Secure configuration
  • Firewalls and internet gateways
  • Access control
  • Malware protection
  • Patch management

 

Cyber Essentials Plus takes this even further, including everything covered in the basic Cyber Essentials certification, but with one major difference: It is independently tested and verified by a qualified assessor.

For SMEs, Cyber Essentials has long been a trusted way to demonstrate good cyber hygiene, reassure customers and partners, meet supply‑chain expectations and reduce the risk of common cyberattacks. Increasingly, it also supports growth by helping businesses qualify for new opportunities. For example, Cyber Essentials is also becoming a common prerequisite in public sector procurement, with many government departments and agencies requiring certification for suppliers handling sensitive or personal data.

It is designed to be practical and achievable, even by small businesses with limited internal IT resource.

While the 2026 update hasn’t changed the purpose of Cyber Essentials, it has significantly raised the bar.

 

Why the standard needed an update

When Cyber Essentials launched in 2014, the threat landscape was far simpler. Today, SMEs face a very different set of challenges, including targeted phishing campaigns and ransomware. There are also some key vulnerabilities, such as around remote working, misconfigured cloud services, supply‑chain risk, and the use of mobile devices.

The National Cyber Security Centre (NCSC) has updated the standard to reflect these realities. The goal being to ensure Cyber Essentials remains relevant, practical, and effective.

Government data shows just how widespread cyber incidents have become. According to the UK’s Cyber Security Breaches Survey 2025, 43% of businesses experienced a cyber breach or attack in the past 12 months. The risk increases sharply with size, with 67% of medium‑sized businesses and 74% of large organisations reporting incidents over the same period.

 

What changes have been made to Cyber Essentials in 2026?

  1. Cloud services are now fully in scope

This is one of the most significant updates. Many SMEs rely on Microsoft 365, Google Workspace, AWS, and other cloud platforms, but historically, cloud responsibilities have often been misunderstood.

Under the new rules, organisations must demonstrate:

  • Mandatory multi‑factor authentication (MFA)
  • Secure configuration of cloud services
  • Proper access controls
  • Understanding of shared‑responsibility models
  • Logging and monitoring where available

If your business uses cloud services – as most SMEs now do – this is a major area to review.

 

  1. Stronger identity and access management

Compromised credentials remain one of the biggest causes of cyber breaches. The updated standard now requires:

  • MFA across more systems
  • Stronger password policies
  • Stricter controls on admin accounts
  • Clearer separation between standard and privileged access

Identity is now treated as a core security control, not an optional extra.

 

  1. Tighter controls on devices and patching

With the rise in hybrid working, the new standard places greater emphasis on:

  • Device management
  • Operating system versions
  • Patching timelines
  • Mobile device security
  • BYOD (Bring Your Own Device) policies

Unmanaged laptops and mobiles, especially those used at home, are now a much bigger focus for assessors.

 

  1. Updated firewall and network requirements

The new rules clarify what “good” looks like for network protection, including:

  • Stricter expectations for default settings
  • Improved segmentation
  • Clearer rules for home‑working setups
  • Better logging and monitoring

For SMEs with remote teams, this is particularly important.

 

  1. A more detailed assessment process

The 2026 update also strengthens the assessment itself. Businesses can expect:

  • More detailed evidence requirements
  • Clearer definitions of what is in scope
  • Fewer ambiguities
  • More consistency between assessors

SMEs will need to be more organised and proactive when preparing for certification or renewal.

 

What does the Cyber Essentials 2026 update mean for SMEs?

The updated Cyber Essentials standard remains achievable, but it does require more preparation than before.

Here’s what SMEs should focus on now that the new rules are live:

  • Review your cloud setup – Misconfigurations are one of the biggest risks for SMEs.
  • Enforce MFA everywhere – If MFA isn’t already universal, it needs to be.
  • Get control of devices – Every laptop, mobile, and tablet used for work must be secure and accounted for.
  • Update your policies – Clear, practical policies are now essential, especially around remote working and BYOD.
  • Document your evidence – The new assessment process expects more clarity and proof of compliance.

 

Why these changes matter

Cyber Essentials has always been about reducing the risk of the most common cyber risks. The 2026 update strengthens that mission and ensures the standard remains relevant in a world where cyber threats evolve quickly.

For SMEs, this is an opportunity to modernise systems, improve resilience, and demonstrate a strong commitment to security to customers, partners, and regulators.

 

How Dragon can help

At Dragon, we work closely with SMEs, including those in the financial, legal and professional services, to help them meet the new Cyber Essentials requirements with confidence. But our support goes far beyond certification.

We help organisations build efficient, robust IT infrastructure, strengthen their cyber security posture, enable secure and productive remote working, and adopt AI tools safely and effectively. Whether you’re modernising your systems, tightening your defences, or exploring new technologies, we provide practical, tailored guidance that fits the realities of SME operations.

Whether you’re navigating the new Cyber Essentials rules for the first time or renewing under the updated framework, Dragon can help you stay secure, compliant, and ahead of the curve, while ensuring your technology supports your business, not the other way around.

Talk to us about Cyber Security-as-a-Service, an easy way to stay compliant and protected.

Get in touch to find out more – info@dragon-is.com

 

You may also be interested in: