BITS Group
Cyber Essentials just got stricter. Here's what changed and why it matters for your renewal

Cyber Essentials just got stricter. Here's what changed and why it matters for your renewal

Last Tuesday, the head of the National Cyber Security Centre stood up at the CYBERUK conference in Glasgow and said something that made a lot of IT teams sit up straight. Richard Horne confirmed that his agency is now handling around four nationally significant cyber incidents every single week, and that the most serious attacks are increasingly coming from nation states, not just criminal gangs. China, Russia, and Iran were all named directly.

Five days later, today, the updated Cyber Essentials v3.3 standard takes effect. The timing isn't a coincidence. The bar is being raised because the threat landscape has shifted, and the old standard wasn't keeping pace.

If your business holds Cyber Essentials certification, or you've been meaning to get it, here's what you need to know.

MFA is no longer optional for any cloud service

This is the headline change. Under v3.3, multi-factor authentication (MFA) must be turned on for every cloud service your business uses, wherever the option exists. That includes Microsoft 365, Google Workspace, your CRM, your accounting software, your project management tools. If MFA is available and it isn't switched on, your assessment fails. Full stop.

Previously, there was some wiggle room. Businesses could point to IP allowlisting as an alternative to MFA in certain situations. That's gone. IP allowlisting is no longer accepted as a substitute.

For most organisations we work with, the practical impact is this: you need to audit every cloud service your team uses and confirm MFA is enabled on each one. That includes the tools people signed up for themselves (the ones IT didn't necessarily know about). Shadow IT becomes a compliance problem, not just a security one.

The patching window just got tighter

Cyber Essentials has always required you to keep systems patched, but v3.3 makes the timeline explicit. All critical and high-risk security updates for operating systems, router and firewall firmware, and applications (including browser extensions) must be installed within 14 days of release. Miss it on even one system and the assessment fails, regardless of how well you score everywhere else.

Fourteen days sounds generous until you factor in change approval processes, testing, and the reality that someone in accounts is still running a three-year-old browser extension nobody knew about. The businesses that handle this well tend to have automated patch management in place. The ones that struggle are still relying on someone remembering to click "update later" one fewer time.

Cloud services are now defined more broadly

The definition of what counts as a "cloud service" under Cyber Essentials has expanded. Any service accessed via a business email or account is now in scope. That pulls in a lot of SaaS tools that might previously have sat outside the assessment boundary: your email marketing platform, your e-signature tool, your HR system.

This is actually a sensible change. Attackers don't respect the boundaries of an audit scope. If your team logs into a service with company credentials and no MFA, that's a way in, whether or not it was on the Cyber Essentials checklist before.

Why this matters beyond the certificate

It would be easy to treat these changes as a compliance headache and nothing more. But the NCSC's warning from last week puts them in a sharper light. State-backed groups are now using large-scale covert networks for everything from reconnaissance to data exfiltration. Supply chain compromise is the fastest-growing attack vector. And 79% of small businesses have experienced at least one cyber attack in the last five years, according to Coalition's most recent study.

The updated Cyber Essentials standard isn't just about passing an audit. It's about making sure the basics are genuinely covered, because the basics are still where most attacks succeed. Phishing, stolen credentials, unpatched systems. The UK Government's Cyber Security Breaches Survey consistently shows that the most common attacks aren't sophisticated. They're opportunistic. They work because a cloud login didn't have MFA, or a patch sat waiting for three months, or nobody checked what tools the team was actually using.

What to do before your next renewal

If your Cyber Essentials renewal is coming up in the next few months, or if you're going for certification for the first time, there are a few things worth doing now.

  1. Run an audit of every cloud service your business uses. Not just the ones IT manages, but the ones people signed up for with a work email. Check MFA is enabled on each one.

  2. Review your patching process. Can you confidently say that critical updates are applied within 14 days across all devices and applications? If not, automated patch management is worth looking at.

  3. Check for shadow IT. Browser extensions, free SaaS tools, that PDF converter someone installed last year. Under v3.3, these are all in scope.

  4. Brief your team. The people using these tools every day need to understand that MFA prompts aren't optional and that updates can't be deferred indefinitely.

The good news is that none of this requires a massive budget or a team of specialists. It requires visibility into what your business actually uses, a sensible patching routine, and MFA switched on everywhere. Most of the organisations we support get there with a straightforward review and a few configuration changes.

If you're unsure where your setup stands against the new v3.3 requirements, a quick Cyber Essentials readiness check is a good place to start. Our team runs these regularly, and they're a practical way to catch gaps before they become a compliance issue or, worse, a security one. We also offer a free Cyber Essentials Checklist on our website to get you started.

Need IT Support?

Contact us today for a free consultation and discover how we can help your business.

Get Started Today