If you run a small or medium-sized business, you already know that Cyber Essentials is the gold standard for proving to your clients that their data is safe in your hands. But what you might not know is that the rules of the game are about to change.
On April 27th, 2026, the National Cyber Security Centre (NCSC) is rolling out one of its strictest updates in recent years: Version 3.3 (also known as the “Danzell” update).
The bad news? The “easy passes” are gone. The good news? We’re here to help you navigate the changes without the jargon. Here is what you need to know before you renew.
1. The End of “Optional” MFA
For years, Multi-Factor Authentication (MFA)—where you need a password plus a code sent to your phone—was highly recommended. Under the old rules, an auditor might just give you a slap on the wrist if you hadn’t turned it on for every single app.
As of April 27th, MFA is mandatory wherever it is technically available.
* Does your cloud software offer MFA as a free feature? You must use it.
* Does your software only offer MFA if you pay for a premium upgrade? You still must use it.
If a cloud service supports MFA and you haven’t enforced it across all your staff accounts (not just the admins), your assessment is an automatic fail. There are no longer any acceptable excuses for bypassing it.
2. Your Cloud Apps Are Now in the Crosshairs
In the past, there was a lot of grey area around what counted as a “Cloud Service.” Some businesses assumed that because their data was sitting in an external app (like a CRM or HR software), it wasn’t their responsibility to secure it for the audit.
The 2026 update removes that ambiguity completely. If a cloud service stores or processes your organisational data, it is formally “in scope.” You cannot simply tick a box saying it’s handled by someone else; you must prove that the service is configured securely and that your team’s access is locked down.
3. The “No Hiding” Scoping Rules
The new guidelines also tighten the net on the devices your team uses. Any device connected to the internet must be included in your assessment. If you want to exclude a specific device or network, you now have to provide detailed technical proof that it is completely separated from the rest of your business data.
Don’t Wait for a Fail Notice
If your renewal is coming up, or if you are applying for Cyber Essentials for the first time to win a new contract, the April 2026 changes mean you can no longer treat the certification as a “tick-box exercise.” Assessors will be looking for real, technical proof that your security is actually working.
Is your business ready for the April 27th deadline?
If this has prompted you to think about how your business could be more secure, WebbyTech is here to help. You can see the full range of services we offer
here or
contact us directly for a no obligations conversation.