Monitor

Blog › Article

28 July 2026 · Article

Cyber Essentials requirements in 2026

Cyber Essentials asks for five technical controls across everything in scope. The controls haven't changed much in years. What changed in 2026 is how strictly two of them are enforced — and scope, which decides where every control applies, is still where most organisations go wrong.

What Cyber Essentials is for

The scheme exists to stop the most common internet-based attacks: the automated, opportunistic kind that look for an unpatched system, a default password or an account without MFA. It isn't meant to stop a determined, targeted attacker. Its requirements are deliberately basic, which is exactly why falling short on any of them is hard to explain.

Scope: where the requirements apply

Every requirement applies to everything in scope, so scope comes first.

The five technical controls

1. Firewalls

Requirement: every in-scope device is protected by a correctly configured firewall, with inbound connections blocked unless there's a documented need. Default passwords are changed and the admin interface isn't exposed to the internet without good reason and protection.

Why: a firewall is the first thing an automated scan meets. Laptops that leave the office need their own software firewall, because on a hotel or café network the office router isn't protecting them.

2. Secure configuration

Requirement: unnecessary software, services and accounts are removed or disabled, default passwords are changed, autorun is off, and devices lock when unattended. Password-based logins are protected against guessing.

Why: out-of-the-box settings favour convenience. Every default account and unneeded service is something an attacker can try without any effort.

3. Security update management

Requirement: all software in scope is licensed and supported by its vendor, and high-risk or critical updates are applied within fourteen days of release. Unsupported software is removed, or moved into a separate subset with no internet access at all.

Why: once a vulnerability is published, attackers automate it quickly. Fourteen days is the window the scheme allows between a fix existing and it being applied.

4. User access control

Requirement: accounts are created and removed through a defined process, people have only the access they need, administrator accounts are used only for administration, and cloud services use MFA wherever it's offered.

Why: a stolen password for an ordinary account is a nuisance. A stolen password for an administrator account, or for a cloud service with no second factor, is the whole organisation.

5. Malware protection

Requirement: every device that supports it runs anti-malware that is kept up to date, or uses application allow-listing so only approved software can run.

Why: some malicious software will always get as far as a device. This control is about stopping it running once it's there.

The four automatic-fail questions

Since the question set changed on 27 April 2026, four questions fail an assessment on their own. They fall into two groups:

Both requirements existed before. The difference is that a "no" can no longer be balanced against everything else in the questionnaire.

The requirement is continuous; the assessment isn't. Fourteen-day patching means every machine, every fortnight, all year. The questionnaire asks about one day. Organisations that pass comfortably tend to be the ones who know, for any day, how far behind each machine is.

Cyber Essentials Plus requirements

Cyber Essentials Plus has the same requirements. What it adds is proof: instead of accepting the questionnaire's answers, an assessor tests them. That typically means scanning what faces the internet, testing a sample of devices, and checking that malware protection and MFA work in practice rather than on paper.

You need a current Cyber Essentials certificate first, and Plus has to be completed within three months of it. Because the assessor tests real machines, a gap the questionnaire might have glossed over — a laptop weeks behind on updates, say — is exactly what the audit finds.

Quick answers

What are the five Cyber Essentials controls?

Firewalls, secure configuration, security update management, user access control and malware protection.

Do personal devices have to meet the requirements?

If they access organisational data or services, yes, they're in scope.

Are cloud services included?

Yes. Cloud services that hold or process organisational data are in scope, and MFA on them, where it's available, is one of the automatic-fail requirements.