ITogether is proud to hold both Cyber Essentials and ISO 27001 certification โ the worldโs leading standard for information security.
What is changing in April 2026 for Cyber Essentials ?
As of 27 April, Cyber Essentials will be updated to the new “Danzell” question set introducing some additional requirements.
๐๐ฒ๐ ๐ฐ๐ต๐ฎ๐ป๐ด๐ฒ๐ ๐ถ๐ป๐ฐ๐น๐๐ฑ๐ฒ:
๐ ๐ฎ๐ป๐ฑ๐ฎ๐๐ผ๐ฟ๐ ๐ ๐๐: Services must have MFA enabled if available; failure to do so is now an automatic fail.
๐๐น๐ผ๐๐ฑ ๐ถ๐ ๐๐๐น๐น๐ ๐ถ๐ป ๐ฆ๐ฐ๐ผ๐ฝ๐ฒ: Any cloud service (SaaS, PaaS, IaaS) that processes or stores company data and is accessed via a business email/account is in scope. It cannot be excluded.
๐ญ๐ฐ-๐๐ฎ๐ ๐ฃ๐ฎ๐๐ฐ๐ต๐ถ๐ป๐ด: The non-patching of High-risk and critical security updates within 14 days is now an automatic failure.
๐ฅ๐ฒ๐บ๐ผ๐๐ฒ ๐ช๐ผ๐ฟ๐ธ๐ฒ๐ฟ ๐๐ผ๐ฐ๐๐: The scope broadens from “home workers” to “remote workers” (including cafes/hotels) to cover all off-site devices.
๐ญ๐ฎ-๐ ๐ผ๐ป๐๐ต ๐๐ฒ๐ฐ๐น๐ฎ๐ฟ๐ฎ๐๐ถ๐ผ๐ป: A senior official must sign a declaration promising to maintain compliance throughout the entire 12-month certification period.
๐ฃ๐ฎ๐๐๐๐ผ๐ฟ๐ฑ๐น๐ฒ๐๐ ๐ฎ๐ ๐๐ต๐ฒ ๐๐ผ๐น๐ฑ ๐ฆ๐๐ฎ๐ป๐ฑ๐ฎ๐ฟ๐ฑ: The update recognises and encourages methods such as passkeys, biometrics and FIDO2 hardware tokens. ITogether suggest Yubikey.
๐๐ผ๐ฐ๐๐ ๐ผ๐ป ๐๐ฎ๐ฐ๐ธ๐๐ฝ ๐ฅ๐ฒ๐๐ถ๐น๐ถ๐ฒ๐ป๐ฐ๐ฒ: While backups are still technically guidance, the framework elevates their importance with a focus on ensuring they are offline and/or immutable. Of course they should also be tested frequently for recovery.
If you want a Network & Cybersecurity partner whose practices are independently verified to global standards, talk to us today. Letโs keep your organisation running securely and seamlessly.
๐ UK +44 (0) 113 341 0123
๐ NZ +64 (0)9 802 2444
๐ง hello@itogether.com

0 Comments