Changes in April 2026 to Cyber Essentials

ITogether is proud to hold both Cyber Essentials and ISO 27001 certification โ€“ the worldโ€™s leading standard for information security.

What is changing in April 2026 for Cyber Essentials ?

As of 27 April, Cyber Essentials will be updated to the new “Danzell” question set introducing some additional requirements. 

๐—ž๐—ฒ๐˜† ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ๐˜€ ๐—ถ๐—ป๐—ฐ๐—น๐˜‚๐—ฑ๐—ฒ:

๐— ๐—ฎ๐—ป๐—ฑ๐—ฎ๐˜๐—ผ๐—ฟ๐˜† ๐— ๐—™๐—”: Services must have MFA enabled if available; failure to do so is now an automatic fail.

๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐—ถ๐˜€ ๐—™๐˜‚๐—น๐—น๐˜† ๐—ถ๐—ป ๐—ฆ๐—ฐ๐—ผ๐—ฝ๐—ฒ: Any cloud service (SaaS, PaaS, IaaS) that processes or stores company data and is accessed via a business email/account is in scope. It cannot be excluded.

๐Ÿญ๐Ÿฐ-๐——๐—ฎ๐˜† ๐—ฃ๐—ฎ๐˜๐—ฐ๐—ต๐—ถ๐—ป๐—ด: The non-patching of High-risk and critical security updates within 14 days is now an automatic failure.

๐—ฅ๐—ฒ๐—บ๐—ผ๐˜๐—ฒ ๐—ช๐—ผ๐—ฟ๐—ธ๐—ฒ๐—ฟ ๐—™๐—ผ๐—ฐ๐˜‚๐˜€: The scope broadens from “home workers” to “remote workers” (including cafes/hotels) to cover all off-site devices.

๐Ÿญ๐Ÿฎ-๐— ๐—ผ๐—ป๐˜๐—ต ๐——๐—ฒ๐—ฐ๐—น๐—ฎ๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป: A senior official must sign a declaration promising to maintain compliance throughout the entire 12-month certification period.

๐—ฃ๐—ฎ๐˜€๐˜€๐˜„๐—ผ๐—ฟ๐—ฑ๐—น๐—ฒ๐˜€๐˜€ ๐—ฎ๐˜€ ๐˜๐—ต๐—ฒ ๐—š๐—ผ๐—น๐—ฑ ๐—ฆ๐˜๐—ฎ๐—ป๐—ฑ๐—ฎ๐—ฟ๐—ฑ: The update recognises and encourages methods such as passkeys, biometrics and FIDO2 hardware tokens. ITogether suggest Yubikey.

๐—™๐—ผ๐—ฐ๐˜‚๐˜€ ๐—ผ๐—ป ๐—•๐—ฎ๐—ฐ๐—ธ๐˜‚๐—ฝ ๐—ฅ๐—ฒ๐˜€๐—ถ๐—น๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ: While backups are still technically guidance, the framework elevates their importance with a focus on ensuring they are offline and/or immutable. Of course they should also be tested frequently for recovery.

If you want a Network & Cybersecurity partner whose practices are independently verified to global standards, talk to us today. Letโ€™s keep your organisation running securely and seamlessly.

๐Ÿ“ž UK +44 (0) 113 341 0123

๐Ÿ“ž NZ +64 (0)9 802 2444

๐Ÿ“ง hello@itogether.com

0 Comments

Submit a Comment