{"id":1026,"date":"2026-03-07T14:12:30","date_gmt":"2026-03-07T12:12:30","guid":{"rendered":"https:\/\/www.cloudtango.net\/blog\/?p=1026"},"modified":"2026-03-07T14:12:31","modified_gmt":"2026-03-07T12:12:31","slug":"what-you-need-to-know-about-the-cyber-essentials-april-2026-update","status":"publish","type":"post","link":"https:\/\/www.cloudtango.net\/blog\/2026\/03\/07\/what-you-need-to-know-about-the-cyber-essentials-april-2026-update\/","title":{"rendered":"What you need to know about the Cyber Essentials April 2026 update"},"content":{"rendered":"<p>The National Cyber Security Centre (NCSC) and IASME have announced the newest update for the UK\u2019s top cybersecurity certification \u2013 Cyber Essentials.<\/p>\n<p>The Cyber Essentials April 2026 update introduces several big changes designed to keep pace with the shifting threat landscape.<\/p>\n<p>Having a\u00a0Cyber Essentials certification\u00a0demonstrates that your business is among the top IT providers and aligns with cybersecurity best practices.<\/p>\n<p>With these new updates, to not only become accredited by Cyber Essentials ,but also remain an accredited and certified Cyber Essentials business, you\u2019ll need to adhere to the changes they\u2019re set to make in April.<\/p>\n<p>In this blog, we\u2019ll break down what these changes are and what you can do as a business to think ahead.<\/p>\n<h2 class=\"wp-block-heading\">Mandatory MFA rule<\/h2>\n<p>This rule has been in place for Google Cloud Services since the end of 2025, but now the criteria are becoming even stricter.<\/p>\n<p>Read more:\u00a0<a href=\"https:\/\/cloudtech24.com\/2025\/05\/mandatory-mfa-for-google-cloud-users-by-the-end-of-2025\/\">Mandatory MFA for Google Cloud users by the end of 2025<\/a><\/p>\n<p>MFA (Multi-factor authentication) is now non-negotiable for all cloud services.<\/p>\n<p>By April 27th 2026, if a cloud service supports MFA, whether that service is free or subscription-based, you must implement it. If you haven\u2019t, then it will result in an automatic failure from Cyber Essentials.<\/p>\n<h2 class=\"wp-block-heading\">Embracing passwordless authentication<\/h2>\n<p>Over the past few years, there\u2019s been a clear aim to move away from traditional password-based login, and it\u2019s only gotten clearer following Cyber Essentials\u2019 new updates, which place heavy emphasis on passwordless authentication.<\/p>\n<p>The NCSC is now explicitly recommending the use of Passkeys and FIDO2 (Fast Identity Online2), such as Touch ID and Face ID authenticators.<\/p>\n<p>These methods use public-key cryptography (such as biometrics or hardware tokens) to verify identity, making them significantly more resistant to phishing than traditional passwords.<\/p>\n<p>By suggesting passwordless authentication as the standard, the scheme is telling businesses to adopt a more secure approach.<\/p>\n<p>Read more:\u00a0<a href=\"https:\/\/cloudtech24.com\/2026\/01\/ct24-jan-a-quick-guide-to-passwordless-login\/\">A quick guide to passwordless login<\/a><\/p>\n<p>This means that things like hardware security keys or biometric devices are now an official way to meet Cyber Essentials requirements.<\/p>\n<h2 class=\"wp-block-heading\">Cloud services are the new norm<\/h2>\n<p>The update tightens the requirements for cloud security by introducing a strict definition of cloud services.<\/p>\n<p>To comply, companies, in a sense, need to perform a full \u201ccloud audit\u201d, similar to what they would do with inventory. This includes any cloud tools that you buy later down the line.<\/p>\n<p>The most important thing to remember is that it\u2019s an automatic fail if you\u2019re found to have any cloud app holding company data that you haven\u2019t informed Cyber Essentials about.<\/p>\n<p>This includes SaaS (software as a service), apps, and storage\/management platforms, as they cannot be excluded from the assessment scope if they handle any sort of organisational data.<\/p>\n<h2 class=\"wp-block-heading\">How to prepare for the April 2026 update<\/h2>\n<p>All of these updates officially begin on April 27th 2026, so from that point onward, all assessments from Cyber Essentials will be judged against these new updates.<\/p>\n<p>So what can you do to ensure your business is ready?<\/p>\n<ol class=\"wp-block-list\">\n<li>Update MFA on every cloud service that you use, whether free or subscription-based.<\/li>\n<li>Ensure every cloud service is fully stated and documented to comply with Cyber Essentials\u2019 new changes.<\/li>\n<li>Utilise new passwordless login techniques like biometrics and hardware tokens.<\/li>\n<\/ol>\n<h2 class=\"wp-block-heading\">A final thought<\/h2>\n<p>This update from Cyber Essentials is adapting to the current, rapid changes that businesses are seeing<\/p>\n<p>By making MFA a must, going modern with logins, and closing the gaps in cloud scoping, the NCSC and IASME are ensuring that Cyber Essentials remains a strong way to ensure you\u2019re up to standard with cybersecurity, rather than just a \u201cbadge\u201d on a website.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The National Cyber Security Centre (NCSC) and IASME have announced the newest update for the UK\u2019s top cybersecurity certification \u2013 Cyber Essentials. The Cyber Essentials April 2026 update introduces several big changes designed to keep pace with the shifting threat landscape. Having a\u00a0Cyber Essentials certification\u00a0demonstrates that your business is among the top IT providers and[\u2026] <a class=\"read-more\" href=\"https:\/\/www.cloudtango.net\/blog\/2026\/03\/07\/what-you-need-to-know-about-the-cyber-essentials-april-2026-update\/\">Read<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" enable-background=\"new 0 0 24 24\" height=\"16px\" viewBox=\"0 0 24 24\" width=\"16px\" fill=\"#091926\"><rect fill=\"none\" height=\"16\" width=\"16\"\/><path d=\"M14.29,5.71L14.29,5.71c-0.39,0.39-0.39,1.02,0,1.41L18.17,11H3c-0.55,0-1,0.45-1,1v0c0,0.55,0.45,1,1,1h15.18l-3.88,3.88 c-0.39,0.39-0.39,1.02,0,1.41l0,0c0.39,0.39,1.02,0.39,1.41,0l5.59-5.59c0.39-0.39,0.39-1.02,0-1.41L15.7,5.71 C15.32,5.32,14.68,5.32,14.29,5.71z\"\/><\/svg><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-1026","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"_links":{"self":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/comments?post=1026"}],"version-history":[{"count":2,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1026\/revisions"}],"predecessor-version":[{"id":1029,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/posts\/1026\/revisions\/1029"}],"wp:attachment":[{"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/media?parent=1026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/categories?post=1026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudtango.net\/blog\/wp-json\/wp\/v2\/tags?post=1026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}