Cyber Essentials Plus 2026: A CISO Checklist for the New Rules | INFORMD Executive Briefing

Cyber Essentials Plus 2026: A CISO Checklist for the New Rules

Cyber Essentials Plus recertification rules change from April 2026, tightening MFA, password and patch requirements set by the NCSC and delivery partner IASME.

The update is the most significant revision to the scheme since its 2022 refresh, and it lands at a moment when Cyber Essentials Plus has become a de facto gate for UK government contracts, supply chain assurance questionnaires and cyber insurance underwriting. According to the UK government’s Cyber Security Breaches Survey 2025/2026, 43% of UK businesses — around 612,000 organisations — reported a breach or attack in the past 12 months, and medium and large businesses were far more exposed, at 65% and 69% respectively. For CISOs, the certificate is no longer a compliance formality; it is increasingly the baseline evidence a board, a customer or an insurer asks for first.

Organisations with an assessment account opened before 26 April 2026 get a six-month grace period on the previous requirements. Everyone else assesses against the new version immediately, which makes early scoping essential rather than optional.

What Is Changing in Cyber Essentials Plus From April 2026?

The scheme’s five technical control areas remain unchanged in structure, but several requirements inside them have been substantially rewritten. Multi-factor authentication now applies to all accounts with internet-facing access, including user accounts into cloud services such as Microsoft 365, Google Workspace or any SaaS application — not just administrator accounts, as many organisations had assumed. The “web applications” control has been renamed “application development” and now references the UK government’s Software Security Code of Practice, bringing publicly available commercial web applications into scope by default rather than by exception.

IASME, which delivers the scheme on the NCSC’s behalf, has also tightened how CE+ on-site and remote assessments are conducted after audits found organisations applying patches only to a sampled subset of devices rather than across the full certification scope. Assessors will now expect evidence that fixes were deployed estate-wide, not just to the machines an auditor happened to check.

Executive Action:

  • Confirm with IT and the assessment body which requirement version applies to your next certification window.
  • Ask the CISO for a gap analysis against the revised five controls before renewal, not during it.
  • Flag the change to procurement teams citing CE+ as a supplier requirement in contracts.

How Should CISOs Prepare for the New MFA and Password Rules?

Password policy is being simplified but made conditional on MFA coverage. Where MFA is enabled, passwords need only be eight characters, with screening against common and breached passwords replacing complex character rules. Where MFA cannot be enabled — some legacy or operational technology systems — the minimum rises to twelve characters. Mandatory periodic password rotation is dropped entirely; passwords should be changed only on evidence of compromise, aligning the scheme with NCSC’s long-standing password guidance and with NIST SP 800-63B.

The practical difficulty is not the policy itself but the discovery work behind it. Many organisations do not have a reliable inventory of every internet-facing account, particularly SaaS tools procured outside central IT. Closing that gap before assessment prevents a failed audit and, more importantly, closes a genuine attack path — credential stuffing and account takeover remain among the most common entry points into UK businesses.

Executive Action:

  • Commission an inventory of all internet-facing and SaaS accounts before the next CE+ assessment cycle.
  • Retire mandatory password rotation policies and replace with breached-password screening.
  • Brief the audit and risk committee on the MFA coverage gap identified, with a remediation date.

What Do the Patch Management and Passwordless Authentication Changes Require?

The scheme now sets a firm 14-day patching window for critical and high-severity updates across all in-scope devices, explicitly extending to firmware on routers, firewalls, managed switches and other internet-connected network equipment — a category many patch management programmes have historically excluded because it sits with network operations rather than endpoint teams. CISOs should expect this to surface ownership gaps between IT, network engineering and any managed service provider.

Alongside this, the user access control requirements now actively promote passwordless authentication — passkeys and hardware security keys — as the preferred alternative to traditional passwords, reflecting NCSC’s broader push away from password-dependent authentication across government and regulated sectors. This is not yet mandatory, but assessors will increasingly treat passkey adoption as evidence of a mature control environment. This work sits close to any zero trust architecture programme already under way, and CISOs should sequence the two rather than run them in parallel.

Executive Action:

  • Extend patch management ownership formally to network and firmware devices, not just endpoints and servers.
  • Pilot passkey or hardware-key authentication for privileged and finance-system accounts this year.
  • Require any managed service provider to confirm firmware patching SLAs in writing.

Why Does Cyber Essentials Plus Matter Beyond the Certificate?

Cyber Essentials Plus increasingly functions as a proxy for operational resilience assurance across three audiences that matter to the board: government and enterprise customers embedding it in procurement terms, cyber insurers using it to underwrite premiums and exclusions, and regulators who reference basic cyber hygiene schemes when assessing whether a board exercised reasonable oversight after an incident. According to NCSC and IASME’s published Cyber Essentials management information, 59,090 certificates were awarded in the year to March 2026, of which 14,482 were at the more rigorous Plus level — a meaningful minority, and a differentiator for organisations that hold it credibly rather than as a box-ticking exercise.

The certification also complements deeper resilience work already under way in many UK organisations, including zero trust architecture rollouts and supply chain risk programmes, both of which overlap directly with the new MFA, device and third-party control requirements. Boards can use our AI governance and project review assessment tools or the technology strategy review template to fold CE+ evidence into existing oversight cycles rather than treating it as a separate exercise.

Executive Action:

  • Position CE+ renewal as evidence for the board’s annual risk and controls attestation, not a standalone IT task.
  • Ask insurers directly whether CE+ status affects premium or ransomware coverage terms at next renewal.
  • Review CE+ scope alongside any active zero trust or supply chain assurance programme to avoid duplicated control work.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/). Questions on your CE+ readiness? Contact INFORMD.

What is Cyber Essentials Plus and who needs it?

Cyber Essentials Plus is the NCSC-backed, IASME-delivered UK certification verifying five technical security controls through independent audit. It is increasingly required for government contracts, supply chain assurance and, in some cases, cyber insurance underwriting, making it relevant well beyond organisations handling government data directly.

When do the new Cyber Essentials Plus rules take effect?

The revised requirements apply to all assessment accounts created after 26 April 2026. Accounts opened before that date have a six-month grace period to certify under the previous version before the new MFA, password and patching rules become mandatory.

Does Cyber Essentials Plus affect cyber insurance premiums?

Insurers increasingly reference Cyber Essentials Plus status when setting premiums and ransomware coverage terms, particularly as the UK’s ransomware payment ban changes recovery options for public bodies and CNI operators. CISOs should confirm directly with insurers whether certification affects renewal pricing.

What is the biggest change CISOs should prepare for first?

Multi-factor authentication now covers every internet-facing account, including SaaS logins, not just administrators. Most organisations lack a full inventory of these accounts, so building one before the next assessment is the single highest-priority preparation step.

Similar Posts