Axistwelve Insights

Cyber Essentials requirements and what a certificate proves

Written by Axistwelve | Aug 25, 2026, 7:00:00 AM

The Cyber Essentials requirements cover five technical controls, and a certificate confirms that an assessor accepted the organisation met all five on the day it was assessed, across the scope it declared. The certificate runs for twelve months from issue.

Two versions of the requirements are in circulation this year, and the April 2026 update changed how one control is marked rather than introducing it.

The five controls the Cyber Essentials requirements cover

Five controls make up the assessment: firewalls, secure configuration, user access control, malware protection, and security update management. Together they function as the checklist an assessor works through, and they apply across the devices, servers and cloud services an organisation puts in scope.

Security update management carries the tightest deadline of the five, at 14 days from release for critical and high-risk updates. For a buyer, that makes patching cadence the more useful thing to ask about.

Ask how a supplier evidences update timings in the months between assessments and you learn more about how the estate is run than the certificate itself tells you.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is awarded on a verified self-assessment, and Cyber Essentials Plus adds a technical audit in which a qualified assessor tests a sample of devices rather than accepting the declared answers. Both tiers cover the same five controls and both certificates last twelve months.

At the base tier the organisation works through a question set, someone at board level signs to confirm the answers are accurate, and an independent assessor reviews the submission without touching the systems, while the Plus assessor scans a sample of devices for vulnerabilities.

That distinction decides which tier belongs in a tender. For work involving citizen data or a live connection into a government network, Plus is the level worth naming at RFI rather than accepting later.

Who owns Cyber Essentials, and who sets the cost of certification?

The National Cyber Security Centre owns Cyber Essentials, a UK government-backed certification scheme covering baseline technical controls. IASME delivers it as the Official Delivery Partner and licenses the Certification Bodies that carry out assessments, so the certificate a supplier shows you was issued by one of those bodies rather than by NCSC directly. IASME also holds the record of which organisations are certified, which is what a supplier’s emailed PDF should be checked against.

Certification fees are set by IASME and the Certification Bodies it licenses. Anyone budgeting for Cyber Essentials or Cyber Essentials Plus should take the figure from IASME rather than from a summary published by a reseller, since the fee depends on the assessment route and the organisation being assessed. The NCSC scheme overview sets out what the certification is designed to cover.

What changed in Cyber Essentials in April 2026?

Requirements v3.3 took effect in April 2026 and made failing to apply multi-factor authentication to cloud services an automatic fail. Multi-factor authentication on cloud services was already mandatory before that date. Requirements v3.2 states that “authentication to cloud services must always use MFA”, and the same version put cloud services in scope. The self-assessment question set changed at the same point, from Willow to Danzell.

Two further changes came with v3.3. A formal definition of what counts as a cloud service was added, and the scoping criteria were simplified so that an organisation now has to justify anything it leaves out.

The automatic fail applies whether the multi-factor authentication is included in a licence the organisation already pays for or charged as an extra. An organisation failing on that control under v3.3 is failing a requirement that has been in force since April 2025, marked more severely than it was.

Plus retests now draw a fresh sample of devices

Where a Plus assessment fails and is retested, the assessor tests a new random sample of devices alongside the ones checked first. A second failure revokes the certificate. Self-assessment answers are locked once Plus testing begins, so an applicant can no longer revise them part way through an audit.

A supplier therefore cannot prepare only the machines it expects to see tested, which makes a Plus certificate awarded on retest under v3.3 harder-won evidence than the same document was previously.

What a certificate proves to a buyer reading one

Scope is where the ambiguity usually sits. An organisation can certify a single business unit or one hosting environment, so the question worth asking is whether the scope named on the document covers the team and the infrastructure that will actually deliver your contract.

The issue date does not tell you which version of the Cyber Essentials requirements applied. Organisations with an assessment account created before the cut-over have six months to certify under the previous Willow requirements. Add the twelve-month validity to that window and a certificate assessed against the older bar can still be live into 2027, carrying a 2026 date.

Asking which question set the assessment used, Willow or Danzell, settles it in a single line of an email and tells you more than the date does. Pair it with the scope statement and you know what the certificate is worth before you score the bid.

The checks that apply across a supplier’s other certificates, from ISO 27001 to a framework listing, are set out in our guide to the security accreditations public sector suppliers need.

AxisTwelve holds Cyber Essentials Plus, listed with our accreditations and verifiable with IASME.

Frequently asked questions

What is the Danzell question set?

Danzell is the Cyber Essentials self-assessment question set introduced in April 2026, replacing Willow. It accompanies Requirements v3.3.

What is the Cyber Essentials patching deadline?

Critical and high-risk security updates must be applied within 14 days of release. Security update management is the one control of the five that depends on a routine held every fortnight for a year rather than on a setting configured once.

Is a Cyber Essentials certificate issued before April 2026 still valid?

Yes. A certificate runs for twelve months from issue and holds for its full term. IASME also gives organisations six months to certify under the previous requirements where the assessment account was created before the cut-over.