Important: Changes to Cyber Essentials Certification & how we support you

Changes to Cyber Essentials Certification - urgent update image

The governing bodies for Cyber Essentials have recently introduced significant changes that will affect how organisations achieve certification from 27th April 2026. In many cases, these updates will make the standard harder to achieve, requiring a more robust approach to compliance.

Cyber Essentials (CE) is currently undergoing its most significant period of flux since its inception. With the introduction of the latest standards by IASME and the NCSC, the certification process has become considerably more demanding. The “Verified Self-Assessment” (VSA) is no longer a simple tick-box exercise; it is now a rigorous technical declaration with zero margin for error.

Please note: these changes will apply regardless of which company you use as a Certification Body for Cyber Essentials/Cyber Essentials Plus.

Why the standards are changing

The threat landscape has evolved. To combat sophisticated automated attacks, the governing bodies have tightened “auto-fail” criteria – particularly around Multi-Factor Authentication (MFA), cloud security, and the mandatory 14-day patching rule.

To ensure our clients remain compliant and protected, Securious is updating our support structure for all renewals and new applications effective 27th April 2026.

Updated assessment tiers

To reflect the increased time required for detailed technical verification, our base CE VSA service now includes two structured reviews:

  • The comprehensive review: A full assessment of your questionnaire with detailed feedback and guidance on all weak areas.
  • The final validation: A final pass/fail assessment. Please note: Under new guidelines, if a failure point is identified during this stage, the assessment will cease at that point to allow for remediation. The certification process will then need to be restarted, including the payment of a new certification fee.

Our recommendation: The Cyber Essentials Assisted Package

Given that the standards are now “harder than ever,” we are moving our Cyber Essentials Assisted Package to be our default recommendation for all organisations. This service provides a critical safety net and includes:

  • A one-hour screen-share walkthrough to guide you through the questionnaire.
  • A total of three assessment reviews to ensure accuracy before final submission.

The cost for this service is £295 (+VAT) in addition to the standard certification fees.

Note for large organisations

If your organisation falls under the “Large” category (250+ employees), please be aware that IASME now requires a mandatory moderation period. This can add up to three working days to the feedback loop while we coordinate with the governing body. We advise starting your renewal at least four weeks before your current certificate expires.

A warning on Cyber Essentials Plus

It is important to note that these VSA changes sit alongside even stricter rules for Cyber Essentials Plus. As we recently highlighted here, a failure during the technical audit phase can now result in the immediate revocation of your basic certificate. This “double jeopardy” makes getting the initial VSA right the first time more critical than ever.

Further reading

If you would like to read the official guidance on these changes from the National Cyber Security Centre (NCSC) and IASME, please see the following links:

Moving forward

Cyber Essentials remains the “gold standard” for foundational security in the UK, and these changes ensure the badge continues to carry real-world weight. Our goal is to ensure that you achieve the certification and that your business stays genuinely resilient.

If you have any questions about how these changes affect your upcoming renewal, please contact the Securious team on 01392 247 110, email info@securious.co.uk or send us a message using the form below.