Critical changes to Cyber Essentials Plus – action may be required to avoid future certification risk

Image to illustrate critical changes to Cyber Essentisals Plus

Fundamental changes to the Cyber Essentials Plus (CE+) scheme are being introduced that will impact anyone starting or renewing their Cyber Essentials certification after 27 April 2026.

The governing body, IASME, is introducing Version 3.3, which significantly increases the “jeopardy” of the assessment. Based on our analysis of these new rules, we estimate that approximately 90% of organisations that passed last year would likely fail this time without a change in approach.

Please note: these changes will apply regardless of which company you use as a Certification Body for Cyber Essentials/Cyber Essentials Plus.

Why the stakes are now higher for Cyber Essentials Assessment

The assessment process has become much more clinical, with stricter “auto-fail” criteria:

  • The Double-Sampling Rule: If your initial scan identifies vulnerabilities, Certification Bodies are now required to conduct a second scan on double the number of devices. This is likely to involve an additional fee.
  • Limited Notice: Certification Bodies are now only permitted to confirm which devices make up the initial sample set three days before the assessment.
  • Instant Failure: If a vulnerability from the first scan appears in the second sample, it is an instant failure. Revocation of All Certificates: A failure at the CE+ stage now results in the immediate revocation of your basic Cyber Essentials certificate. Because the basic certificate is a prerequisite for CE+, you would lose both and be required to pay for and restart the entire process from the beginning.
  • Certification Bodies now have to perform two extra tests – one for scope boundary and one for internal scope validation – if it turns out your scope doesn’t match what you said in CE Level 1, that’s also an instant fail.

Moving forward together

At Securious, we believe these changes are ultimately a good thing; they ensure the certification remains a meaningful and robust mark of security. However, we recognise they also place a significant burden on your team to ensure every device is perfectly patched at the moment of the audit.

To help manage this risk, we have developed a proactive safety net designed to move away from the “all or nothing” stress of audit week and provide the visibility needed to fix issues long before they threaten your certification.

Our recommended solution: Cyber Essentials Vulnerability Scanning Service

To keep you safely on the right side of the new auto-fail rules, as part of a new Cyber Essentials Vulnerability Scanning Service, Securious can deploy Qualys Cloud Agents across your whole estate and deliver quarterly scan reports throughout the year, highlighting vulnerabilities that must be remediated within 14 days to meet the CE standard.

This gives you regular visibility so you can prioritise critical/high issues before they breach the 14-day window and minimise the chance of any surprises on the day.

Benefits include:

  1. Visibility: You see the exact scan results we see, well before the audit begins.
  2. Compliance: You can verify that your entire estate meets the mandatory 14-day patching rule for high-risk updates.
  3. Efficiency: It removes the stress and “back-and-forth” during the audit week.

 

We are offering the Cyber Essentials Vulnerability Scanning Service for £400 (+ VAT) per annum (plus a one-off £495 + vat set up fee)

Alternatively, we can perform a one-off pre-assessment gap analysis for £1,500 (+ VAT). This will effectively involve a ‘mock assessment’, where our assessors will undertake the same process as they would for real, but share the results with you so you can undertake any required remediation before your official assessment.

Why act now?

IASME’s new rules apply to assessment due after 26 April 2026. Early preparation avoids the scramble and the risk of failing the second CE+ sample set.

Please do get in touch if you would like to start this process or discuss any aspects of the changes and their potential implications further.

See our Cyber Essentials and Cyber Essentials Plus service page here

 

FAQs: Cyber Essentials v3.3 Update

 

Why is the remediation period being removed?

IASME’s new “double sampling” rule is designed to ensure that security is maintained year-round, rather than just being “fixed” during an audit week. If a vulnerability is found in the second, larger sample, it is viewed as a systemic failure of your patching policy, leading to an immediate failure and revocation of your certificates.

Will I know which devices make up the initial sample set?

You will receive three days’ notice of the initial sample set. However, you will not know which devices will be selected if a second, double-sized sample is required due to a failed initial scan. Because of this, your entire estate must be compliant and “audit-ready” at all times.

What are the new rules regarding Multi-Factor Authentication (MFA)?

MFA is now mandatory for all cloud services. If a service offers MFA, it must be enabled for all users; there is no longer a “non-conformity” allowance for services that support it but don’t have it active.

Is Software Development included?

A significant change in Version 3.3 is that any device used for software development must be strictly separated from the assessment scope. If you develop software in-house, we need to review your network segregation to ensure your certification is not at risk.

What happens if I fail the CE+ assessment?

If you fail the CE+ audit (specifically if a vulnerability repeats in the second sample), your basic Cyber Essentials certificate will be revoked. You would lose both certifications, potentially breaching existing contracts or tenders, and would have to pay to restart the entire process from scratch.

How will the Cyber Essentials Scanning Service help?

It removes the guesswork. By having the Qualys agent on your devices, you see the exact same vulnerability data that we see during an audit. It allows you to identify “Auto-Fails” as soon as they occur and track whether your patching process is meeting the mandatory 14-day window for critical updates.

What other benefits are there from the Cyber Essentials Scanning Service ?

By having Qualys Cloud Agents across your whole estate, your organisation will become much more cyber resilient. By maintaining a “compliance-ready” state, it makes subsequent years of Cyber Essentials Plus assessments much easier and far more likely to be successful.

Does Cyber Essentials Plus still require a current Cyber Essentials Certification?

Yes, Cyber Essentials Plus must be completed within three months of Cyber Essentials, so a revocation or expiry forces you to re-do Cyber Essentials before Cyber Essentials Plus. 

What does Cyber Essentials Plus typically cost?

Market rates vary by size/complexity. Many organisations budget £2,500–£3,000 annually. 

Where can I read the official updates?

Please see IASME’s April 2026 update post (https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/) and NCSC’s v3.3 requirements PDF. NCSC “Requirements for IT Infrastructure v3.3” (https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf)

 

.