What Cyber Essentials v3.3 mean for your business? | Bistech

What is Cyber Essentials v3.3?

Cyber Essentials v3.3 is the updated version of the UK Government-backed cyber security standard that defines the baseline controls organisations must meet. As of 27 April 2026, it has evolved from v3.2 to the Danzell v3.3 question set.

The update reflects how modern organisations actually operate, particularly their reliance on cloud services, identity-based access and software-driven processes.

Why the changes matter

The v3.3 update responds directly to shifts in cloud adoption, identity-focused cyber threats and software supply chain risk. As a result, organisations now have clearer expectations and a stronger baseline to work from.

These changes reinforce an important principle. Real security comes from implementing effective controls, not simply holding a certificate.

Before you rush to recertify

Organisations are encouraged to recertify as quickly as possible. However, that approach often misses the point.

It is not the certificate that improves your security posture. It is the correct implementation of the controls and the maturity that follows. It is the principle we encourage customers to adopt when preparing for Cyber Essentials v3.3.

Taking time to understand the changes and apply them properly delivers far greater long-term value than rushing through assessment.

Key changes in Cyber Essentials v3.3

The most notable updates include:

Bringing cloud services fully into scope which reflects cloud‑first environments and removes earlier ambiguity

Referencing passwordless and FIDO2 authentication more clearly, encouraging a move towards phishing-resistant identity methods.

Simplifying scope wording by removing references to untrusted connections, reducing confusion that is often found in hybrid environments.

Introducing a Software Security Code of Practice for organisations that build or customise software

Placing greater emphasis on backups, reflecting their importance in ransomware defence, even though they remain outside formal controls

When do the new requirements apply?

The timing of Cyber Essentials v3.3 is based on when your assessment account is created.

IASME has confirmed that:

  • all assessment accounts created on or after 26 April 2026 must use the v3.3 requirements
  • organisations with an active assessment account created before this date have six months to achieve certification using the previous version

Cyber Essentials applications under the previous Willow version can be submitted until 27 October 2026.

For organisations pursuing Cyber Essentials Plus, there is an additional three-month extension, allowing assessments to be completed until 27 January 2027.

This phased transition gives organisations time to adapt without disrupting certification plans already in progress.

MFA expectations are now stricter

Multifactor authentication has been part of Cyber Essentials for some time. What has changed under v3.3 is how it is enforced.

Where multifactor authentication is available for cloud services, whether it is free, included, provided through another service or available as a paid option, failure to implement it will result in an automatic failure.

There is no longer flexibility where MFA exists but is not enabled. This change reflects how commonly cyber attacks exploit weak or compromised credentials and highlights the critical role MFA plays in protecting cloud environments.

Why these changes help your business

The latest updates provide stronger protection against current cyber threats, especially as attackers increasingly target identity methods, cloud environments and software supply chains.

By sharpening its focus in these areas, Cyber Essentials v3.3 raises the baseline of security across organisations of all sizes.

Clearer requirements also reduce the risk of misconfiguration. Many teams struggle with vague or inconsistently interpreted controls, which can lead to gaps in protection. The refined guidance in v3.3 allows organisations to apply controls with greater confidence and accuracy.

In practical terms, the changes also support improved resilience and recovery. Stronger expectations around backups and secure development help organisations withstand incidents and reduce risks introduced during software creation.

Common misconceptions about Cyber Essentials v3.3

A common misconception is “We should recertify early before the bar rises.” In reality, focusing on improving your controls provides far more long‑term value than rushing certification.

Another belief is that “Cloud is not really in scope yet.” Cloud services are firmly in scope under v3.3 and should be treated as a priority area for review and improvement.

Some organisations also assume that “Passwordless is optional.” While technically optional, passwordless authentication is strongly encouraged because it significantly reduces phishing risk while improving usability.

How to prepare for Cyber Essentials v3.3

Use the checklist below to begin planning.

  1. review your cloud environment and confirm ownership of each service.
  2. evaluate your MFA setup and consider adopting passwordless authentication.
  3. assess your software development or customisation practices
  4. revisit your backup and recovery processes
  5. map your current controls to the v3.3 updates to identify priority improvements.

Ready to talk through your next steps?

Bistech helps organisations interpret the new requirements and turn them into clear, actionable plans.

Our team guides businesses through cloud security, modern authentication, secure development practices and overall security uplift, so the changes lead to real improvements rather than surface‑level compliance.

Book a short conversation with our team to review your position against v3.3 and shape a pragmatic plan that aligns with your goals.

 

Book a call today


Louis Adams, Senior Solutions Architect

Louis Adams helps organisations navigate modern technology and cyber security by turning complex technical challenges into practical business outcomes. As a Senior Solutions Architect at Bistech, he works closely with customers to develop secure, scalable, and resilient technology strategies aligned to long-term goals. With experience across cyber security, cloud, infrastructure, and managed services, Louis combines technical expertise with a practical, customer-focused approach. He delivers strategic workshops, shares industry insights, and helps organisations strengthen security, manage risk, and maximise the value of their technology investments.