26 August 2026 | By James Thomas
Four challenges every organisation must solve to adopt AI safely
Discover four key challenges affecting AI adoption and how organisations can build confidence in their approach.
Read moreCyber Essentials v3.3 is the updated version of the UK Government-backed cyber security standard that defines the baseline controls organisations must meet. As of 27 April 2026, it has evolved from v3.2 to the Danzell v3.3 question set.
The update reflects how modern organisations actually operate, particularly their reliance on cloud services, identity-based access and software-driven processes.
The v3.3 update responds directly to shifts in cloud adoption, identity-focused cyber threats and software supply chain risk. As a result, organisations now have clearer expectations and a stronger baseline to work from.
These changes reinforce an important principle. Real security comes from implementing effective controls, not simply holding a certificate.
Organisations are encouraged to recertify as quickly as possible. However, that approach often misses the point.
It is not the certificate that improves your security posture. It is the correct implementation of the controls and the maturity that follows. It is the principle we encourage customers to adopt when preparing for Cyber Essentials v3.3.
Taking time to understand the changes and apply them properly delivers far greater long-term value than rushing through assessment.
The most notable updates include:
Bringing cloud services fully into scope which reflects cloud‑first environments and removes earlier ambiguity
Referencing passwordless and FIDO2 authentication more clearly, encouraging a move towards phishing-resistant identity methods.
Simplifying scope wording by removing references to untrusted connections, reducing confusion that is often found in hybrid environments.
Introducing a Software Security Code of Practice for organisations that build or customise software
Placing greater emphasis on backups, reflecting their importance in ransomware defence, even though they remain outside formal controls
The timing of Cyber Essentials v3.3 is based on when your assessment account is created.
IASME has confirmed that:
Cyber Essentials applications under the previous Willow version can be submitted until 27 October 2026.
For organisations pursuing Cyber Essentials Plus, there is an additional three-month extension, allowing assessments to be completed until 27 January 2027.
This phased transition gives organisations time to adapt without disrupting certification plans already in progress.
Multifactor authentication has been part of Cyber Essentials for some time. What has changed under v3.3 is how it is enforced.
Where multifactor authentication is available for cloud services, whether it is free, included, provided through another service or available as a paid option, failure to implement it will result in an automatic failure.
There is no longer flexibility where MFA exists but is not enabled. This change reflects how commonly cyber attacks exploit weak or compromised credentials and highlights the critical role MFA plays in protecting cloud environments.
The latest updates provide stronger protection against current cyber threats, especially as attackers increasingly target identity methods, cloud environments and software supply chains.
By sharpening its focus in these areas, Cyber Essentials v3.3 raises the baseline of security across organisations of all sizes.
Clearer requirements also reduce the risk of misconfiguration. Many teams struggle with vague or inconsistently interpreted controls, which can lead to gaps in protection. The refined guidance in v3.3 allows organisations to apply controls with greater confidence and accuracy.
In practical terms, the changes also support improved resilience and recovery. Stronger expectations around backups and secure development help organisations withstand incidents and reduce risks introduced during software creation.
A common misconception is “We should recertify early before the bar rises.” In reality, focusing on improving your controls provides far more long‑term value than rushing certification.
Another belief is that “Cloud is not really in scope yet.” Cloud services are firmly in scope under v3.3 and should be treated as a priority area for review and improvement.
Some organisations also assume that “Passwordless is optional.” While technically optional, passwordless authentication is strongly encouraged because it significantly reduces phishing risk while improving usability.
Use the checklist below to begin planning.
Bistech helps organisations interpret the new requirements and turn them into clear, actionable plans.
Our team guides businesses through cloud security, modern authentication, secure development practices and overall security uplift, so the changes lead to real improvements rather than surface‑level compliance.
Book a short conversation with our team to review your position against v3.3 and shape a pragmatic plan that aligns with your goals.