Cyber Essentials Renewal: What Changes From Year to Year
Cyber Essentials Renewal: What Changes From Year to Year
A lot of businesses treat Cyber Essentials as something you get once and file away. It isn’t. Your certificate is valid for exactly 12 months from the date it’s issued, and renewing isn’t just re-submitting the same answers you gave last time. The scheme itself gets updated, usually once a year, and this year’s update is bigger than most.
The Basic Cycle
Whichever level you hold, Cyber Essentials or Cyber Essentials Plus, you go through the assessment again at renewal: the self-assessment questionnaire for the base certification, or the full technical audit for Plus. The five core control areas, firewalls, secure configuration, access control, malware protection, and patch management, stay the same every year. What changes is the detail underneath them: the exact wording, the scope, and how strictly each answer is marked.
What Actually Changed in 2026
The update that took effect on 27 April 2026 is a genuinely substantial one, not a wording tidy-up. A few of the changes worth knowing about specifically:
- MFA is no longer a “should”, it’s a hard requirement. If multi-factor authentication is available for a cloud service you use and it isn’t switched on, that’s now an automatic assessment failure, not a point that gets marked down.
- Cloud services can no longer be excluded from scope. Previously, some organisations left certain SaaS platforms out of the assessment. Under the current requirements, any cloud service that stores or processes your organisation’s data is in scope, full stop.
- Personal devices get more scrutiny. If staff use their own phones or laptops to access company email, files, or cloud services, that now needs proper consideration, appropriate controls, not just a policy document nobody’s read.
- Shared and generic accounts are actively discouraged. The expectation is that each user has their own identity and access rights, rather than a team sharing one login.
Which Version Applies to You
Here’s the detail that trips people up: which set of requirements you’re assessed against depends on when your assessment account was created, not when you last certified or when you happen to be renewing. If your account was set up before 27 April 2026, you get assessed against the previous requirements for a transition period. If it was created on or after that date, the current requirements apply straight away. Two businesses renewing in the same month can genuinely be held to different standards, depending on that one date.
Why This Matters Beyond the Certificate Itself
Cyber Essentials has moved well past being a nice-to-have badge on your website. It’s increasingly a genuine commercial requirement, referenced in public sector procurement rules, and more larger organisations are starting to require it from their own suppliers before they’ll do business with them. If you supply into that kind of client base, losing certification at renewal isn’t just a compliance gap, it can mean being excluded from tender processes before a conversation even starts.
What to Do Before Your Renewal Date
The organisations that sail through renewal are the ones who check their position a month or two ahead, not the ones who leave it until the certificate’s about to lapse. Worth doing now rather than at renewal time: confirm MFA is genuinely enforced everywhere it’s available, not just switched on for admin accounts, make sure every cloud service your business actually uses is accounted for, and tidy up any shared logins into individual accounts. None of this is complicated, but it’s much easier to fix with a few weeks’ notice than the week before an assessment.
If you’re renewing for the first time and want to know what commonly catches people out even on a straightforward first attempt, our guide to what actually trips businesses up during Cyber Essentials certification covers that in more depth.
Where CCSW Comes In
We’re Cyber Essentials certified ourselves, and we support clients through both first-time certification and annual renewal, including checking your setup against whichever version of the requirements actually applies to you. Read more about our cyber security services, or get in touch if your renewal date is coming up and you’d like a second pair of eyes on it before you submit.
