Why Cyber Essentials Is Getting Harder to Pass in 2026

200+ Articles published
5 IT topics covered
20+ Years of IT expertise
CE+ Cyber Essentials Plus
Share
In This Article
    Speedster IT
    Worried About Cyber Threats?

    Get a free cyber security review and find out where your business is exposed.

    Explore Cyber Security

    Cyber Essentials is getting harder to pass. It isn’t your imagination, and it isn’t just your business either.

    The scheme’s April 2026 rule changes tightened several requirements at once, and assessors have removed some of the flexibility that used to let borderline cases through. If you’re preparing for certification or renewal, it’s worth understanding exactly what’s changed before you apply, not after a failed assessment.

    Speedster IT provides Cyber Essentials certification support for London businesses, alongside MFA rollouts and wider IT security reviews. This guide covers why more organisations are failing, the most common mistakes, and what you need in place to pass first time.

    What Has Changed in Cyber Essentials?

    Why the Certification Requirements Have Tightened

    Cyber Essentials moved to a new question set in April 2026. The update, widely referred to as the Danzell update, closed several gaps that businesses had previously used to scope certain devices or services out of their assessment.

    Our Cyber Essentials Changes article covers the full rule set in detail. In short, the scheme is stricter because attackers were exploiting exactly the gaps it used to tolerate.

    The Impact of Cloud Adoption on Compliance

    Most businesses now run far more of their operations through cloud services than they did when Cyber Essentials was first designed. The scheme has caught up with that shift.

    Cloud services are now explicitly in scope if they’re accessed with a business email or account. That includes services a business might not think of as “IT infrastructure” at all, not just Microsoft 365 or an obvious line-of-business system, which is worth reading up on if you’re still weighing up what belongs on-premises versus in the cloud.

    New Security Expectations for Modern Businesses

    Two changes matter most in practice. Multi-factor authentication is now a hard requirement everywhere it’s available, and high or critical security updates must be applied within 14 days of release, with no exceptions built in.

    Both of these are now automatic-fail conditions. Miss either one on a single in-scope device or service, and the whole assessment fails, regardless of how strong everything else is.

    Why More Businesses Are Failing Cyber Essentials Assessments

    Poor Visibility of Cloud Applications

    Many businesses don’t have a complete picture of every cloud service staff actually use. A marketing team using a file-sharing tool outside Microsoft 365, or a project team on a tool IT never signed off, both count as shadow IT under the current rules.

    If that service holds business data, it’s in scope. If it’s in scope and doesn’t meet the MFA and patching requirements, it can fail the whole assessment on its own.

    Incomplete Asset Inventories

    Incorrect scoping is one of the most common reasons organisations fail. The 2026 update removed several of the exemptions that previously let certain devices sit outside the assessment.

    If your asset inventory is out of date, or was built for an earlier version of the scheme, it’s likely missing devices and services that now need to be included.

    Weak Multi-Factor Authentication Controls

    A typical failure looks like this: MFA is properly enabled on Microsoft 365 email, but a VPN, a remote desktop gateway, or a separate cloud management portal still only asks for a password. One gap is enough to fail.

    Unpatched Software and Operating Systems

    Patch management is now the leading cause of Cyber Essentials Plus failures. The 14-day window for high and critical updates applies to operating systems, applications, and firmware, and assessors can see exactly which patches are missing during testing.

    Any software that’s stopped receiving security updates from its vendor altogether can’t be brought into compliance at all. It has to be replaced or upgraded before certification is possible.

    Remote Working Security Gaps

    Devices used for remote or hybrid working are just as in scope as anything in the office. A laptop that connects to company systems from home still needs the same patching, MFA, and secure configuration as a desktop on-site, something worth reviewing properly if hybrid working is a permanent fixture for your business rather than a temporary arrangement.

    The Most Common Cyber Essentials Mistakes

    Missing Devices from the Assessment Scope

    Personal phones used to check work email, an old laptop kept “just in case,” or a device a contractor uses to access company systems are all easy to leave off an asset list. Any of them can be in scope.

    Unsecured Microsoft 365 Environments

    Microsoft 365 is the single most common source of Cyber Essentials problems we see, simply because it’s where most UK businesses now store their data and manage user accounts.

    Weak Password Policies

    Password requirements that haven’t been reviewed in years, shared logins, or accounts with no password expiry policy at all are still common findings, even with MFA in place.

    Lack of User Access Controls

    Staff accounts with more access than their role actually needs are a recurring issue. This includes former employees whose accounts were never fully removed.

    Unsupported Software and Legacy Systems

    An old server, an unsupported version of an operating system, or software the vendor no longer patches will block certification outright. There’s no compensating control that gets around this one.

    How Microsoft 365 Can Cause Compliance Problems

    MFA Misconfigurations

    Enabling MFA at the tenant level doesn’t guarantee every account is actually covered. Exclusions, legacy authentication protocols, and accounts set up before MFA was enforced can all leave gaps that assessors will find.

    Excessive Administrator Privileges

    Admin accounts need to be kept separate from everyday user accounts, and used only for administrative tasks. A staff member who does their day-to-day work while logged in as an admin is a common finding, and a risky one.

    Third-Party Application Risks

    Apps connected to Microsoft 365 through third-party integrations can access company data without going through the same security checks as the core platform. These connections are easy to lose track of over time.

    Shadow IT and Unmanaged Devices

    Once a team starts using a tool IT doesn’t know about, nobody is checking it against Cyber Essentials requirements at all. It sits there as a genuine compliance gap until someone finds it, usually during an assessment.

    What Businesses Need Before Applying for Cyber Essentials

    Complete Asset Inventory

    Every device, server, and cloud service that touches company data needs to be listed, including anything used for remote working. This is the foundation everything else in the assessment is built on. Our remote work cybersecurity checklist is a useful starting point if you haven’t audited this properly before.

    Work With Speedster IT

    Want IT support that actually works?

    Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.

    Talk to Our Team

    Patch Management Process

    You need a working process for applying high and critical security updates within 14 days, not just a general habit of updating things eventually. Assessors will check for evidence of this, not just ask about it.

    Secure Device Configuration

    Devices need to be configured to a recognised secure baseline before assessment, not brought up to standard reactively once a gap is found.

    Access Control Policies

    Clear rules on who gets access to what, how admin accounts are handled, and how access is removed when someone leaves, all need to be in place and followed consistently.

    Security Awareness Training

    Staff need to understand basic security practices, since many of the weaknesses assessors find come down to how people actually use systems day to day. Our cyber security training covers exactly this.

    Cyber Essentials vs Cyber Essentials Plus

    Key Differences Explained

    Cyber Essentials is a self-assessed questionnaire, verified by an external assessor. Cyber Essentials Plus adds a technical audit, where an assessor actually tests your systems rather than relying on your answers alone.

    Which Certification Is Right for Your Business?

    Cyber Essentials is a solid starting point for most SMEs and demonstrates baseline good practice. Cyber Essentials Plus gives a stronger level of assurance, since your answers are independently verified rather than taken on trust.

    When Clients Require Cyber Essentials Plus

    Some clients, particularly in the public sector or regulated industries, specifically require Cyber Essentials Plus in their contracts. It’s worth checking what your own clients and prospective clients actually ask for before deciding which level to pursue.

    How to Pass Cyber Essentials First Time

    Carry Out a Readiness Assessment

    A readiness assessment checks your current setup against the actual Cyber Essentials requirements before you submit anything formally. This is where most gaps get caught, while they’re still cheap and quick to fix.

    Identify Gaps Before Submission

    Once you know where the gaps are, you can prioritise them properly. An automatic-fail issue like missing MFA on one system needs fixing before anything else.

    Fix Common Security Weaknesses

    Work through the gaps methodically: patch what’s overdue, enable MFA everywhere it’s available, tidy up admin accounts, and remove anything unsupported from scope.

    Document Security Controls Properly

    Assessors need evidence, not just assurances. Written policies, patch records, and a clear asset inventory all make the assessment itself far more straightforward.

    Test Your Security Posture

    A final check before submission, ideally by someone who wasn’t involved in fixing the original gaps, catches anything that slipped through.

    Cyber Essentials Checklist for London SMEs

    Review All Devices

    List every device that connects to company systems or data, including personal devices used for work and anything used remotely.

    Verify Multi-Factor Authentication

    Check MFA is enabled on every in-scope system, not just the obvious ones. VPNs, remote access tools, and admin portals all need it too.

    Check Software Updates

    Confirm every operating system and application in scope has had high and critical updates applied within the last 14 days, and has a process to keep doing so.

    Audit User Accounts

    Remove accounts for anyone who’s left, review who has admin access, and confirm access matches what each role actually needs.

    Secure Cloud Services

    Identify every cloud service in use across the business, including anything staff have signed up to independently, and check it against the same MFA and access requirements as everything else.

    Remove Unsupported Systems

    Anything no longer receiving vendor security updates needs to be replaced or upgraded before you apply. There’s no way around this one.

    How Speedster IT Helps Businesses Achieve Cyber Essentials Certification

    Cyber Essentials Gap Analysis

    We assess your current setup against the current Cyber Essentials requirements and give you a clear list of what needs fixing before you apply. Our Cyber Essentials certification guide covers the process itself in more detail, if you’re starting from scratch.

    Microsoft 365 Security Reviews

    Since Microsoft 365 is where most of these issues turn up, we review your tenant configuration, admin privileges, and MFA coverage specifically, rather than treating it as a footnote to the wider assessment.

    Remediation and Compliance Support

    Once gaps are identified, we help fix them, from patching and MFA rollout to tidying up access controls and asset records.

    Cyber Essentials Plus Preparation

    If your business needs Cyber Essentials Plus, we help prepare for the technical audit specifically, not just the underlying self-assessment questions.

    Ongoing Managed Cyber Security Services

    Certification isn’t a one-off task. Our managed cyber security services keep your business in a position to pass renewal each year, rather than scrambling to catch up every time the scheme changes.

    If Cyber Essentials feels harder to pass than it used to, that’s because it genuinely is. Get in touch with our team for a straightforward conversation about where your business stands today.

    Ready to Talk?

    Let’s fix this properly.

    Book a free consultation with one of our engineers and find out what better IT support actually looks like.

    Get In Touch