From 27 April 2026, Cyber Essentials (CE) and Cyber Essentials Plus (CE+) will undergo a significant shift in how assessments are enforced. While the five technical controls remain the same, IASME is tightening the interpretation and evidence requirements to make the scheme more robust, consistent and reflective of modern cyber risks.
As an MSP who is also an IASME accredited Certifying Body (CB), Air IT Group welcomes these changes. They’re designed to strengthen cyber resilience across the UK and give organisations greater confidence that their security controls work – not just at audit time.
In this article, we break down what’s changing, what it means for SMEs, and how you can stay ahead of your next assessment.
The threat landscape has evolved. Cloud usage has grown. Attackers move faster. And many organisations rely on Cyber Essentials as a foundation for insurance, supply chain assurance and government tenders.
The 2026 changes strengthen the scheme by removing ambiguity and increasing consistency across assessments. This means:
For SMEs, it’s an opportunity to boost cyber maturity rather than fear failure.
“Cyber Essentials has always provided a strong foundation, but the 2026 updates bring it in line with how businesses operate today, especially in the cloud. For SMEs, these changes shouldn’t be intimidating. In most cases, it’s about formalising and strengthening controls that should already be in place. With the right preparation and guidance, compliance is absolutely achievable.”
Guy Liu, Head of Cyber Security, Air IT Group
Organisations that were previously “just compliant” may no longer meet the threshold if controls aren’t applied consistently across users, devices and cloud services. This isn’t punitive – it’s simply raising the baseline of what good looks like.
If a system supports multi-factor authentication, IASME now expects it to be enabled, even if it requires an additional licence. Partial MFA (e.g. only applied to admins) is no longer sufficient. This aligns with broader industry best practice and dramatically reduces account compromise risk.
Any cloud platform your team uses for work now falls under assessment, including:
If staff can sign into it, it’s in scope. This reflects the modern reality that the cloud holds your most valuable data.
Basic assessments can no longer rely on simple yes/no answers. Organisations must now:
For many SMEs, this will be the area needing the most uplift.
CE+ assessors will now test whether controls operate correctly day-to-day, not just in theory. This means real-world validation, stronger assurance and fewer gaps between policy and practice. In addition, there is a deliberate “hardening” of this area, with assessors seeking evidence of compliance that goes beyond simply reviewing a small sample size.
The aim is to ensure that robust security measures are consistently in place across the organisation, rather than relying on isolated examples or best-case scenarios.
For smaller organisations, these changes shouldn’t be viewed as obstacles. In fact, they provide:
The key is preparation – not panic.
Don’t wait until renewal. Many organisations will need time to enable MFA, update legacy systems or streamline patching. Starting with the right advice is also important. Without a gap analysis/advice from a knowledgeable expert, customer won’t be able to use the extra time to make the “right” preparations either.
Prioritise reviewing:
A proactive review now prevents surprises later.
Automation, centralisation and monitoring are your friends. SMEs who rely on manual processes are most vulnerable to noncompliance, and cyber incidents.
As an IASME-certified Cyber Essentials assessor and trusted MSP, Air IT Group is uniquely placed to guide organisations through these changes.
We help SMEs by:
Whether you renew annually or are working towards CE+ for the first time, our accredited team ensures you’re prepared.
The April 2026 changes enhance Cyber Essentials, making it more consistent, more effective and more aligned with how businesses operate today. With the right preparation, and the right partner, these changes become an opportunity to strengthen your security posture, not a barrier.
If you’d like a readiness check or tailored guidance ahead of the April update, our IASME-certified team is here to help.
Get a free consultation
Cyber Security
Insights
‘Does ISO 27001 Require Pen Testing?’ and Other Questions
16/10/2024
Cyber Security
Data & AI
Insights
Four Tech Trends UK SMEs Can’t Ignore in 2026
29/12/2025
Cyber Security
Insights
How Businesses Can Reduce Their Cyber Insurance Premiums
01/06/2024