All news
Rules & compliance
28 April 2025

Cyber Essentials changes: what the latest requirements ask of you

The scheme's technical requirements were updated again, tightening the rules on passwordless authentication, home working and unsupported software.

What this means for your business

If you certify annually — or want to bid for work that requires it — the questions have moved. Most failures are still the same three things.

Cyber Essentials is the UK government-backed baseline, run by IASME. The technical requirements are refreshed periodically; the recent updates clarified passwordless authentication, brought home-working setups further into scope, and tightened language on unsupported software and asset management.

What usually causes a fail

In our experience the same three things:

  1. Unsupported operating systems or software still in use — an old Windows machine, an out-of-date server, a phone that stopped getting updates two years ago.
  2. MFA not applied to every cloud service, particularly the ones bought by a department rather than IT.
  3. No reliable asset list, so nobody can say with confidence what's on the network.

Why bother

  • It's a common requirement in public-sector and enterprise supply chains.
  • Basic certification includes cyber liability insurance for smaller UK organisations, subject to the scheme's conditions.
  • It forces the boring, effective work: patching, MFA, admin separation, firewall configuration.

We take customers through certification start to finish, and the honest first step is usually an audit that tells you what would fail today.

Need help staying compliant?

Practical GDPR and data protection support for small and medium businesses.

GDPR support

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.