OpusBUSINESS EXPERT

Cyber Essentials got stricter in April, and last year's pass is not this year's

Andy Shepherd6 min read
  • IT consultancy
  • Cyber security
  • Knutsford

Cyber Essentials used to be forgiving. You answered the question set, a few answers were weaker than others, and a decent overall showing carried you. That is no longer how it is marked.

Since the April update there are questions that fail the entire assessment on their own, regardless of how well you did everywhere else. Three of them, and each one catches a habit that was survivable last year.

The scheme's new requirements document is version 3.3, and the question set that goes with it is called Danzell. It replaced Willow for assessment accounts created after late April. If you started an assessment before the cutoff you had six months to finish on the old set, and that window is closing now, so in practice everyone certifying from here is on the new one.

What actually changed

Nothing about the five controls. The controls have not moved for years and they are not the point. What moved is the marking, and it moved in one direction.

Multi-factor authentication on cloud services is now an auto-fail. Where a cloud service offers MFA, you have to have it on. IASME's wording closes the obvious exit: it applies whether MFA is free, included in your plan, or something you would have to pay extra for. Cost is not a defence.

Security updates on a 14-day clock are now two auto-fails. Question A6.4 covers high-risk and critical updates for operating systems and for router and firewall firmware. A6.5 covers applications, and it says "including any associated files and extensions", which is browser plugins and add-ins written out so nobody can pretend otherwise. Miss either and the assessment fails, whatever else you scored.

Cloud services cannot be excluded from scope. The requirements document now defines a cloud service for the first time, and follows it with a flat statement that if your data or services are hosted on one, it is in scope. There is no version of the sentence that lets you leave something out.

The three firms this will catch

Every small business we have looked at has at least one of these, and none of them feel like negligence from the inside.

There is the director exempted from MFA. It went on for everyone else, and then one person found it awkward on their phone, or travels, or simply asked, and an exception was made quietly and never revisited. That exception is now the whole assessment.

There is the account nobody counted. The file-sharing tool one department signed up for. The design subscription paid on a personal card and expensed. The old webmail address the business still publishes. Under the new definition, a service accessed with a business email address that stores or processes your data is a cloud service, and it is in scope whether or not anyone told IT about it.

And there is the machine on the workshop floor running something that cannot be patched inside a fortnight, which used to sit in a grey area and no longer does.

The honest part about turning MFA on

The reason MFA is not already on for everyone is almost never that the owner disagrees with it. It is that the fortnight after you switch it on is genuinely disruptive, and everyone knows someone it went badly for.

Here is what actually happens, and it is worth knowing before you commit to a date. The first day is fine. The second day is the shared mailbox nobody can get into, the till or booking screen that logs in as a generic account, and the mail app on somebody's older phone that does not support modern authentication and just fails silently. Then there is the person who does not have their phone at work, and the one who will not install a work app on a personal handset, both of whom need a hardware key rather than an argument.

None of that is a reason not to do it. It is a reason to do it deliberately, with the awkward accounts identified first, rather than on the Friday before an assessment.

  1. 01List every service anyone signs into with a work email address, including the ones bought on a personal card
  2. 02Check each one for MFA, and note which accounts are shared or generic rather than personal
  3. 03Fix the shared accounts first: they are the ones that break, and usually the answer is a proper licensed account or a hardware key
  4. 04Turn MFA on for everyone, in a normal week, with someone available to answer questions
  5. 05Then check your update clock: high-risk and critical patches inside 14 days, on servers, laptops, phones, browsers and the firewall

The last step is the one people skip, and it is now two of the three auto-fails. Windows updating itself is not the answer to it. The firewall firmware, the browser extensions and the line-of-business application are all in the question, and they are usually the ones nobody has a process for.

Whether it is worth certifying at all

Sometimes it is not, and we will say so. If nobody is asking you for it, no customer procurement form mentions it, and you are not bidding for public sector work, then Cyber Essentials is a certificate you are buying for yourself. The controls behind it are worth having regardless. The badge is worth having when somebody wants to see it.

But that calculation has changed slightly, because the certificate now says more than it used to.

A pass under the new marking means MFA is genuinely on everywhere it can be, and patches genuinely land inside a fortnight. Last year's certificate did not promise either.

There is also a new line in the declaration a director signs: an explicit acknowledgement that the organisation is responsible for keeping the controls in place for the whole certification period, not just on assessment day. The scheme has also made "point in time" mean the date the certificate is issued, so the software has to be supported then, not when you started filling the form in.

If you hold a certificate and it expires this year, the useful thing to do now is not to book the assessment. It is to walk the estate against those three auto-fails while there is time to fix what you find. Failing costs money and a re-run. Finding out in August that one licence needs upgrading costs a licence.

We run Microsoft 365 estates for clients, including migrations off on-premise Exchange, so the MFA rollout above is a job we have done rather than a list we have read. If you want someone to walk it with you before you commit to a date, that conversation costs nothing.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy