Don’t do SECURITY. Do business SECURELY.

Major update to Cyber Essentials requirements

The biggest update to Cyber Essentials since its launch brings cloud services, home working and multi-factor authentication into focus.

A significant update to the Cyber Essentials technical requirements takes effect today, the biggest change since the scheme launched in 2014.

Key changes

  • Cloud services are now explicitly in scope, with responsibilities shared between customer and provider.
  • Home and remote workers’ devices used for work are in scope.
  • Multi-factor authentication is required for cloud services.
  • Stronger password requirements and clarified rules on user and administrator accounts.
  • Unsupported software must be removed from scope or segregated; security updates must be applied within 14 days.
  • Thin clients, servers and network devices are addressed more clearly.

Organisations renewing their certification should review their scope carefully, particularly cloud and home working arrangements, well before their renewal date.

Source: January 2022 changes to Cyber Essentials (IASME, Cyber Essentials delivery partner)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights