An update to the Cyber Essentials technical requirements (v3.2) and a new Willow question set apply to assessments started from today.
Highlights
- Clarified expectations for multi-factor authentication on cloud services, including passwordless authentication options.
- Updated definitions and scoping guidance, including for home workers and cloud services.
- Refinements to vulnerability fixing and security update requirements.
As always, organisations approaching renewal should review their scope, especially cloud services, and confirm MFA is enabled everywhere it is available.
Source: Cyber Essentials: Requirements for IT Infrastructure v3.2 (NCSC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.