Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal

13 February 2026

3 minutes read time

What you need to know about the Cyber Essentials April 2026 update

I’ve been Chief Operating Officer at CloudTech24 for over eight years and have played a key role in its growth from a team of three people in 2018 to a business of 45 and growing today. During that time, we’ve achieved more than 25 times revenue growth while building a reputation for delivering high-quality managed IT and cyber security services.

My career began in sales and IT support before progressing into website hosting, technical pre-sales and leadership. That experience has given me a broad understanding of both the commercial and technical aspects of running a successful technology business.

As Chief Operating Officer for CloudTech24, I lead our operations, technical services and customer experience. I’ve helped shape our technology strategy, securing Microsoft Tier 1 Direct Partner status, Microsoft Modern Work Solutions Partner and Security designations, while maintaining our Google Workspace partnership and introducing new technologies that continue to strengthen our services.

I’m passionate about building high-performing teams, improving the way we work and using automation and AI to help businesses become more efficient, secure and resilient.

In my spare time, I enjoy playing 7-a-side football, keeping up with the latest tech and gadgets, and spending time with my two Maine Coon cats. I’m also a long-time Call of Duty fan, especially from the OG Verdansk and Rebirth Island days.

Read blogs in other categories

The National Cyber Security Centre (NCSC) and IASME have announced the newest update for the UK’s top cybersecurity certification – Cyber Essentials.

The Cyber Essentials April 2026 update introduces several big changes designed to keep pace with the shifting threat landscape.

Having a Cyber Essentials certification demonstrates that your business is among the top IT providers and aligns with cybersecurity best practices.

With these new updates, to not only become accredited by Cyber Essentials ,but also remain an accredited and certified Cyber Essentials business, you’ll need to adhere to the changes they’re set to make in April. 

In this blog, we’ll break down what these changes are and what you can do as a business to think ahead. 

Mandatory MFA rule

This rule has been in place for Google Cloud Services since the end of 2025, but now the criteria are becoming even stricter. 

Read more: Mandatory MFA for Google Cloud users by the end of 2025

MFA (Multi-factor authentication) is now non-negotiable for all cloud services. 

By April 27th 2026, if a cloud service supports MFA, whether that service is free or subscription-based, you must implement it. If you haven’t, then it will result in an automatic failure from Cyber Essentials. 

Embracing passwordless authentication 

Over the past few years, there’s been a clear aim to move away from traditional password-based login, and it’s only gotten clearer following Cyber Essentials’ new updates, which place heavy emphasis on passwordless authentication.

The NCSC is now explicitly recommending the use of Passkeys and FIDO2 (Fast Identity Online2), such as Touch ID and Face ID authenticators. 

These methods use public-key cryptography (such as biometrics or hardware tokens) to verify identity, making them significantly more resistant to phishing than traditional passwords.

By suggesting passwordless authentication as the standard, the scheme is telling businesses to adopt a more secure approach.

Read more: A quick guide to passwordless login

This means that things like hardware security keys or biometric devices are now an official way to meet Cyber Essentials requirements.

Cloud services are the new norm

The update tightens the requirements for cloud security by introducing a strict definition of cloud services.

To comply, companies, in a sense, need to perform a full “cloud audit”, similar to what they would do with inventory. This includes any cloud tools that you buy later down the line. 

The most important thing to remember is that it’s an automatic fail if you’re found to have any cloud app holding company data that you haven’t informed Cyber Essentials about.

This includes SaaS (software as a service), apps, and storage/management platforms, as they cannot be excluded from the assessment scope if they handle any sort of organisational data. 

How to prepare for the April 2026 update

All of these updates officially begin on April 27th 2026, so from that point onward, all assessments from Cyber Essentials will be judged against these new updates. 

So what can you do to ensure your business is ready?

  1. Update MFA on every cloud service that you use, whether free or subscription-based.
  2. Ensure every cloud service is fully stated and documented to comply with Cyber Essentials’ new changes.
  3. Utilise new passwordless login techniques like biometrics and hardware tokens.

A final thought

This update from Cyber Essentials is adapting to the current, rapid changes that businesses are seeing 

By making MFA a must, going modern with logins, and closing the gaps in cloud scoping, the NCSC and IASME are ensuring that Cyber Essentials remains a strong way to ensure you’re up to standard with cybersecurity, rather than just a “badge” on a website.

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more