Cyber Essentials update could put your public sector contracts at risk
Cyber Essentials v3.3, effective from 27 April 2026, introduces a new automatic fail rule for organizations that do not enable Multi-Factor Authentication (MFA) on all cloud services that support it. This change eliminates previous flexibility, making non-compliance an immediate barrier to certification. As Cyber Essentials is mandatory for many public sector contracts, failure to comply could jeopardize government procurement opportunities.
- ▪From 27 April 2026, organizations without MFA enabled on all applicable cloud services will automatically fail Cyber Essentials certification.
- ▪Cyber Essentials is a UK government-backed cybersecurity certification scheme required for suppliers handling sensitive data in central government.
- ▪The new rule applies even if MFA is only available through a paid upgrade, removing previous allowances for non-conformity.
- ▪Around 50,000 organizations obtain Cyber Essentials certification annually, and it is often a baseline for cyber insurance and private sector procurement.
- ▪The update represents the most significant change to the scheme since its inception, with immediate enforcement and no remediation path within the certification cycle.
Opening excerpt (first ~120 words) tap to expand
Pro Cyber Essentials update could put your public sector contracts at risk Opinion By Jonathan Krause published 1 May 2026 Cyber Essentials v3.3 creates a new automatic fail rule When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. (Image credit: Shutterstock) Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter From 27 April 2026, any organization that holds Cyber Essentials certification and has not switched on login verification across every cloud service it uses is looking at an automatic assessment failure.Not a non-conformity to address gradually. Not a remediation point.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Latest from TechRadar .