Cyber Essentials v3.3: what actually changed
· 3 min read
Cyber Essentials v3.3 took effect in April 2026. The five technical controls have not changed. What changed is scope and definitions: cloud services are now formally defined and cannot be excluded from your assessment, passkeys are recognised as multi-factor authentication, and software firms are pointed at the government’s Software Security Code of Practice. Here is each change in plain English, and what to do about it.
First, a recap
Cyber Essentials is the UK’s government-backed security baseline, run by the NCSC and delivered through IASME. Version 3.3 of the Requirements for IT Infrastructure applies to assessments from April 2026, paired with a question set named Danzell. Certificates you already hold stay valid; you’ll meet v3.3 at your next assessment, which for most businesses means renewal within the next twelve months.
Cloud services: defined, and impossible to exclude
Earlier versions left room to argue about which cloud services counted. v3.3 closes the argument twice over. It defines a cloud service properly: on-demand, scalable, hosted on shared infrastructure, reachable over the internet, accessed with an account, and storing or processing your organisation’s data. And it states definitively that cloud services cannot be excluded from scope.
Microsoft 365 and Google Workspace were never realistically out. The long tail is the point. The CRM. The accounting platform. The file-sharing tool someone signed up for two years ago with a company email address. If it holds organisational data, it is in your assessment, and you cannot certify a service you haven’t listed.
The practical work here is inventory. Most businesses guess low on how many cloud services they use, sometimes badly. Start the list now, not the week before the assessment.
Passkeys count as MFA
v3.3 updates the passwordless authentication definition to include FIDO2, and FIDO2 authenticators (passkeys, hardware security keys) are regarded as multi-factor authentication in their own right. If you were waiting for the scheme to catch up before moving accounts, especially admin accounts, to passkeys, you can stop waiting. The requirement that authentication to cloud services must always use MFA is unchanged; passkeys are now an unambiguous way to meet it.
A push on secure software development
The software development section now introduces the Software Security Code of Practice, the government’s voluntary code for how software should be built and maintained. If you sell software, treat this as the direction of travel: expect customers and assessors to lean on it more over time.
‘Untrusted connections’ is gone from scoping
Older scope wording leaned on the idea of untrusted connections, which generated more debate than clarity. The v3.3 scope criteria drop the phrase. The boundary conversation is now simpler: your devices, your networks, your cloud services.
Backups: louder, still not mandatory
v3.3 puts more emphasis on backing up your data while stopping short of making it a technical requirement. The document is candid about this: backing up is “not a technical requirement of Cyber Essentials”, but it is highly recommended, and automatic backups should be considered wherever they’re available. Our advice is to treat it as mandatory anyway. Certification is a floor, not a target, and the day you need a backup is a bad day to start taking them.
What hasn’t changed
- The five technical controls: firewalls, secure configuration, security update management, user access control, malware protection.
- The 14-day rule. Vulnerability fixes rated critical or high risk by the vendor must be applied within 14 days of release.
- Software must be licensed and supported, and the vendor must publish when support will end. Unsupported software must be removed, or cut off from the internet in a defined sub-set.
- MFA on cloud services, for everyone, every time.
Before your next assessment
- List every cloud service that stores or processes organisational data. Include the ones nobody remembers signing up for.
- Check MFA coverage across that list. Admin accounts first.
- Confirm critical and high-risk fixes actually land within 14 days, with automatic updates on wherever possible.
- Find anything past or approaching its end-of-support date and plan its exit.
- Sort your backups, even though nobody will mark you down for skipping them.
If you’d rather this were checked continuously instead of in a pre-renewal scramble, that is what we do. Foundry Cyber runs its benchmark against your environment continuously, and on Silver and above renders your findings against Cyber Essentials v3.3, so renewal becomes a formality rather than a project. See the tiers, or talk to us.