Preparing for Cyber Essentials renewal? Learn how April 2026 changes affect you.

JDI-UK
Home
IT Support Services
Digitalisation Services
Data Protection Services
Cyber Security Services
News
Contact
JDI-UK
Home
IT Support Services
Digitalisation Services
Data Protection Services
Cyber Security Services
News
Contact
More
  • Home
  • IT Support Services
  • Digitalisation Services
  • Data Protection Services
  • Cyber Security Services
  • News
  • Contact

  • Home
  • IT Support Services
  • Digitalisation Services
  • Data Protection Services
  • Cyber Security Services
  • News
  • Contact

Cyber Essentials Certification

 

Changes to Cyber Essentials certification happened
on April 27th 2026

00

DaysDays

00

HrsHours

00

MinsMinutes

00

SecsSeconds

April 2026 Cyber Essentials Updates

 

Cyber Essentials requirements changed in April 2026, making the renewal process more rigorous than previous years. Organisations must now provide additional evidence to demonstrate compliance, including multi-factor authentication (MFA), timely security updates, accurate device and cloud asset inventories, and clearly defined certification scope.


Whether you're renewing your certification or applying for the first time, JDI will guide you through the latest requirements and help you achieve certification with confidence.

What's Changed

Cloud services must now be fully included in scope

 

IASME has confirmed that from April 2026, all cloud services used to store, process, or access organisational data will be fully in scope for Cyber Essentials. For solicitors, this means platforms such as Microsoft 365, case‑management systems, document portals, and other hosted services will be assessed to the same standard as your local devices and network.

This update places greater emphasis on understanding how your cloud services are configured, secured, and accessed. Even when a provider manages the underlying infrastructure, your firm remains responsible for ensuring secure use of the service — including access controls, MFA, and appropriate governance. With renewals approaching, now is the ideal time to review your cloud estate and confirm that each service meets the updated requirements.

Multi‑Factor Authentication becomes mandatory

From April 2026, Cyber Essentials will require Multi‑Factor Authentication (MFA) for all users and administrators of cloud services, wherever MFA is supported. For solicitors, this applies to platforms such as Microsoft 365, case‑management systems, document portals, and any other cloud‑based tools handling client or operational data. Password‑only access will no longer meet the standard.

The update places greater emphasis on consistent enforcement. Firms must ensure MFA is enabled for every account, including partners, fee‑earners, support staff, and external users. With renewals approaching, now is the ideal time to review your cloud platforms and confirm MFA is fully in place ahead of the April 2026 assessment changes.

High and critical vulnerabilities (CVSS 7+)

 

Under the April 2026 Cyber Essentials requirements, organisations must patch:

  • All vulnerabilities rated CVSS 7.0 or higher
  • Within 14 days of a fix being released

This threshold covers High and Critical severity vulnerabilities according to the Common Vulnerability Scoring System (CVSS). These are the types of weaknesses most likely to be exploited in real‑world attacks, which is why Cyber Essentials now enforces a strict remediation window.

The requirement applies to:

  • Operating systems
  • Applications
  • Cloud services (where patching is within your control)
  • Network devices, including firewalls and routers

This aligns with the broader shift in the scheme toward more mature, measurable vulnerability management.

Firewall and router firmware updates

From April 2026, Cyber Essentials will require firewall and router firmware to be updated within 14 days whenever a high‑ or critical‑severity vulnerability is identified. This brings network devices firmly into the same patching expectations as operating systems and applications.

For organisations, this means moving from occasional firmware updates to a more structured process that ensures your boundary defences are always current and supported. With renewals approaching, now is a good time to review your firewall estate and confirm that update procedures are in place ahead of the April 2026 changes.

Windows 10 devices

 

From April 2026, Cyber Essentials will only accept Windows 10 devices that are covered by Microsoft’s Extended Security Updates (ESU). Once mainstream support ended in October 2025, any Windows 10 machine without ESU have been treated as an unsupported operating system and will fall out of scope for certification.

For organisations, this means reviewing all remaining Windows 10 laptops and desktops and deciding whether to upgrade, replace, or enrol them into ESU. With renewals approaching, now is the time to plan your transition to ensure your device estate remains compliant under the updated standard.

BYOD devices

From April 2026, Cyber Essentials will require all personal (BYOD) devices used to access organisational data to meet the same security standards as firm‑owned equipment. This includes personal mobiles, tablets, and laptops used for email, case‑management access, or document handling.

For organisations, this means informal or unmonitored use of personal devices will no longer be acceptable. Firms will need clear policies and assurance that every device accessing client or operational data is secure and supported. With renewals approaching, now is the time to review your BYOD arrangements and ensure they align with the updated requirements.

Stricter governance

 From April 2026, Cyber Essentials will introduce tighter governance around administrator accounts and firewall rule changes. Firms will need clear, documented processes showing how admin access is granted, reviewed, and removed, along with formal approval steps for any changes to firewall configurations.

For organisations, this means informal or ad‑hoc IT practices will no longer meet the standard. Stronger oversight, proper documentation, and regular reviews will be essential to demonstrate compliance. With renewals approaching, now is a good time to ensure your governance processes are up to date and fully aligned with the new requirements.

Is Your Cyber Essentials Certification Due for Renewal?

 

Following the April 2026 updates, renewing Cyber Essentials is no longer a simple "copy and paste" from last year's submission. The requirements have changed, making expert guidance more valuable than ever.


JDI's Fixed-Price Cyber Essentials Renewal Service helps you achieve certification quickly, confidently and with no hidden surprises.

request fixed-price quote

Contact Us

Lets start a conversation!

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

We would love to start a conversation to see how we can help with your IT, Cyber Essentials & GDPR compliance.

JDI-UK

T: 01138 715023 M: 07486 860990 E: cyber.essentials@jdi-uk.com

Business Hours

Mon

09:00 – 17:00

Tue

09:00 – 17:00

Wed

09:00 – 17:00

Thu

09:00 – 17:00

Fri

09:00 – 17:00

Sat

By Appointment

Sun

Closed

Copyright © 2025 JDI-UK - All Rights Reserved.

Powered by GoDaddy

  • Home
  • IT Support Services
  • Digitalisation Services
  • Data Protection Services
  • Cyber Security Services
  • News
  • Privacy Policy

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept