Cyber Essentials now has three automatic fails. Here is what they are.

Cyber security · Cyber Essentials

Cyber Essentials now has three automatic fails. Here is what they are.

Since 26 April 2026, getting any one of three questions wrong fails your Cyber Essentials assessment outright, however well you answer the rest. Most small firms will find out at renewal.

September 2026 · For UK accountancy, legal and healthcare practices

Cyber Essentials is the UK government-backed baseline for small-business security, delivered for the National Cyber Security Centre by IASME. For most practices it is a once-a-year questionnaire, often completed because a client, a tender or an insurer asked for it.

Until this year, a practice could fall short on one or two questions and still pass on balance. That has changed. Three questions now fail the whole assessment on their own.

What changed in April

A new question set, known as Danzell (requirements version 3.3), applies to every assessment account created after 26 April 2026. If you already hold a certificate, it stays valid until it expires 12 months after issue, but your renewal will be assessed against the new rules.

Worth checking now

If you opened an assessment before 26 April and have not finished it, IASME allows six months to complete it under the old requirements. That window closes around 26 October 2026.

The three automatic fails

1. MFA on every cloud service where it is available

Multi-factor authentication is now mandatory for every cloud service that offers it. Not most of them: all of them, for every user, including administrators.

The scheme now defines a cloud service as an on-demand, scalable service on shared infrastructure, reached over the internet through an account, that stores or processes your data. Cloud services cannot be left out of scope.

Email and Microsoft 365 are rarely the problem. The ones that catch practices are the quieter logins: a software vendor's portal, the payroll bureau, a file-sharing account someone set up for one client, the admin account nobody uses day to day.

2. System, router and firewall updates within 14 days

Question A6.4 asks whether all high-risk or critical security updates for operating systems and for router and firewall firmware are installed within 14 days of release. A “no” is now a fail.

Windows machines on automatic updates usually pass. The gaps are the router and firewall that nobody has logged into since they were installed, and the server whose updates wait because a reboot needs to happen out of hours.

3. Application updates within the same 14 days

Question A6.5 applies the same 14-day rule to applications, including their associated files and extensions. That means browser extensions, Office add-ins, PDF tools and your practice software’s own updates, not just the operating system. Software its maker no longer supports cannot meet this at all.

Why it matters even if you do not need the certificate

These three controls were not chosen at random. Stolen passwords and known, unpatched vulnerabilities are how most attacks on small firms actually start. Hiscox’s Cyber Readiness Report, published this month, found 38% of UK small businesses had a successful cyber attack in the last year, the highest rate of any country it surveyed.

A practice that gets these three right is harder to break into, whether or not it ever sits the assessment.

A pre-renewal check you can do this week

  • List every cloud service you use. Include the ones one person set up. For each, confirm MFA is on for every user, including shared and admin accounts.
  • Log into your router and firewall. Note the firmware version and when it was last updated. If nobody can log in, that is the first thing to fix.
  • Check how updates really happen. Who approves them, and what happens to a machine that needs a restart?
  • Look for applications nobody updates. Old PDF tools, browser extensions, add-ins, and anything no longer supported by its maker.
  • Put your renewal date in the diary. Start the questionnaire a month before, not a week.

Other changes worth knowing

  • Passwordless sign-in, such as passkeys, is now highlighted as the preferred approach.
  • Your scope description can be as detailed as you like and is visible on the digital certificate. Anything out of scope must now be described.
  • Certificates must identify the legal entity, including its name, address and company number.
  • “Point in time” now explicitly means the date the certificate is issued.
  • For Cyber Essentials Plus, a failed update retest now samples new devices at random, and self-assessment answers cannot be changed once Plus testing has started.

Common questions

What are the automatic fails in Cyber Essentials?

Three questions: MFA not enabled on a cloud service that offers it, high-risk or critical updates to operating systems or router and firewall firmware not installed within 14 days (A6.4), and the same for applications and their extensions (A6.5).

When did the changes take effect?

They apply to assessment accounts created after 26 April 2026. Accounts opened before that date have six months to complete under the previous requirements.

Does MFA really have to be on every cloud service?

On every cloud service where MFA is available, for every user. One service with MFA switched off is enough to fail.

How quickly must security updates be installed?

High-risk and critical updates must be installed within 14 days of release, for operating systems, router and firewall firmware, and applications.

I already have a certificate. Do I need to do anything now?

Your current certificate remains valid until it expires, but your renewal will be assessed under the new rules. The safest time to check the three automatic-fail areas is a month or two before renewal.

Want a second pair of eyes before your renewal?

We can go through the three automatic-fail areas with you, covering cloud MFA, update timings and forgotten applications, and tell you where you stand before the assessor does. We are not a certification body, so this is preparation, not the assessment itself.

Book a free consultation →
iK

iKORE Cloud — Technical Team

iKORE is a managed IT provider specialising in hosted desktop, Microsoft 365, cyber security and IT support for accountancy, legal and healthcare practices. This article was written in September 2026.