Insights · Cyber Essentials

Cyber Essentials for UK regulated firms: what changed in 2026 and why it matters

What Cyber Essentials covers, what changed in April 2026, why it matters to FCA- and SRA-regulated firms, and how it compares with ISO 27001 and the regulators’ own rules.
The short answer

Cyber Essentials is a UK government-backed scheme, run with the NCSC and delivered by IASME through certification bodies, that verifies five technical controls. Neither the FCA, the PRA nor the SRA requires it, but it is a low-cost, well-recognised baseline that clients, insurers and some government contracts ask for. ISO 27001 and the regulators’ rules cover much more.

Key points
  • Five controls: firewalls, secure configuration, user access control, malware protection and security update management.
  • Version 3.3 and the Danzell question set apply to new assessments from 27 April 2026, with stricter marking.
  • It is not required by the FCA, PRA or SRA, but it lines up well with the access and security controls they expect.
  • It does not cover governance, operational resilience, incident response or third-party oversight.
  • Certificates last 12 months.

What Cyber Essentials is

Cyber Essentials is a scheme developed by the UK’s National Cyber Security Centre (NCSC) and delivered by IASME. It checks that you have five basic technical controls in place, which together are designed to protect against the most common internet-based attacks:

  • Firewalls. Boundary and device firewalls that filter unwanted traffic.
  • Secure configuration. Remove unused software and accounts and change default settings.
  • User access control. Separate admin accounts, least privilege and multi-factor authentication.
  • Malware protection. Anti-malware or application allow-listing.
  • Security update management. Keep operating systems, firmware and applications patched.

There are two levels. Cyber Essentials is a self-assessment that a certification body verifies. Cyber Essentials Plus adds hands-on technical testing by an assessor.

What changed in April 2026

The requirements moved to version 3.3 and a new question set, Danzell, which replaces Willow, for new assessments from 27 April 2026. Organisations whose assessment account already existed have a six-month transition. The five controls are unchanged, but marking is stricter:

  • Multi-factor authentication is required for all cloud services where it is available.
  • Critical and high-risk security updates must be applied within 14 days for operating systems, firmware and applications.
  • Falling short on either of these is an automatic fail.
  • Cloud services cannot be excluded from scope.
  • Scope descriptions are more detailed, legal entities must be named, and there are new rules on how Cyber Essentials Plus re-test samples are chosen.
  • The director’s declaration now includes an acknowledgement of ongoing compliance.

Why it matters to regulated firms

Neither the FCA, the PRA nor the SRA requires Cyber Essentials. It is still one of the quickest ways for a regulated firm to show that the basics are in place: client due diligence questionnaires, cyber insurers and some UK government contracts ask for it, and it gives your board an independent check of the controls that most attacks exploit.

It lines up well with the protective controls regulators expect (authentication, patching, malware protection and access control), which makes it a practical first milestone. It does not cover governance, operational resilience, incident response or third-party oversight, which regulators also expect.

Cyber Essentials, ISO 27001 and the regulators’ rules

Cyber EssentialsISO 27001:2022FCA, PRA and SRA rules
What it isUK government-backed baseline schemeInternational standard for an information security management systemRegulatory rules for authorised firms
What it coversFive technical controlsGovernance, risk, people, suppliers and technologyGovernance, technical controls, third parties, incidents and reporting
How you show itCertificate (Essentials or Plus), renewed every 12 monthsCertificate from an accredited body, audited each yearEvidence to the regulator on request, plus incident reporting
Mandatory for regulated firms?NoNoYes

Getting ready

  • Scope honestly. List every user, device (including personal devices that reach firm data), network boundary and cloud service. Under version 3.3, cloud services stay in scope.
  • Fix the usual failure points first: unsupported operating systems, missing MFA on cloud accounts, patches older than 14 days, everyday use of admin accounts, default passwords and open ports.
  • Complete the self-assessment accurately and have a director sign the declaration.
  • Choose Cyber Essentials Plus if a client, insurer or contract asks for independently tested evidence.
  • Diarise renewal. Certificates last 12 months.

Certification itself is carried out by a certification body licensed by IASME. An MSP can prepare you and supply the technical evidence, and Cre8 IT helps clients scope, fix and evidence their controls, but no MSP can certify you.

Sources and further reading

Last reviewed 25 September 2026. This guide is general information, not legal or regulatory advice. Rules change, so check the current text and take advice from your compliance officer or legal adviser before relying on it.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a managed IT and cyber security company that has supported businesses across the UK, the UAE and Saudi Arabia since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

Is Cyber Essentials mandatory for FCA- or SRA-regulated firms?

No. It is not required by the FCA, the PRA or the SRA. Clients, insurers and some government contracts may ask for it.

How long does a Cyber Essentials certificate last?

Twelve months. You renew every year, and your scope and answers are assessed against the current requirements.

Should we do Cyber Essentials or ISO 27001 first?

If you want a quick, low-cost baseline, Cyber Essentials is a sensible first step and much of the work carries over. If you want a full management system that speaks to your regulator’s governance expectations, aim for ISO 27001. Many firms do both.
Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
ISO 27001

ISO 27001 for regulated firms: how it supports FCA, PRA and SRA expectations

What ISO/IEC 27001:2022 certifies, how its controls map to FCA, PRA and SRA expectations, and how to read a supplier’s certificate.
4 min read · Reviewed 25 September 2026
Microsoft 365

Microsoft 365 governance for regulated firms: a practical baseline

How to govern Microsoft 365 in an FCA-, PRA- or SRA-regulated firm: identity, devices, data, logging and licences, with a 30-day order of work.
4 min read · Reviewed 25 September 2026
Audit readiness

IT audit readiness for regulated firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls: the evidence pack, a mock audit and a six-week plan.
3 min read · Reviewed 25 September 2026

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.