Cyber Security Guide · 22 May 2026
Cyber Essentials Plus: what changed in 2026
The latest control changes, common audit failures and how to prepare in six weeks.

Cyber Essentials Plus keeps evolving as the threat landscape shifts. The 2026 update tightens several controls that trip up organisations who scraped through last year.
What changed
- Stricter scope rules for home-working and BYOD devices
- MFA required on all cloud services, not just admin accounts
- Software update SLAs shortened for high-severity vulnerabilities
- Clearer expectations around passwordless and phishing-resistant MFA
Common audit failures
- Unmanaged personal devices accessing corporate email
- Unsupported operating systems still in production
- Missed patches on browsers, Office and third-party apps
- MFA exceptions for shared or service accounts
A six-week readiness plan
- Week 1: scope confirmation and asset inventory
- Weeks 2-3: MFA everywhere, remove unsupported software
- Weeks 4-5: patch backlog, secure configuration baselines
- Week 6: gap review, then book the audit
