Cyber Essentials 2026: Scope and Requirements
A current guide to Cyber Essentials and Cyber Essentials Plus, including the five controls, version 3.3 changes, scope decisions and where pentesting fits.

Cyber Essentials is the UK government-backed baseline certification for defending against common internet-based attacks. The scheme is organised around five technical controls:
- Firewalls.
- Secure configuration.
- Security update management.
- User access control.
- Malware protection.
The current requirements are version 3.3, effective from 27 April 2026. Organisations that started an assessment before that date may be subject to the previous version, so confirm the applicable requirements with the certification body.
This guide explains the scheme at a practical level. The NCSC requirements and resources remain the authoritative source.
Cyber Essentials vs Cyber Essentials Plus
Both levels assess the same five control themes, but the assurance process differs.
| Cyber Essentials | Cyber Essentials Plus | |
|---|---|---|
| Assessment model | Verified self-assessment | The same control requirements with independent technical verification |
| Evidence | Questionnaire and supporting information requested by the certification body | Technical tests and evidence performed under the scheme specification |
| Typical use | Baseline assurance and supplier requirements | Higher confidence that controls are implemented in practice |
| Penetration test? | No bespoke penetration test | Technical verification, but not a general-purpose penetration test |
Cyber Essentials Plus is sometimes casually described as a penetration test. That is misleading. The assessor follows a defined technical test specification to verify the scheme controls. A bespoke penetration test has a different objective: to explore and validate attack paths in an agreed application, API, network, cloud or other scope.
What changed in version 3.3?
The NCSC's version 3.3 requirements document highlights these changes:
- A definition of cloud services has been added.
- The scheme states explicitly that cloud services cannot be excluded from scope merely because they are cloud-hosted.
- The passwordless-authentication definition now includes FIDO2.
- The Software Security Code of Practice is introduced in the software-development guidance.
- Scope language no longer refers to “untrusted connections.”
- The importance of backing up data is emphasised.
These are not a replacement for reading the current document. Small wording differences can matter when defining scope and answering the assessment.
Scope Cyber Essentials before changing controls
Most avoidable certification friction starts with an unclear boundary. Establish what part of the organisation is being certified and which people, devices, servers, networks, applications and cloud services sit inside it.
Questions to resolve include:
- Which legal entity and business units are included?
- Which internet-facing IP addresses and domains belong to the organisation?
- Which cloud productivity, identity, hosting and development services are used?
- Which laptops, desktops, mobile devices and servers can access organisational data or services?
- How do home workers and bring-your-own-device arrangements connect?
- Which third parties administer in-scope systems?
- Are unsupported systems present, and can they be removed or isolated?
Scope choices must reflect the scheme rules; they should not be used to hide inconvenient cloud services or unmanaged devices.
The five controls in practice
1. Firewalls
Use host and network firewalls to restrict unnecessary inbound and outbound access. Remove obsolete rules, protect administrative interfaces and avoid exposing management services directly to the internet.
Evidence might include device policy, cloud firewall rules, router configuration and a documented process for approving changes.
2. Secure configuration
Remove or disable unnecessary accounts, services, applications and insecure defaults. Change default credentials, apply secure settings and prevent ordinary users from changing controls they do not need to administer.
A build standard and device-management policy make these decisions repeatable.
3. Security update management
Keep in-scope operating systems, applications, firmware and cloud-managed components supported and appropriately updated. Know what software you operate, who owns it and how security fixes are identified and deployed.
The exact scheme requirements, including vulnerability and timing criteria, should be taken from the current NCSC document—not an old checklist or blog post.
4. User access control
Grant access according to business need, protect accounts with appropriate authentication, control administrative privileges and remove access promptly when it is no longer required.
Cloud identity is central here. Review privileged roles, dormant accounts, guest users, shared credentials, MFA coverage and account-recovery paths.
5. Malware protection
Use an allowed scheme approach to prevent or contain malicious code on in-scope devices. Depending on platform and use case, that may involve anti-malware, application allow-listing or restrictions on executing untrusted code.
The control should be managed and monitored rather than merely installed.
Need to validate a real attack surface?
Scope an AI-augmented penetration test with our in-house team. Every reported issue is reproduced, evidenced and ready for remediation.
Speak to SalesA practical readiness workflow
1. Download the current requirements
Record the version and assessment start date. Do not prepare against a previous year's interpretation when a newer version applies.
2. Build the asset and cloud-service inventory
Map people, endpoints, servers, network equipment, public IPs, cloud applications and administrators to the intended boundary.
3. Assign an owner to each control
One accountable lead should coordinate the assessment, but operational evidence will usually come from IT, identity, cloud, development and HR processes.
4. Run a gap review
Assess every applicable requirement, record the evidence available, name remediation owners and set target dates. Avoid answering “yes” on the basis of policy if devices or services do not enforce it.
5. Correct systemic gaps
Fix the process behind repeated issues. If unsupported software keeps returning, improve inventory and procurement. If dormant accounts remain active, connect identity reviews to joiner, mover and leaver workflows.
6. Complete the assessment and preserve evidence
Keep the final scope, answers, technical evidence, exceptions and remediation decisions together. This gives the next annual renewal a reliable starting point.
Where penetration testing fits
Penetration testing is complementary assurance, not a shortcut to certification. It can help an organisation understand whether weaknesses in its wider environment create exploitable attack paths beyond the scheme's baseline checks.
Relevant scopes may include:
- External network testing of internet-facing infrastructure.
- Web application testing of customer or staff portals.
- API testing of application backends and integrations.
- Cloud testing of identity, configuration and attack paths.
- Mobile application testing where mobile services handle organisational or customer data.
Pentestly's AI agents help testers explore more application states and potential paths. In-house human testers authorise each action, validate exploitability, assess context and own every finding. The report can support a broader security-improvement programme, but it should not be represented as the Cyber Essentials certificate or the Cyber Essentials Plus assessment.
Common mistakes
- Using a 2025 questionnaire for an assessment started under version 3.3.
- Omitting cloud services from the inventory.
- Treating an installed security product as proof that a control is effective.
- Keeping unsupported software because it is “internal only.”
- Giving ordinary accounts permanent local administrator rights.
- Assuming Cyber Essentials Plus is a bespoke web or infrastructure pentest.
- Waiting until the questionnaire deadline to discover ownership and evidence gaps.
FAQs
What changed in Cyber Essentials requirements version 3.3?
Version 3.3, effective 27 April 2026, clarifies cloud-service scope, adds a cloud-services definition, updates passwordless authentication to include FIDO2, introduces the Software Security Code of Practice in its development guidance and emphasises backups. Applicants should use the NCSC's current requirements document for the full wording.
Is penetration testing required for Cyber Essentials?
A bespoke penetration test is not the standard Cyber Essentials assessment. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds independent technical testing against the scheme specification. A separate penetration test can provide deeper assurance but does not replace certification.
What are the five Cyber Essentials controls?
The five controls are firewalls, secure configuration, security update management, user access control and malware protection.
Does Cyber Essentials cover cloud services?
Yes. Version 3.3 explicitly states that cloud services cannot simply be excluded from scope. Identify the services used and apply the scheme's shared-responsibility guidance to the controls managed by the organisation and the provider.
If you want deeper assurance around an application, API, cloud environment or network alongside certification work, speak to Pentestly about a separately scoped penetration test.
Get started
Need professional security testing?
Speak directly with our team about the risks, scope and testing approach that matter to your organisation.
More Articles
Internal Penetration Testing: Scope and Methods
Plan an internal penetration test around identity, segmentation and critical assets, with practical guidance on scope, access, evidence, reporting and retesting.
Supabase Security: Lessons from Real Pentests
Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.