Back to Pentestly Labs
    Pentestly Labs

    Cyber Essentials 2026: Scope and Requirements

    A current guide to Cyber Essentials and Cyber Essentials Plus, including the five controls, version 3.3 changes, scope decisions and where pentesting fits.

    10 min read
    by Aidan PrestonAbout the team
    Share
    Cyber Essentials 2026: Scope and Requirements

    Cyber Essentials is the UK government-backed baseline certification for defending against common internet-based attacks. The scheme is organised around five technical controls:

    1. Firewalls.
    2. Secure configuration.
    3. Security update management.
    4. User access control.
    5. Malware protection.

    The current requirements are version 3.3, effective from 27 April 2026. Organisations that started an assessment before that date may be subject to the previous version, so confirm the applicable requirements with the certification body.

    This guide explains the scheme at a practical level. The NCSC requirements and resources remain the authoritative source.

    Cyber Essentials vs Cyber Essentials Plus

    Both levels assess the same five control themes, but the assurance process differs.

    Cyber EssentialsCyber Essentials Plus
    Assessment modelVerified self-assessmentThe same control requirements with independent technical verification
    EvidenceQuestionnaire and supporting information requested by the certification bodyTechnical tests and evidence performed under the scheme specification
    Typical useBaseline assurance and supplier requirementsHigher confidence that controls are implemented in practice
    Penetration test?No bespoke penetration testTechnical verification, but not a general-purpose penetration test

    Cyber Essentials Plus is sometimes casually described as a penetration test. That is misleading. The assessor follows a defined technical test specification to verify the scheme controls. A bespoke penetration test has a different objective: to explore and validate attack paths in an agreed application, API, network, cloud or other scope.

    What changed in version 3.3?

    The NCSC's version 3.3 requirements document highlights these changes:

    • A definition of cloud services has been added.
    • The scheme states explicitly that cloud services cannot be excluded from scope merely because they are cloud-hosted.
    • The passwordless-authentication definition now includes FIDO2.
    • The Software Security Code of Practice is introduced in the software-development guidance.
    • Scope language no longer refers to “untrusted connections.”
    • The importance of backing up data is emphasised.

    These are not a replacement for reading the current document. Small wording differences can matter when defining scope and answering the assessment.

    Scope Cyber Essentials before changing controls

    Most avoidable certification friction starts with an unclear boundary. Establish what part of the organisation is being certified and which people, devices, servers, networks, applications and cloud services sit inside it.

    Questions to resolve include:

    • Which legal entity and business units are included?
    • Which internet-facing IP addresses and domains belong to the organisation?
    • Which cloud productivity, identity, hosting and development services are used?
    • Which laptops, desktops, mobile devices and servers can access organisational data or services?
    • How do home workers and bring-your-own-device arrangements connect?
    • Which third parties administer in-scope systems?
    • Are unsupported systems present, and can they be removed or isolated?

    Scope choices must reflect the scheme rules; they should not be used to hide inconvenient cloud services or unmanaged devices.

    The five controls in practice

    1. Firewalls

    Use host and network firewalls to restrict unnecessary inbound and outbound access. Remove obsolete rules, protect administrative interfaces and avoid exposing management services directly to the internet.

    Evidence might include device policy, cloud firewall rules, router configuration and a documented process for approving changes.

    2. Secure configuration

    Remove or disable unnecessary accounts, services, applications and insecure defaults. Change default credentials, apply secure settings and prevent ordinary users from changing controls they do not need to administer.

    A build standard and device-management policy make these decisions repeatable.

    3. Security update management

    Keep in-scope operating systems, applications, firmware and cloud-managed components supported and appropriately updated. Know what software you operate, who owns it and how security fixes are identified and deployed.

    The exact scheme requirements, including vulnerability and timing criteria, should be taken from the current NCSC document—not an old checklist or blog post.

    4. User access control

    Grant access according to business need, protect accounts with appropriate authentication, control administrative privileges and remove access promptly when it is no longer required.

    Cloud identity is central here. Review privileged roles, dormant accounts, guest users, shared credentials, MFA coverage and account-recovery paths.

    5. Malware protection

    Use an allowed scheme approach to prevent or contain malicious code on in-scope devices. Depending on platform and use case, that may involve anti-malware, application allow-listing or restrictions on executing untrusted code.

    The control should be managed and monitored rather than merely installed.

    Need to validate a real attack surface?

    Scope an AI-augmented penetration test with our in-house team. Every reported issue is reproduced, evidenced and ready for remediation.

    Speak to Sales

    A practical readiness workflow

    1. Download the current requirements

    Record the version and assessment start date. Do not prepare against a previous year's interpretation when a newer version applies.

    2. Build the asset and cloud-service inventory

    Map people, endpoints, servers, network equipment, public IPs, cloud applications and administrators to the intended boundary.

    3. Assign an owner to each control

    One accountable lead should coordinate the assessment, but operational evidence will usually come from IT, identity, cloud, development and HR processes.

    4. Run a gap review

    Assess every applicable requirement, record the evidence available, name remediation owners and set target dates. Avoid answering “yes” on the basis of policy if devices or services do not enforce it.

    5. Correct systemic gaps

    Fix the process behind repeated issues. If unsupported software keeps returning, improve inventory and procurement. If dormant accounts remain active, connect identity reviews to joiner, mover and leaver workflows.

    6. Complete the assessment and preserve evidence

    Keep the final scope, answers, technical evidence, exceptions and remediation decisions together. This gives the next annual renewal a reliable starting point.

    Where penetration testing fits

    Penetration testing is complementary assurance, not a shortcut to certification. It can help an organisation understand whether weaknesses in its wider environment create exploitable attack paths beyond the scheme's baseline checks.

    Relevant scopes may include:

    Pentestly's AI agents help testers explore more application states and potential paths. In-house human testers authorise each action, validate exploitability, assess context and own every finding. The report can support a broader security-improvement programme, but it should not be represented as the Cyber Essentials certificate or the Cyber Essentials Plus assessment.

    Common mistakes

    • Using a 2025 questionnaire for an assessment started under version 3.3.
    • Omitting cloud services from the inventory.
    • Treating an installed security product as proof that a control is effective.
    • Keeping unsupported software because it is “internal only.”
    • Giving ordinary accounts permanent local administrator rights.
    • Assuming Cyber Essentials Plus is a bespoke web or infrastructure pentest.
    • Waiting until the questionnaire deadline to discover ownership and evidence gaps.

    FAQs

    What changed in Cyber Essentials requirements version 3.3?

    Version 3.3, effective 27 April 2026, clarifies cloud-service scope, adds a cloud-services definition, updates passwordless authentication to include FIDO2, introduces the Software Security Code of Practice in its development guidance and emphasises backups. Applicants should use the NCSC's current requirements document for the full wording.

    Is penetration testing required for Cyber Essentials?

    A bespoke penetration test is not the standard Cyber Essentials assessment. Cyber Essentials is a verified self-assessment, while Cyber Essentials Plus adds independent technical testing against the scheme specification. A separate penetration test can provide deeper assurance but does not replace certification.

    What are the five Cyber Essentials controls?

    The five controls are firewalls, secure configuration, security update management, user access control and malware protection.

    Does Cyber Essentials cover cloud services?

    Yes. Version 3.3 explicitly states that cloud services cannot simply be excluded from scope. Identify the services used and apply the scheme's shared-responsibility guidance to the controls managed by the organisation and the provider.

    If you want deeper assurance around an application, API, cloud environment or network alongside certification work, speak to Pentestly about a separately scoped penetration test.

    Get started

    Need professional security testing?

    Speak directly with our team about the risks, scope and testing approach that matter to your organisation.

    More Articles

    Internal Penetration Testing: Scope and Methods

    Plan an internal penetration test around identity, segmentation and critical assets, with practical guidance on scope, access, evidence, reporting and retesting.

    25 min read

    Supabase Security: Lessons from Real Pentests

    Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.

    20 min read

    How Often Should Penetration Testing Be Done?

    Learn when annual, quarterly and change-triggered penetration testing make sense, with a practical risk-based schedule for UK organisations.

    9 min read