
Cyber Essentials 2026: Preparation for the New Questionnaire
asitplan Cyber Team
Author
Current status
This article covers the confirmed changes to the Cyber Essentials and Cyber Essentials Plus schemes, coming into effect in early 2026.
At a glance
- MFA Scope Expanded: Multi-factor authentication requirements will apply to a broader range of accounts and services.
- Patch Management Tightened: The timeline for applying critical security updates will be strictly enforced with new evidence requirements.
- BYOD Scrutiny: Bring Your Own Device (BYOD) policies will face harder compliance checks during Cyber Essentials Plus audits.
Why the changes?
The National Cyber Security Centre (NCSC) updates the Cyber Essentials technical requirements regularly to ensure the scheme remains effective against contemporary cyber threats. As ransomware attacks against the education sector become increasingly sophisticated, the 2026 update focuses heavily on closing common entry points: compromised credentials and unpatched vulnerabilities.
What is changing in 2026?
1. Universal MFA
Previously, MFA was only strictly required for cloud services (like Microsoft 365 or Google Workspace) and administrative accounts. The 2026 update expands this. Schools will now need to demonstrate that MFA is enforced for any remote access to the network, including VPNs, remote desktop gateways, and potentially web-facing MIS portals.
2. Patching Timelines and Evidence
The requirement to apply critical or high-severity patches within 14 days remains. However, assessors will now require much stronger evidence (such as vulnerability scan reports or patch management dashboard exports) to prove this is happening consistently, rather than relying on self-declaration.
3. Bring Your Own Device (BYOD)
Schools heavily reliant on staff using their own devices will find the new questionnaire challenging. The boundaries of what constitutes an "in-scope" device have been tightened. If a staff member accesses school data (even just email) on their personal phone, that phone must be subject to the school's update policies and basic security controls.
Next Steps for IT Teams
- Audit your MFA coverage: Ensure you don't have any legacy systems or VPNs that allow single-factor remote access.
- Review BYOD Policies: Decide whether the cost of securing staff personal devices outweighs the benefit. It may be easier to ban BYOD and issue school-owned devices instead.
- Automate Patching: If your server patching is still a manual process, look into automated deployment tools to guarantee the 14-day compliance window.