Cyber Essentials Does Not Cover Everything
Cyber Essentials is one of the most useful cyber-security certifications available to UK businesses.
It provides a clear baseline.
It forces organisations to address weaknesses that commonly lead to compromise.
And increasingly, customers and supply chains expect businesses to have it.
But there is an important distinction:
Cyber Essentials is a strong foundation. It is not a complete cyber-security strategy.
The National Cyber Security Centre describes Cyber Essentials as the minimum standard of cyber security recommended by government, built around five technical controls intended to prevent common internet-based attacks.
Those five controls matter enormously.
But a business can pass Cyber Essentials and still have important risks elsewhere.
Understanding that distinction is the key to getting real security value from the certification.
What Does Cyber Essentials Actually Cover?
The current Cyber Essentials Requirements for IT Infrastructure v3.3 organise certification around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
In practical terms, that means checking whether your organisation has controls around:
internet-facing network protection
secure device and software configuration
supported and patched software
appropriate user and administrator access
malware protection
These are not arbitrary controls.
The NCSC says they are designed specifically to reduce exposure to the most common online attacks.
That makes Cyber Essentials an excellent starting point for an SME.
Cyber Essentials Got Stricter in 2026
The April 2026 update is worth understanding because some businesses may still think of Cyber Essentials as the scheme they completed several years ago.
It has evolved.
Under v3.3, cloud services used by the organisation cannot simply be excluded from scope, and the requirements now include an explicit cloud-service definition.
That matters because modern businesses increasingly depend on services such as:
Microsoft 365
cloud CRM
cloud accounting
cloud storage
hosted applications
Cyber Essentials increasingly reflects that reality rather than assuming that every important system is sitting in your office.
MFA Is Now Much Harder to Ignore
One of the most significant 2026 changes concerns multi-factor authentication.
IASME states that MFA is mandatory for cloud services where it is available, whether the capability is free, included with the service or requires payment. Failure to implement it in those circumstances now results in automatic assessment failure.
That is a substantial improvement.
But it still does not mean:
“Cyber Essentials passed = our identity security is fully mature.”
A more advanced identity strategy may still include:
phishing-resistant MFA
Conditional Access
privileged identity management
risky sign-in monitoring
separate administrator accounts
stronger controls for finance and executives
Cyber Essentials gives you the baseline.
Risk-based identity security goes further.
Critical Security Updates Need to Be Timely
The 2026 scheme has also become stricter around patching.
IASME says two update-management questions now carry automatic failure where high-risk or critical security updates and vulnerability fixes for operating systems, router/firewall firmware and applications are not installed within 14 days of release.
That is exactly the sort of requirement that materially reduces everyday attack exposure.
But again, it is a minimum requirement.
A mature vulnerability-management programme might also consider:
actively exploited vulnerabilities
asset criticality
exposure to the internet
zero-day mitigations
emergency patching
vulnerability scanning
Some flaws should be addressed much faster than fourteen days.
So What Doesn’t Cyber Essentials Fully Cover?
This is where the distinction matters most.
Cyber Essentials is intentionally focused on its five technical controls. It does not attempt to assess every component of a mature security programme.
Areas that generally need additional attention include:
security awareness and human behaviour
incident response
business continuity
backup resilience and restore testing
continuous security monitoring
vulnerability management beyond baseline patch compliance
penetration testing
supplier and supply-chain risk
data classification
advanced detection and response
Your existing article already identifies many of these gaps, and that central argument is worth keeping.
1. Security Awareness Training
Cyber Essentials includes technical controls that make attacks harder.
It does not replace the need to teach staff how attackers operate.
Employees still encounter:
phishing emails
fake Microsoft 365 login pages
payment diversion fraud
malicious attachments
QR-code phishing
telephone social engineering
MFA fatigue attacks
A secure configuration cannot stop every employee from willingly handing credentials to a convincing fake website.
Businesses therefore still need:
regular awareness training
simulated phishing where appropriate
clear reporting routes
role-specific education
Technical controls and human controls work together.
2. Incident Response
Cyber Essentials helps reduce the likelihood of common attacks succeeding.
It does not give you a complete incident-response plan for the day one does.
Every organisation should still know:
Who leads the response?
Who isolates affected systems?
How do we contact people if Microsoft 365 is unavailable?
Who contacts our insurer?
Who decides whether customers or regulators need notification?
Where are our recovery credentials?
These questions need answers before the incident.
Not while ransomware is spreading.
3. Backup and Disaster Recovery
The v3.3 Cyber Essentials requirements now explicitly emphasise the importance of backing up data, but backup and disaster-recovery maturity is not one of the five technical control categories being certified.
A proper backup strategy still needs to consider:
off-site copies
immutability
isolation
retention
separate backup credentials
restore testing
ransomware recovery
recovery time objectives
A company may satisfy Cyber Essentials and still discover during a disaster that nobody has ever successfully restored the accounting database.
That is a different problem.
4. Continuous Security Monitoring
Cyber Essentials checks whether baseline controls are in place.
That is different from continuously detecting suspicious activity.
Modern businesses may also need capabilities such as:
endpoint detection and response
identity monitoring
Microsoft Defender
centralised alerting
security event monitoring
suspicious sign-in detection
managed detection and response
The difference is:
Cyber Essentials helps make compromise harder.
Monitoring helps tell you when something is happening anyway.
You need both as security maturity increases.
5. Vulnerability Management
Cyber Essentials strongly addresses patching.
But full vulnerability management is broader than:
“Install critical updates within fourteen days.”
A mature programme may need to know:
which vulnerabilities exist
where they exist
whether they are exposed externally
whether attackers are actively exploiting them
which systems are business-critical
which mitigations exist before a patch is available
That often requires:
vulnerability scanning
prioritisation
remediation tracking
verification
Patch compliance is crucial.
It is not the whole vulnerability-management process.
6. Penetration Testing
Cyber Essentials does not mean an ethical hacker has attempted to compromise your complete environment.
Cyber Essentials Plus gives greater assurance by technically auditing whether the Cyber Essentials controls have been implemented, but it remains an assessment against those same core Cyber Essentials requirements rather than a full penetration test of the organisation. IASME describes CE+ as a higher-assurance technical audit of the organisation’s cyber-security measures against the scheme.
A penetration test asks different questions:
Can we exploit this application?
Can we move laterally?
Can permissions be abused?
Can this custom system be compromised?
Some organisations need both.
7. Supplier Risk
Your security does not stop at your firewall.
Businesses increasingly depend on:
accountants
software providers
MSPs
cloud platforms
payroll services
contractors
outsourced support
A supplier with privileged access can create risk even when your own Cyber Essentials controls are correctly implemented.
The NCSC itself encourages organisations to use Cyber Essentials within supply chains as part of a wider strategic approach to cyber risk.
That phrase matters:
part of a wider approach.
Supplier risk still needs active management.
8. Data Classification and Governance
Cyber Essentials helps control access.
But it does not answer questions such as:
Which information is genuinely sensitive?
Which Teams sites contain financial information?
Which SharePoint folders can guests access?
Which information should never leave the organisation?
Those questions belong to broader information governance.
Without it, you can have technically secure systems containing badly organised and excessively shared data.
Cyber Essentials Is Still Extremely Valuable
None of this is an argument against Cyber Essentials.
Quite the opposite.
The NCSC describes the scheme as the minimum security standard it recommends, and the five controls are specifically designed to stop many common attacks.
It also brings commercial benefits.
The NCSC says a growing number of organisations require suppliers to hold Cyber Essentials before they can bid for work, and certification can help demonstrate that a business takes cyber security seriously.
For SMEs in particular, the scheme gives a very practical starting point.
Cyber Essentials Is a Point-in-Time Assessment
This is another 2026 point I would strengthen substantially.
IASME clarified that Cyber Essentials remains a point-in-time assessment, with the relevant point being the date the certificate is issued. The 2026 process also requires the board-level declaration to acknowledge the organisation’s responsibility to maintain compliance during the certification period.
That means:
Passing in May does not protect you from configuration drift in November.
During the year:
employees join
employees leave
devices are purchased
software goes out of support
cloud applications are added
permissions change
firewall rules accumulate
Cyber Essentials needs to be maintained, not merely renewed.
Cyber Essentials Plus Does Not Make You Invincible Either
Cyber Essentials Plus is the more rigorous version.
It provides greater confidence because an assessor performs technical verification rather than relying only on the verified self-assessment. The 2026 CE+ process has also been tightened so organisations cannot simply fix only the sampled devices and leave the wider estate non-compliant.
That is a meaningful improvement.
But CE+ still does not mean:
“No attacker can breach us.”
It means there is stronger independent evidence that the Cyber Essentials technical controls are operating as required.
That distinction matters.
A Better Security Model for SMEs
I would think of security in layers.
Layer 1 — Cyber Essentials
Get the baseline right:
firewalls
secure configuration
security updates
access control
malware protection
Layer 2 — Identity and Email
Add:
strong MFA
Conditional Access where appropriate
email protection
phishing controls
privileged-account protection
Layer 3 — Detection
Add:
EDR
identity monitoring
central security alerts
Layer 4 — Recovery
Build:
immutable/off-site backups
restore testing
disaster recovery
business continuity
Layer 5 — People and Process
Develop:
staff training
incident response
supplier management
security policies
Layer 6 — Assurance
Use as appropriate:
vulnerability scanning
Cyber Essentials Plus
penetration testing
external security reviews
That creates something much stronger than treating certification as the finish line.
The Questions to Ask After You Pass
Once you have Cyber Essentials, ask:
1. Are all important cloud services included in our security model?
2. Is MFA enabled wherever it is available?
3. Can we reliably deploy critical updates within the required timescale?
4. Are administrator privileges reviewed regularly?
5. Can we detect suspicious activity?
6. Could we recover from ransomware?
7. When did we last test a backup restore?
8. Do employees know how to recognise and report phishing?
9. Do we understand supplier access?
10. Have we tested the environment beyond the Cyber Essentials baseline?
If several answers are:
“No”
then that tells you exactly where to go next.
How Hamilton Group Can Help
Hamilton Group can help businesses achieve Cyber Essentials without treating the certificate as the end of the security journey.
We can assist with:
Cyber Essentials readiness
Cyber Essentials Plus preparation
Microsoft 365 security
MFA
patch management
firewall configuration
endpoint protection
vulnerability scanning
security awareness training
backup and disaster recovery
ongoing cyber-security management
The objective should be:
achieve Cyber Essentials, maintain it throughout the year and then build additional protection around the risks the scheme was never designed to assess in full.
Visit hgmssp.com or call 0330 043 0069 to discuss Cyber Essentials and cyber security.