If your business holds a Cyber Essentials certificate — or is planning to get one — the rules changed significantly in April 2026. The updated v3.3 requirements, which apply to every certification and recertification from 28 April 2026 onwards, have expanded the mandatory use of multi-factor authentication (MFA) well beyond what most SMEs currently have in place.

The headline change: MFA is now required for all user accounts on all cloud services, not just administrator accounts. If your team logs into Microsoft 365, Google Workspace, Xero, your CRM, your cloud accounting software, or any other SaaS tool using business credentials — MFA must be enabled for every single person, every single tool.

Under the old requirements, many SMEs passed Cyber Essentials with MFA only on admin and privileged accounts. That is no longer sufficient. An auditor finding MFA gaps on standard user accounts will now fail the assessment automatically.

What counts as a “cloud service”

The updated guidance defines a cloud service broadly: any service accessed online that stores or processes your organisation’s data. If your staff log in with a business email address, it is in scope.

In practice for most UK SMEs, that means:

  • Microsoft 365 and all its apps (Outlook, Teams, SharePoint)
  • Google Workspace
  • Cloud accounting (Xero, QuickBooks, FreeAgent)
  • CRM systems (Salesforce, HubSpot, Zoho)
  • Cloud storage (Dropbox, OneDrive, Google Drive)
  • Any HR, payroll or project management tool accessed via browser

If the service supports MFA and you have not enforced it for every user, that is now a failing control under Cyber Essentials.

Why this matters beyond certification

Even if you have no immediate plans to certify or recertify, these requirements exist because they reflect genuine best practice. Stolen credentials are the most common entry point for cyberattacks on UK SMEs — phishing, credential stuffing and brute-force attacks all depend on finding accounts protected only by a password.

Enforcing MFA across your entire cloud estate is one of the highest-value, lowest-cost security improvements your business can make this year. The NCSC estimates that MFA blocks over 99% of automated credential-based attacks.

For businesses working with the public sector, NHS, or larger supply chains, Cyber Essentials certification is increasingly a contractual requirement — and the bar just got higher.

How to check your current position

Start with a cloud service audit: list every SaaS tool your team uses and check whether MFA is enabled and enforced for all accounts, not just admins. Most Microsoft 365 and Google Workspace tenants can enforce MFA centrally through admin settings with minimal disruption.

Conditional Access policies in Microsoft 365 (available on Business Premium) allow you to enforce MFA automatically based on login location or device status — a step up from basic per-user MFA and worth considering if you are recertifying.

ApplyAI can help businesses assess their current Microsoft 365 security configuration and identify the quickest path to compliance across cloud tools. Getting MFA right once, properly enforced, removes the most common attack vector from your business in a single afternoon.

The deadline that matters

If your Cyber Essentials certificate is due for renewal, check the expiry date against 28 April 2026. Any renewal from that date is assessed against v3.3. If MFA is not enforced across all your cloud services when the assessor checks, you will fail. Fix it before you apply.