Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Cyber Essentials update could put your public sector contracts at risk | TechRadar

Cyber Essentials v3.3 creates a new automatic fail rule Discover insights about cyber essentials update could put your public sector contracts at risk | techrad

TechnologyInnovationBest PracticesGuideTutorial
Cyber Essentials update could put your public sector contracts at risk | TechRadar
Listen to Article
0:00
0:00
0:00

Cyber Essentials update could put your public sector contracts at risk | Tech Radar

Overview

News, deals, reviews, guides and more on the newest computing gadgets

Start exploring exclusive deals, expert advice and more

Details

Unlock and manage exclusive Techradar member rewards.

Unlock instant access to exclusive member features.

Get full access to premium articles, exclusive features and a growing list of member rewards.

Cyber Essentials update could put your public sector contracts at risk

Cyber Essentials v 3.3 creates a new automatic fail rule

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Not a non-conformity to address gradually. Not a remediation point. An immediate fail with no second chance within that certification cycle.

Cyber Essentials is the UK government's flagship cybersecurity certification scheme, backed by the National Cyber Security Centre and administered by IASME. Around 50,000 organizations certify every year. For suppliers to central government handling sensitive data it is mandatory.

It’s time cyber security understood human behavior and acted accordingly

Authentication in 2026 - moving beyond foundational MFA to tackle the new era of attacks

Regulatory whiplash: Why cyber resilience is now a governance imperative

For many others it has become a baseline expectation for cyber insurance and private sector procurement. I have been assessing organizations against the scheme since 2017.. Version 3.3, which takes effect on 27 April, is the most significant update in all of that time.

The specific change is this: if a cloud service offers Multi-Factor Authentication (MFA) and an organization has not enabled it for all users, the assessment fails immediately.

This applies even where the feature is only available through a paid upgrade to an existing plan. Under the previous version of the scheme, non-compliant answers on this point were survivable. That route is now closed.

For most organizations, resolving this is a straightforward technical project. But in my assessments this year I have encountered a specific category of organization for which it is anything but. The gap between what v 3.3 now requires and what they can actually deliver is significant, and the scheme update does not address it.

The pressure points I see consistently appear in environments built around shared access, rapid task switching, and frequent staff or volunteer turnover.

Think of a station operations room where multiple staff rotate through shared terminals across shifts, needing to access time-critical information in seconds.

From boardroom risk to deal flow: why cyber M&A is accelerating in 2026

How to meaningfully measure the effectiveness of cyber resilience

Or a nationally known charity with hundreds of high street locations and a large volunteer workforce on short shifts, for whom managing individual authentication at scale is a real practical problem.

In both cases, the relevant cloud services offer the required verification feature. In both cases it has not been enabled, not out of carelessness, but because the operational reality makes standard approaches genuinely difficult to deploy.

Under the previous version of the scheme that position was survivable. Under v 3.3 it becomes an automatic fail.

That does not make stronger authentication unnecessary. If anything it makes it more important. But it does mean that some organizations have supported the principle while delaying the harder work of designing how it will actually function day to day. That distinction matters much more under v 3.3.

This is a workflow design problem, not a policy problem

The organizations that will navigate v 3.3 well are not the ones with the most sophisticated security policies. They are the ones that have done the practical work of making stronger authentication usable in the environments where it is hardest to deploy.

That means mapping every in-scope cloud service and establishing exactly where verification features are available, including where they require a paid upgrade, because v 3.3 makes no distinction. It means reviewing whether current authentication approaches are suitable for fast-moving operational environments.

And it means looking seriously at options such as FIDO2 security keys, passkeys, badge-linked identity workflows, and context-aware access controls that can reduce friction without reducing assurance.

NCSC's own guidance has increasingly reflected the value of phishing-resistant approaches over codes and prompts, and v 3.3 moves in the same direction.

Cyber Essentials now makes cloud services unambiguously part of scope where they store or process organizational data. Organizations can no longer assume that awkward operational exceptions will remain tolerable.

The bar is rising. The organizations that will meet it are the ones treating authentication as a design challenge, not a compliance checkbox.

The businesses most likely to struggle with Cyber Essentials v 3.3 are not the ones that disagree with stronger authentication. They are the ones that have postponed the practical work of making it usable everywhere the standard now expects it to be.

This should not be left until renewal. Rolling out new authentication methods, adjusting processes for joiners and leavers, and getting users comfortable with a new access model all take time. If verification features are available on your cloud services but not yet enabled, 27 April is closer than it appears.

Cyber Essentials v 3.3 is not just a tougher compliance checkpoint. It is a prompt to make sure that how your organization verifies who can access its systems actually works in the real world, especially in the environments where getting that right is hardest.

This article was produced as part of Tech Radar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of Tech Radar Pro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

You must confirm your public display name before commenting

1007 First Light senior combat designer explains how all the cool gadgets can be used in combat

2I've made thousands of pizzas for slice-loving customers, and the Gozney Arc Lite is a near-perfect pizza oven for beginners

3 Chinese researchers develop iron battery 80 times cheaper than lithium

4'They're building each other': new X1 Neo robot video shows the humanoids assisting in the robot production process, just as all science fiction foretold

5 Quordle hints and answers for Friday, May 1 (game #1558)

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • News, deals, reviews, guides and more on the newest computing gadgets
  • Start exploring exclusive deals, expert advice and more
  • Unlock and manage exclusive Techradar member rewards
  • Unlock instant access to exclusive member features
  • Get full access to premium articles, exclusive features and a growing list of member rewards

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.