Cyber essentials plus changes 2026 tighten sampling and evidence expectations and align assessments with the National Cyber Security Centre Pathways in 2026 (NCSC, 2026). In the UK, examiners will use the Cyber Essentials Requirements for IT Infrastructure v3 when sampling devices and requesting evidence (Cyber Essentials Requirements for IT Infrastructure v3). Organisations bidding for central government work should review Procurement Policy Note 014 on Cyber Essentials expectations (PPN 014, GOV.UK).
- Key change: Assessments now align with the National Cyber Security Centre Pathways in 2026, shifting evidence towards live technical proof (NCSC, 2026).
- What to expect: Examiners will use the Cyber Essentials Requirements for IT Infrastructure v3 when sampling devices and requesting evidence (Cyber Essentials Requirements for IT Infrastructure v3).
- Who this affects: In the UK, organisations bidding for central government work should review Procurement Policy Note 014 on scheme expectations (PPN 014, GOV.UK).
- Immediate action: Build a device inventory, retain recent logs and patch records, and run a mock evidence review before booking assessment.
What changed in the Cyber Essentials scheme in April 2026?
The April 2026 update changed audit sampling, the IASME Willow question set and introduced the NCSC Pathways guidance, altering how Cyber Essentials Plus assessments are evidence‑checked. These cyber essentials plus changes 2026 tighten sampling, raise evidence expectations and give a new route for small pilots to show assurance.
Willow question set and who issued it
The Willow question set was issued by IASME, with technical alignment to the National Cyber Security Centre (NCSC) test specification, and it replaces previous questionnaires for Plus assessments. The Willow changes refocus auditors on live evidence such as device configuration, multifactor authentication logs and patch records, which means organisations must hold demonstrable artefacts during the audit.
Sampling, evidence and audit practicalities
Audit sampling increased in scope so auditors now inspect a broader set of devices and users rather than a minimal sample, and assessors apply deeper checks to configuration and patching. The NCSC's Cyber Essentials Requirements for IT Infrastructure v3 (NCSC, Requirements v3) underpins these checks. The change means some renewals that passed previously on paperwork alone may now require small technical fixes before certification.
Pathways guidance and procurement context
The NCSC published Cyber Essentials Pathways in 2026 to give an alternative route for small or experimental deployments to show progress towards assurance (NCSC, Pathways 2026). In the UK public sector context, government procurement policy notes such as PPN 014 continue to reference Cyber Essentials as a baseline for supplier assurance, so the April 2026 changes affect both commercial bidders and existing suppliers looking to renew (GOV.UK, PPN 014).
For renewal windows immediately following April 2026, prepare for spot checks and have live evidence ready. If you are preparing for a renewal, our Renewing Cyber Essentials and Cyber Essentials Plus guide explains the updated documentary and technical evidence auditors will expect.
In our experience, the cyber essentials plus changes 2026 make the Plus audit more technical and less document driven, and the Willow set is the main operational change auditors will apply at assessments.
What is Cyber Essentials Plus under the 2026 rules?
Cyber Essentials Plus under the 2026 rules is the independently assessed Cyber Essentials certification with an updated test specification and an optional NCSC Pathways route for alternative evidence of compliance (National Cyber Security Centre, 2026).
The 2026 update clarifies what auditors must test and how evidence may be presented, it does not replace the requirement for an independent hands-on assessment for Plus. The National Cyber Security Centre's Cyber Essentials Requirements for IT Infrastructure remains the baseline test specification for device and configuration checks (National Cyber Security Centre, v3).
What changed for evidence and sampling
Under the 2026 changes, auditors are instructed to sample more devices in-scope and to accept live technical evidence where that better demonstrates secure configuration, but the scheme still allows a mix of evidence types rather than mandating a single collection method. The NCSC's Pathways material explains alternative evidence routes organisations can use when traditional evidence is hard to gather, for example cloud-managed estates or segmented networks (National Cyber Security Centre, 2026).
Risk trends support the emphasis on multifactor authentication and endpoint hygiene: IBM's 2025 X‑Force analysis observed a large rise in credential theft and infostealers, which is why auditors will often request MFA and patching history during Plus assessments (IBM X‑Force, 2025).
Audit-day practicalities
At CyPro, we recommend treating audit day as a technical review, not a paperwork exercise. Prepare a canonical device inventory, ensure patch and update logs are queryable for the sample set, and have MFA rollout evidence ready for sampled accounts. Our Cyber Essentials Plus pre-audit checklist and renewal guidance map these tasks to the NCSC requirements and shorten on-site time (Cyber Essentials Plus pre-audit checklist, Renewing Cyber Essentials and Cyber Essentials Plus).
What this means for renewals is simple: expect closer technical scrutiny of the items auditors test, use the NCSC requirements as your audit checklist, and consider the NCSC Pathways guidance only if your environment cannot produce the usual artefacts.
How does the Willow question set change affect my renewal process?
Willow replaces the old IASME questionnaire with a tighter, evidence‑first set of questions, so renewals now require live technical proof such as patch histories, MFA logs and sampled device tests on assessment day.
What changed in April 2026?
The Willow question set narrows acceptable evidence and asks auditors to verify controls live, increasing sampling and technical checks. The National Cyber Security Centre (NCSC) guidance and Willow mean auditors will request queryable artefacts rather than tickbox screenshots, and examiners can probe patch timelines and MFA enforcement during the visit. This change follows the NCSC move to more technical assurance and aligns with government procurement guidance that expects demonstrable technical controls; organisations should expect auditors to check a sample of endpoints and identity settings on the day.
For context, IBM's 2025 analysis highlights rising credential theft and pressures on identity controls, which is why Willow emphasises live MFA evidence IBM, 2025. The ICO has also urged UK organisations to improve basic controls after seeing widespread incidents, reinforcing why the Willow questions demand queryable records ICO, 2024.
Practical renewal timeline and actions
Start preparing earlier: begin evidence collection at least 8 weeks before your IASME audit to gather patch logs, MFA reports and endpoint inventories. Organisations with rolling renewals should map Willow evidence to their window so auditors see current data, not historic snapshots. We recommend inventorying devices, exporting patch and MFA logs, and running an internal sample check two weeks before assessment.
In our experience, treating the cyber essentials plus changes 2026 as a requirement to produce live, queryable evidence avoids last‑minute failures, and following the NCSC resources on acceptable artefacts speeds the auditor review NCSC Help & resources.
For a quick primer on what to gather and when, see our Cyber Essentials insights.
Who needs Cyber Essentials Plus after the 2026 update?
Organisations that should prioritise Cyber Essentials Plus after the 2026 update are those that must prove technical controls through independent testing, not just self-assessment. This typically includes suppliers to central government, firms with insurer or contract clauses requiring independent assurance, and organisations that hold large volumes of personal or sensitive data.
The National Cyber Security Centre's Cyber Essentials guidance explains the 2026 shift towards live technical checks and the Cyber Essentials Pathways, which increase the weight of technical evidence in audits (National Cyber Security Centre).
Public sector and procurement
Government Procurement Policy Note PPN 014 still treats Cyber Essentials as a baseline for suppliers to central government, and many contracting authorities now expect the Plus level where independent testing is required by the contract. Organisations bidding for central government contracts or operating deep in government supply chains should treat Cyber Essentials Plus as the likely requirement, not an optional enhancement.
Insurance and contractual triggers
The Information Commissioner’s Office has urged stronger technical controls in response to rising incident reporting, which makes Cyber Essentials Plus a pragmatic choice for organisations processing large volumes of personal data (Information Commissioner’s Office, 2024).
At CyPro, we see three pragmatic triggers for choosing Cyber Essentials Plus: a contractual or insurer mandate, a high sensitivity or volume of data, and a device estate large enough that the Pathways or sampled device checks will be complex to evidence. When any trigger applies, start technical evidence collection at least 6 weeks before your assessment window.
For organisations unsure which level to pursue, our comparison guide lays out when CE+ is required by tenders or insurers and what the technical audit examines. See our Cyber Essentials vs Cyber Essentials Plus comparison and our Cyber Essentials Renewal guide for step by step prep and timelines (Cyber Essentials vs Cyber Essentials Plus, Renewing Cyber Essentials and Cyber Essentials Plus).
How much does Cyber Essentials Plus renewal cost in the UK in 2026?
Renewal for Cyber Essentials Plus in the UK typically ranges from £375 to £6,500 per year depending on scope and support level, with larger estates and managed options at the top end. The cyber essentials plus changes 2026 increase emphasis on evidence recency and sampling, which pushes some renewals toward consultancy-led pricing.
Price bands and what they include
Small organisations, 1 to 49 staff, usually pay between £375 and £900 in 2026 for a Cyber Essentials Plus renewal that covers remote sampling and certification management. Mid-market organisations, 50 to 499 staff, commonly see renewals between £1,200 and £3,500 when on-site sampling or hybrid audits are required. Enterprise renewals, 500+ staff, typically cost £3,500 to £6,500 because of larger sample sizes, multi-site checks and extended remediation support. These ranges reflect external audit time, evidence preparation and any follow-up remediation work.
Cost drivers and the 2026 changes
Major cost drivers are number of endpoints, remote or hybrid workforce, complexity of on-prem and cloud systems, and required auditor travel. The cyber essentials plus changes 2026 introduce stronger sampling and pathway options, which can increase audit time for complex estates. For evidence-heavy estates, expect higher consultancy hours for log exports, patch proof and multi-vendor checks, as noted in industry analysis such as the Verizon 2025 Data Breach Investigations Report and practical guidance mirrored by incident trends discussed by Mandiant.
At CyPro, we recommend budgeting for preparation work separately from the auditor fee: inventorying devices, exporting patch and MFA logs, and resolving obvious failures before the assessor arrives reduces the chance of a failed renewal and expensive retests. If you want a quick estimate, see our cost breakdown for Cyber Essentials and Plus on our pricing and cost page which shows example packages and what is included.
| Organisation size | Typical 2026 renewal range (GBP) | What's included |
|---|---|---|
| Small (1-49 staff) | £375 - £900 | Remote audit sampling, certification management, basic remediation advice |
| Mid-market (50-499 staff) | £1,200 - £3,500 | Hybrid or on-site sampling, evidence collation, remediation support |
| Enterprise (500+ staff) | £3,500 - £6,500+ | Multi-site checks, extended remediation, project-managed renewal |
What is the difference between Cyber Essentials Plus and adjacent capabilities like ISO 27001 or SOC assessment?
Cyber Essentials Plus is an audited technical baseline for device and configuration controls, while ISO 27001 is a full Information Security Management System (ISMS) and a SOC assessment evaluates operational controls and monitoring. Cyber Essentials Plus tests devices; ISO 27001 tests processes; SOC assessments test continuous detection and response.
Cyber Essentials Plus verifies device-level controls quickly and cheaply, ISO 27001 builds a management system for wider assurance, and SOC assessments prove continuous monitoring and incident response capability.
Scope and assurance level
Cyber Essentials Plus focuses on endpoint and configuration checks, using sampling and hands-on testing by an IASME-licensed assessor; it gives technical assurance at the device level. ISO 27001 covers risk management, policies, supplier management and continual improvement, producing organisation-wide evidence for auditors and tender panels. A SOC assessment (for example a SOC 2 style readiness or internal SOC health check) measures monitoring, detection and response, and is most relevant where 24x7 detection matters.
Cost, time-to-value and evidence
Cyber Essentials Plus is faster and cheaper to get in place, often yielding a certificate in weeks; ISO 27001 typically takes months and a larger programme budget. A SOC assessment requires ongoing tooling and people costs. In 2026 many UK procurement teams still accept Cyber Essentials Plus as minimum technical proof, while larger customers and regulated sectors ask for ISO 27001 or a formal SOC report (ENISA, 2025 and IBM X-Force, 2025 explain why attackers target credentials and endpoints).
When to pick which
Choose Cyber Essentials Plus if you need rapid, audited proof of basic technical controls for tenders or insurers, or if you want a short certification cycle. Choose ISO 27001 if you need process-level assurance, supplier governance and a certificated management system. Choose a SOC assessment when you must demonstrate continuous detection and response capability. For renewals after the cyber essentials plus changes 2026, treat CE+ as the fast path to technical assurance and ISO 27001 or SOC assessments as follow-on, higher‑assurance investments. Our practical guide on Basic Cyber Essentials explains the stepwise route from self-assessment to Plus (Basic Cyber Essentials).
Implication for UK organisations: use cyber essentials plus changes 2026 to decide whether you need quick audited technical proof or a longer ISMS project, and align your choice to procurement and insurer requirements rather than prestige alone.
How should you choose a provider for your Cyber Essentials Plus renewal?
Pick a provider who is IASME licensed, shows exactly how they sample devices and evidence, offers clear pricing and UK-based support, and has procurement and insurer references that match your sector.
For the cyber essentials plus changes 2026, that means asking for the assessor sampling method, the exact evidence they will request, and whether they will manage the re-test if sampling finds faults.
What to ask on day one
Ask the provider to confirm they hold an IASME licence and will use the current NCSC test specification, and get those promises in writing. Ask for the exact scope they will certify, how many endpoints and servers they will sample, and the format of evidence they expect (screenshots, logs, MDM output). The NCSC guidance on requirements clarifies what assessors may request, so demand alignment with that specification (Cyber Essentials Requirements for IT Infrastructure v3).
Pricing models and what they include
Compare one-off audit fees to managed renewals that include ongoing remediation and a retest window. Ask whether antivirus, patching and MFA checks are included in the price and whether remediation hours are charged separately. Our experience is that managed packages reduce the administrative risk of a lapsed certificate and smooth renewals for procurements and insurers.
Demand references from clients in your sector and ask for a copy of a redacted assessor report from a previous audit, so you can see how the provider records non‑conformities and retest outcomes. For sector risk context, note that the 2025 Verizon Data Breach Investigations Report highlights how basic controls such as MFA and patching prevent common incidents, which is exactly what Cyber Essentials Plus tests.
When you shortlist providers, score them on licence status, sampling transparency, fixed vs variable costs, local UK support and insurer or procurement references. That checklist turns the cyber essentials plus changes 2026 into a clear procurement question rather than a compliance guessing game.
Frequently asked questions
Do I need Cyber Essentials Plus if I already have Cyber Essentials Basic?
Key fact: Cyber Essentials is a self-assessment while Cyber Essentials Plus is an independent technical audit. Cyber Essentials Basic can be enough for very low-risk suppliers, very small teams and devices with limited third-party access. Many tenders, insurers and buyers ask for Plus when sensitive data is handled or device counts grow. Plan an upgrade within the three-month renewal window or schedule a Plus audit at renewal.
What is the Willow question set and why does it matter for my audit?
Key fact: Willow is the April 2026 update to the Cyber Essentials questionnaire published via IASME. Willow raises evidence expectations and clarifies how auditors sample devices and answers. Organisations must map Willow responses to live controls and keep sampled evidence readily available for assessors. Start preparing earlier in the renewal cycle to avoid scope creep during assessment.
How long does a Cyber Essentials Plus renewal typically take?
Key fact: A typical Cyber Essentials Plus renewal in 2026 takes four to eight weeks from a readiness check to certificate issuance. Timelines extend if there is a remediation backlog, a complex IT estate or on-site sampling scheduling. Fast-track options and managed monthly models reduce time to completion. Schedule renewals well before expiry, especially with the Willow questionnaire changes.
Can I outsource Cyber Essentials Plus renewal fully to a provider?
Key fact: Yes, providers can manage readiness assessments, evidence collection and assessor liaison for Cyber Essentials Plus renewals. Your organisation remains responsible for factual accuracy and delivering remediations. When choosing a provider, check their scope, evidence collection methods, estimated remediation hours and re-test SLAs. Managed models suit mid-market firms that lack in-house security staff.
What are common reasons organisations fail the CE Plus audit after the 2026 changes?
Key fact: Common failures after the 2026 changes include insufficient evidence for Willow questions, inconsistent secure configurations, missing patch records and weak malware controls. Sampling often uncovers unmanaged devices outside policy coverage. Most fixes are straightforward but need disciplined asset inventory and patching processes. Running a pre-audit checklist significantly reduces failure risk.