How’s your mood today?

Resource

Cyber Essentials 2026: Why Your Cloud Services Cannot Be Left Out

What Cyber Essentials v3.3 means for cloud services, shared security responsibilities, passwordless authentication, backups, and certification scope.

Bloom Web Article Published July 30, 2026

Cyber Essentials changed on 27 April 2026. The latest requirements, version 3.3, make an important point explicit: if your organisation’s data or services are hosted in the cloud, those cloud services cannot simply be excluded from the certification scope.

For a modern small business, that can include Microsoft 365, Google Workspace, cloud storage, hosted accounting, customer-management systems, web applications, virtual servers, and many other subscriptions used every day.

What Is Cyber Essentials?

Cyber Essentials is the UK government-backed certification scheme designed to protect organisations against common cyber attacks. It is organised around five technical control areas:

  1. Firewalls.
  2. Secure configuration.
  3. Security update management.
  4. User access control.
  5. Malware protection.

The National Cyber Security Centre publishes the current Cyber Essentials resources and requirements. Version 3.3 applies to applications started from 27 April 2026; applications begun before then can continue under version 3.2.

What Changed in Version 3.3?

The NCSC’s April 2026 requirements identify five headline changes:

  • A definition of cloud services has been added.
  • The definition of passwordless authentication now includes FIDO2.
  • The requirements state definitively that cloud services cannot be excluded from scope.
  • The Software Security Code of Practice is introduced in the software-development section.
  • The importance of backing up data is emphasised.

The scope criteria also no longer use the phrase “untrusted connections”. The practical focus remains on the devices, software, networks, and cloud services that connect through the internet and support the organisation’s work.

What Counts as a Cloud Service?

Version 3.3 defines a cloud service as an on-demand, scalable service hosted on shared infrastructure, accessible over the internet, and used through an account that stores or processes organisational data.

The document groups cloud services into three familiar models:

  • Infrastructure as a Service: Virtual servers and network components that the customer largely configures and manages.
  • Platform as a Service: A managed platform on which the customer deploys or manages its own applications.
  • Software as a Service: Hosted applications such as email, storage, collaboration, or business software configured by the customer.

Even when the supplier operates most of the technology, the applicant remains responsible for confirming that the required controls are implemented.

The Shared-Responsibility Problem

A cloud provider may patch the underlying servers and protect its network, but the customer still decides who can sign in, which accounts are administrators, whether multi-factor authentication is enabled, and how securely the service is configured.

For software-as-a-service platforms, small businesses should expect to retain responsibility for user access control and part of secure configuration. Where a provider implements a control, Cyber Essentials expects that commitment to be supported through contractual terms or referenced documents such as a security statement, privacy statement, or shared-responsibility model.

“The supplier handles security” is therefore not enough evidence. You need to know which part the supplier handles and which settings remain yours.

Cloud Checks to Complete Before Applying

  1. Create an application inventory. Include paid subscriptions, free tools, browser extensions, dormant systems, and services bought directly by individual departments.
  2. Identify every business account. Record owners, administrators, users, guests, contractors, service accounts, and emergency accounts.
  3. Enable appropriate MFA. Prioritise administrators and internet-accessible cloud services, using phishing-resistant options where supported.
  4. Remove unnecessary access. Disable leavers, unused accounts, old integrations, and excessive administrator privileges.
  5. Review security settings. Do not assume the default configuration meets the scheme’s requirements.
  6. Collect supplier evidence. Keep links or documents explaining patching, malware protection, infrastructure controls, and shared responsibilities.
  7. Check third-party administration. Accounts owned by your organisation remain in scope when used by a managed-service provider or contractor.
  8. Document the agreed scope. If certification covers a subset, it must be clearly defined, separately managed, and agreed with the certification body.

Passwordless Authentication and FIDO2

Version 3.3 updates the passwordless definition to include FIDO2 authenticators. This aligns the scheme more clearly with passkeys and physical security keys that use modern phishing-resistant authentication.

Passwordless does not mean authentication-free. The identity still needs to be established securely, and devices, recovery methods, account enrolment, and revocation must be controlled.

Backups Are Emphasised, but Not a Certification Control

The new document gives backups greater prominence while stating that backing up data is not one of the five Cyber Essentials technical requirements. The NCSC strongly recommends an appropriate backup solution, regular or automatic copies, and disconnecting removable backup media when it is not in use.

This distinction matters: passing Cyber Essentials does not prove that the business can recover from ransomware, accidental deletion, or a failed cloud service. Recovery still needs its own plan and testing.

What About Websites and Custom Software?

Publicly available commercial web applications are in scope by default. Bespoke and custom components of web applications sit outside the scheme’s direct technical scope, but they still need robust development and testing. Version 3.3 points organisations toward the UK Software Security Code of Practice for that work.

Certification should not be treated as a substitute for application-security testing, secure development, vulnerability management, or an incident-response plan.

The Bottom Line

Cyber Essentials v3.3 reflects how small businesses now operate: business infrastructure is spread across laptops, phones, home working, SaaS platforms, cloud hosting, and third-party administrators.

Before applying, inventory the cloud services that hold or process business data, confirm the shared-responsibility model, secure the accounts you control, and gather evidence for the controls delivered by suppliers. The cloud may be outsourced, but responsibility for using it securely is not.