Avoiding the auto-fail under cyber essentials’ new rules

https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-2560-80.jpg

Cyber Essentials has always been the UK’s baseline cybersecurity standard.

It’s a practical floor designed to block common attacks and ensure business resilience when organizations implement them, rather than treating the scheme as lip service.

The April 2026 update raises the floor, introducing auto-fail outcomes for missing key controls, meaning that certain gaps now end an assessment immediately, rather than becoming items to fix later.

For a lot of organizations, that’s not just a compliance issue but a commercial one; as Cyber Essentials certifications are increasingly a requirement by customers and suppliers.

What actually changed in April 2026?

Three changes define the update to Cyber Essentials, with two aspects now resulting in an “auto-fail” if they are not met.

Firstly, patching deadlines are now strict requirements, with high-risk and critical security updates needing to be applied within 14 days of release across systems.

Second, multi-factor authentication has moved from a...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://cdn.theatlantic.com/thumbor/XRcDfEUMuAcwYSWnXS3dxsMld7A=/0x43:2000x1085/1200x625/media/img/mt/2026/10/2026_10_02_Robinsons_open_ai_safety_final/original.jpg

David Robinson, ex-OpenAI safety and policy: SV lacks a safety-centric culture; labs must study other fields' safety approaches; time for trial and error's over

Sponsor Posts Subquadratic: the LLM built for 12M-token reasoning — SubQ can reason across entire codebases and document sets in one pass with no RAG workarounds. Read how SubQ 1.1 Small holds near-perfect retrieval out to 12M tokens. Introducing Campus: The digital home for educational institutions — Every educational institution needs