Upcoming Changes to Cyber Essentials and IASME Cyber Assurance Standards

Upcoming Changes to Cyber Essentials and IASME Cyber Assurance Standards

First seen 13 Mar 2026, 21:56 UTC IasmeClaranetBizgateway.UkConsciaBcn+64 24.9

Article Content

Browse articles
ThreatCluster

On April 27, 2026, significant updates to the Cyber Essentials and Cyber Essentials Plus certification schemes will be implemented, including the introduction of version 3.3 of the Requirements for IT Infrastructure. The self-assessment process will be renamed to 'Danzell' to better reflect the evolving cyber landscape. These updates aim to enhance security measures against modern cyber threats, particularly by mandating multi-factor authentication (MFA) for all cloud services. The Cyber Essentials scheme, which has been revised multiple times since its launch in 2014, focuses on reducing the risk of security incidents from opportunistic attacks. Additionally, IASME Cyber Assurance provides a structured approach to cyber resilience through fourteen themes organized into four categories, helping organizations of all sizes improve their cybersecurity posture. Certification under IASME also demonstrates compliance with legal requirements such as GDPR. The changes are designed to ensure that both standards remain relevant and effective in the face of evolving cyber threats.

Key Points: • Cyber Essentials v3.3 will launch on April 27, 2026, introducing mandatory MFA for cloud services. • The self-assessment process will be renamed to 'Danzell' to reflect updates in the certification scheme. • IASME Cyber Assurance consists of fourteen themes aimed at improving cyber resilience for organizations.

Timeline

2026-03-13
Announcement of changes to Cyber Essentials and IASME Cyber Assurance
2026-04-27
Implementation of Cyber Essentials v3.3 and Danzell process