Claranet Upcoming Changes to Cyber Essentials and IASME Cyber Assurance Standards
Article Content
- •Cyber Essentials v3.3 will launch on April 27, 2026, introducing mandatory MFA for cloud services.
- •The self-assessment process will be renamed to 'Danzell' to reflect updates in the certification scheme.
- •IASME Cyber Assurance consists of fourteen themes aimed at improving cyber resilience for organizations.
On April 27, 2026, significant updates to the Cyber Essentials and Cyber Essentials Plus certification schemes will be implemented, including the introduction of version 3.3 of the Requirements for IT Infrastructure. The self-assessment process will be renamed to 'Danzell' to better reflect the evolving cyber landscape. These updates aim to enhance security measures against modern cyber threats, particularly by mandating multi-factor authentication (MFA) for all cloud services. The Cyber Essentials scheme, which has been revised multiple times since its launch in 2014, focuses on reducing the risk of security incidents from opportunistic attacks. Additionally, IASME Cyber Assurance provides a structured approach to cyber resilience through fourteen themes organized into four categories, helping organizations of all sizes improve their cybersecurity posture. Certification under IASME also demonstrates compliance with legal requirements such as GDPR. The changes are designed to ensure that both standards remain relevant and effective in the face of evolving cyber threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (89)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…