From 28 April 2026, Cyber Essentials v3.3 requires a director or board-level representative to confirm that the organisation will maintain compliance with Cyber Essentials controls throughout the certification period.
This change shifts Cyber Essentials from a technical checklist to a governance responsibility. Leadership must now ensure scope is defined, access is controlled, updates are maintained, and compliance does not drift between renewals.
For SMEs, this means cyber security is no longer delegated solely to IT. It becomes a board-level accountability issue linked to operational risk, regulatory exposure, supply chain credibility, and insurance expectations.
Organisations preparing for 2026 certification should focus on ownership, scope clarity, privileged access review, and establishing a structured compliance rhythm.