9 April 2026
What’s Changing, and What It Means For Your Organisation
IASME has introduced a series of updates to Cyber Essentials which come into effect from April 2026.
These changes do not fundamentally alter the scheme itself. However, they do tighten expectations around how controls are applied, evidenced, and maintained – particularly in areas such as patching, MFA, and cloud services.
A key shift is the move towards defined remediation expectations, with a 14-day window now expected to be consistently met. This reduces flexibility and places greater emphasis on ongoing control, rather than point-in-time preparation ahead of certification.
For many organisations, this means:
- Less tolerance for inconsistency across systems
- Greater importance on preparation ahead of renewal
- Increased focus on maintaining a continuous state of compliance
In practical terms, environments that are actively managed and monitored will move through certification with significantly less friction than those relying on periodic fixes.
How Redpalm Are Supporting This Transition
We are already working with clients to assess the impact of these changes ahead of renewal, ensuring that any gaps are identified early and addressed in a structured way.
Alongside this, our Vulnerability Management as a Service (VMaaS) provides a continuous operational control layer behind Cyber Essentials.
This includes:
- Ongoing visibility of vulnerabilities across all devices
- Patch validation and remediation tracking aligned to defined timeframes
- Structured reporting to maintain clarity and control
- Alignment with UK security standards beyond certification alone
This approach ensures that compliance is not treated as a one-off exercise, but as something maintained consistently throughout the year.
Full Breakdown of the Changes
The full update, including key areas of change and practical impacts, is outlined here:
What To Do Next
No immediate action is required. Your dedicated Client Manager will be in touch ahead of your next renewal to guide you through any required changes.
If your certification is approaching, we recommend allowing additional time for preparation and avoiding assumptions that previous submissions will pass unchanged.
If you would like a clearer view of your current position, or to see how VMaaS supports ongoing compliance, we can arrange a short walkthrough.