Jon TamplinCyber Essentials Is No Longer a Once a Year Job

Cyber Essentials is no longer a once a year exercise. Jon Tamplin explains why v3.3 rewards organisations that can show their controls are working every day, not just on assessment day.

Passing Cyber Essentials used to be a date in the diary. Now it is a discipline.

When the v3.3 update took effect in April, most of the attention went to the headline changes: tougher rules on multi factor authentication, more cloud services in scope and a higher standard of technical evidence. A few months on, something more interesting is happening. The way organisations approach certification is changing.

The scheme itself is as important as ever. It underpins eligibility for many government and enterprise contracts, insurers look for it, and large organisations increasingly expect it of their suppliers. According to the NCSC, businesses running the Cyber Essentials controls make 92 percent fewer insurance claims.

But v3.3 has raised a question that catches many organisations out. Not "do you have the controls?" but "can you show they are working, everywhere, right now?"

The attacker does not care about your certificate

Threat actors go where the friction is lowest. They are not trying to defeat your strongest defences. They are hunting for the account that slipped through your MFA rollout or the laptop that missed its last three patches. Once they find it, that single weak point becomes their route into everything else.

This is why estate wide visibility sits at the centre of the new requirements. A security team that knows exactly which users, devices and applications exist, and what state each one is in, can find and fix weaknesses before an assessor or an attacker does. A team relying on last quarter's spreadsheet cannot.

Where certifications now fall down

In our work with organisations preparing for assessment under v3.3, four problem areas come up again and again:

Conditional access policies that do not do what everyone assumes they do Accounts nobody owns, including forgotten guest access Devices that have drifted outside their patching window SaaS tools in use that IT never sanctioned and cannot see

None of these is exotic. All of them are now capable of sinking a certification. And each one shares the same root cause: nobody could see it until it was too late.

Compliance as a byproduct, not a project

The most encouraging change since April is a shift in mindset. Rather than mounting a certification project every twelve months, more organisations are building towards a state where compliance evidence exists by default, because their estate is monitored continuously and gaps surface the moment they appear.

That approach does more than smooth the next assessment. It closes the window between a control failing and someone noticing, which is precisely the window attackers exploit. For larger estates, it is the only realistic way to keep thousands of devices inside patching windows and MFA enforced on every account, every day of the year.

ThreatAware was built for exactly this. By connecting agentlessly to the tools you already run, it shows you every user, device and application in real time and flags the moment a control stops working. When assessment day arrives, the proof is already there.

If your next Cyber Essentials renewal is on the horizon, do not wait for the assessor to find your gaps. Find them first.

*As featured in Computing Security.*

Secure Every Device in Your Network

Instantly uncover and protect every asset in your IT estate with ThreatAware.

Identify unknown devices, reconcile asset data across platforms, and eliminate security gaps to ensure continuous cyber hygiene.

Request Trial
App screenshot