Cyber Essentials

Cyber Essentials April 2025: What’s Changed and What Your Business Needs to Know

As the cybersecurity threat landscape continues to evolve, so must the standards that protect UK organisations. From April 28th, 2025, Cyber Essentials and Cyber Essentials Plus certifications will be assessed using Version 3.2 of the requirements and the new “Willow” self-assessment questionnaire. The updates, while not drastic, bring important refinements that reflect today’s modern working practices, authentication technologies, and the growing demand for international alignment.

Key Changes in the 2025 Update

1. Embracing Passwordless Authentication

The 2025 update officially recognises passwordless login methods. Biometrics (such as fingerprint and facial recognition), security keys, and one-time codes are now accepted as primary authentication mechanisms. This move acknowledges that passwords, while convenient, no longer offer sufficient protection against sophisticated cyber threats. Businesses are encouraged to implement multi-factor and passwordless options, helping to reduce risks related to password reuse and phishing.

2. Updated Remote Work Terminology

Cyber Essentials now replaces “home working” with “home and remote working.” This terminology update broadens the scope to include all environments where employees work outside the traditional office—including cafes, hotels, co-working spaces, and public transport. Organisations will need to demonstrate robust security controls for users working on untrusted networks, ensuring company data remains protected regardless of location.

3. Broader Definition of Vulnerability Fixes

The term “patches and updates” has been replaced with the more inclusive “vulnerability fixes.” This covers not only software patches but also registry tweaks, scripts, configuration changes, and any other vendor-approved method for mitigating known vulnerabilities. By recognising diverse remediation practices, the scheme promotes timely and effective threat response.

4. Refined Terminology and Questionnaire Updates

Minor terminology updates include renaming “plugins” to “extensions” and refining the definition of “software.” The self-assessment process now uses the Willow questionnaire, which modernises and clarifies requirements for applicants.

What Do These Changes Mean for Your Business?

  • If you are already Cyber Essentials certified, review your authentication mechanisms and remote working policies.
  • Ensure all devices—wherever they are used—meet the scheme’s updated security requirements.
  • Validate your patch management process includes all forms of vulnerability fixes.
  • Start using the Willow questionnaire for new or renewal applications.

Final Thoughts

The April 2025 Cyber Essentials update may appear subtle, but its impact is significant. By adopting these changes early, your business can stay ahead of compliance requirements and enhance your overall cybersecurity posture. For expert guidance on implementing these updates or navigating the certification process, reach out to IntelloSec —we’re here to help you turn compliance into competitive advantage.