All guides

Scheme update

Cyber Essentials v3.3 changes explained

A practical overview of the Cyber Essentials v3.3 changes UK small businesses should prepare for.

5 min read

A tighter definition of the modern estate

Cyber Essentials v3.3 reflects the way smaller organisations now work: cloud services, remote access and mobile devices are part of normal operations, not edge cases. Preparation therefore starts with an accurate picture of every device, account, service and network that can reach organisational data.

The practical consequence is simple: assumptions that were previously left unstated now need to be checked and described. A clean inventory is the foundation for every control that follows.

Cloud services need deliberate treatment

Business cloud services sit inside the assessment scope. That includes obvious platforms such as Microsoft 365 and less obvious services used by individual teams. Social media accounts used for business can matter too.

Build one register, assign an owner to every service and record whether multi-factor authentication is available and enforced. This makes the later access-control answers far easier to support.

Unsupported technology and slow patching are critical

Support status now needs to cover operating systems and the firmware running on routers and firewalls. High-risk security updates need a reliable deployment process, not a best-effort habit.

  • Check vendor support dates for devices, operating systems and firmware.
  • Make sure critical and high-risk updates can be applied inside the required window.
  • Replace, remove or properly segregate technology that cannot be supported.

How to prepare

Start with evidence rather than optimistic answers. Export device and account inventories, review update policies, list every cloud service and test MFA enforcement. Kelvane Comply is being built to turn those checks into a guided readiness verdict and prioritised remediation plan.