
24 Apr The new “Willow” update to Cyber Essentials
-
The Cyber Essentials scheme, backed by the UK’s National Cyber Security Centre (NCSC), has long served as a key baseline for cybersecurity best practices among UK organisations. As of April 2025, the latest update—called the Willow version—introduces a number of important changes aimed at modernising the standard and addressing evolving threats and technologies.
In this blog, we’ll walk you through what’s changed and what it means for organisations seeking new certifications or renewals.
Password-less Authentication Now Recognised
One of the most forward-looking changes in the Willow update is the official recognition of password-less authentication. Organisations can now adopt methods such as biometrics, FIDO2 keys, or other cryptographic login mechanisms as compliant alternatives to traditional passwords—helping reduce the risk of credential-based attacks.
New Definitions and Enhanced Guidance
The updated standard includes clearer definitions and expanded support throughout the questionnaire.
- New definition for “Vulnerability fixes”: This now explicitly includes not only patches and updates but also configuration changes, registry fixes, scripts, or any vendor-approved method of resolving known vulnerabilities.
Take note
- Links to additional guidance: Throughout the standard, IASME has embedded direct links to official guidance, helping applicants better understand what is required for compliance.
This improvement is aimed at reducing ambiguity and making the self-assessment process more user-friendly.
To mirror this, we have provided some links to key information sources below:
Download the Willow Cyber Essentials Question Set (PDF)
Download the Willow Cyber Essentials Question Set (Excel)
Download the latest NCSC Requirements for Infrastructure (Version 3.2)
Download the Willow Cyber Essentials Test Specification
Cloud Services Are Always in Scope
A major clarification in the Willow version is that cloud services can never be excluded from scope. This means all Software-as-a-Service (SaaS), Infrastructure-as-a-Service (IaaS), and Platform-as-a-Service (PaaS) used by the organisation must be considered as part of your Cyber Essentials assessment.
This change reinforces the idea that your security posture is only as strong as your weakest link—including your cloud providers.
Updated and Reworded Question Set
Many of the assessment questions have been revised for clarity, and some now include additional requirements:
- Reworded for clarity:
- “Have you reviewed your firewall rules in the last 12 months?”
- “Are all high-risk or critical security updates and vulnerability fixes for operating systems, routers, and firewall firmware installed within 14 days of release?”
- New inclusions:
- Specific technologies such as Virtual Desktop Infrastructure (VDI) servers are now directly referenced in relevant questions.
- Expanded detail in guidance:
- Each question now includes more thorough explanations of what’s expected, helping ensure that applicants correctly interpret and meet each requirement.
What about Cyber Essentials Plus?
What This Means for You?
Whether you’re a new applicant or looking to renew your certification, the Willow version represents a meaningful shift in how Cyber Essentials is applied and understood:
- More alignment with modern infrastructure (especially cloud and remote environments)
- Increased clarity and transparency throughout the assessment process
- Stronger encouragement for secure-by-default practices, such as password-less logins and timely patching
how can we help?
At InfoShelter, we’re here to make your transition to the new Willow version of Cyber Essentials as smooth and stress-free as possible. Whether you’re applying for the first time or renewing your certification, our team of cybersecurity experts can guide you through every stage — from initial gap assessments and policy reviews to technical remediation and pre-audit checks. We ensure your systems, cloud services, and documentation meet the latest requirements, including those for Cyber Essentials Plus.
With InfoShelter by your side, you’ll be fully prepared, fully compliant, and fully confident on your path to certification.
Contact us using the form on this page to enquire about our certification services.
The new “Willow” update to Cyber Essentials
The Cyber Essentials scheme, backed by the UK’s National Cyber Security Centre (NCSC), has long se...
Balancing confidentiality with accuracy and accessibility using the NHS’ IGF
Since the introduction of GDPR (General Data Protection Regulation) and the Data Protection Act 2018...
Mobile Phone Theft – The Hidden Dangers and How to Protect Yourself
Mobile Phone Theft: A Growing Threat Mobile phone theft is not only common but also becoming increas...
Evolution of Phishing – what AI is doing to revolutionise social engineering
Phishing started as a basic tactic for attackers to exploit our trust. They were often directionless...
Going the extra mile with Cyber Essentials Plus
Most companies are aware of the benefits of obtaining Cyber Essentials certification for their busin...
Charity Cyber Essentials awareness month: strengthening cybersecurity for charities
This October, InfoShelter is excited to join forces with IASME and the National Cyber Security Centr...
Sorry, the comment form is closed at this time.