What are the Cyber Essentials Plus patching requirements?

As of 24 January 2022, software updates need to be applied within 14 days of release, where the update fixes address vulnerabilities described by the vendor as ‘critical’ or ‘high risk’ or where no level of vulnerabilities is provided by the vendor, or where the fixes address vulnerabilities with a CVSS v3 score of 7 or above.

For password-based authentication in Internet-facing services, you must:

  • Protect against brute-force password guessing by using at least one of the following methods:
    • Lock accounts after no more than 10 unsuccessful attempts
    • Limit the number of guesses allowed in a specified time period to no more than 10 guesses within 5 minutes
  • What is the required Cyber Essentials password policy?
  • Set a minimum password length of at least 8 characters and use automatic blocking of common passwords via a deny list
  • Set a minimum password length of at least 12 characters
  • Use multi-factor authentication
  • Not set a maximum password length
  • Change passwords promptly when you know or suspect that you have been compromised
  • Implement a password policy that tells users:
    • How to avoid choosing obvious passwords (such as those based on easily discoverable information like the name of a favourite pet)
    • Not to choose common passwords — this could be implemented by technical means, using a password deny list
    • Not to use the same password anywhere else, at work or at home
    • Where and how they may record passwords to store and retrieve them securely (for example, in a sealed envelope in a secure cupboard), whether they may use password management software, which software, and how to use it
    • Which passwords they must memorise.

You are NOT required to:

  • Enforce regular password expiry for any account (we actually advise against this)
  • Enforce password complexity requirements.
Our assessor has been amazing and a pleasure to work with on the assessments. He always goes above and beyond to help, reassure, and advise, and is an asset to the company.
IT company
Apply for Cyber Essentials certificationApply for Cyber Essentials Plus

Mitigating Cyber Risks: Why Cyber Essentials Matters More Than Ever

Published on
16 Apr
2026

URM’s blog highlights the growing threat to cyber security in the UK and the importance of the Cyber Essentials scheme in mitigating these risks.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/4/2026
Cyber Essentials Requirements Update

URM’s blog breaks down the latest changes to the Cyber Essentials requirements and outlines why these updates matter for organisations seeking certification.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/4/2026
Cyber Essentials Update 2026

URM’s blog breaks down key changes to the Cyber Essentials scheme coming into force on 27 April 2026, including the new Danzell Question Set.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
9/4/2026
NHS Cyber Security Open Letter: What Does it Mean for Suppliers?

URM’s blog explains the recent open letter to suppliers issued by the NHS, what it means, why it matters, and the practical steps you can take to prepare.

Read more
"
Our experience with URM was all around great and seamless, starting with our account manager who organised everything and was very accommodating, working around our schedule and fitting us in as soon as we wanted. This continued with our assessor for the CE questionnaire part; he was very helpful, taking the time to explain some aspects that were a bit unclear to me and guiding me the whole way through. The same was true of our assessor for the CE+, who took the time to answer any questions I had beforehand and guide me through elements that I was unfamiliar with. During the assessment, he was very helpful, made the process very easy and guided me through some points that needed some additional set up in order to ensure a successful process. This was our first year working with URM and I am sure we’ll be talking again next year. Thank you for all your help!
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.