Cyber Essentials in 2025 October 31, 2024 – Posted in: Cyber Security, News – Tags: , , ,

What changes are coming to Cyber Essentials in April 2025?

The good news is there are no major updates to what you’ll need to do to meet for next year. The IASME are:

  • Introducing passwordless authentication options.
  • Requiring stricter vulnerability management protocols.
  • Making changes to how they describe things.

Passwordless Authentication

From 2025 IASME will recognise passwordless authentication as a secure access method in the same way it does multi-factor authentication. Passwordless authentication methods include: Security keys and tokens like physical devices like USB keys, biometric data like fingerprints or facial recognition, one-time passcodes sent via text or email or push notifications sent via an app on your phone.

Essentially this just means you have some extra options available and your staff are able to use password free authentication methods.

Terminology Changes

IASME is making changes to their wording and terminology to help ensure you understand what’s being asked of you. They are replacing the word plugins with extensions to improve clarity. Home working is changing to home and remote working to cover staff working in places like coworking spaces, libraries or cafes as well as at home.

This won’t affect your submission beyond making sure you make sure you include anyone working from the road in your protocols.

Vulnerability Management

The requirements for vulnerability management will be stricter as of next year. At the moment you’re expected to to apply patches for vulnerabilities considered ‘high’ or ‘critical’ on the CVSS score scale. Next year IASME is rewording from patches and updates to vulnerability fixes to recognise that not all fixes are software patches. You’ll be expected to eliminate vulnerabilities using any and all vendor-approved recommendations including registry fixes and configuration changes or scripts.

This is the change most likely to impact your assessment. You’ll need to talk to your IT company about what you can do internally and what you expect from them to make sure your business is secure.