
New Cyber Essentials Requirements 2025: What Defence Contractors Need to Know
The latest changes to Cyber Essentials certification and what they mean for MoD suppliers and contractors.

David Broadbent
23 Aug 2025
The latest changes to Cyber Essentials certification and what they mean for MoD suppliers and contractors.
David Broadbent
23 Aug 2025
The Cyber Essentials scheme has undergone significant updates for 2024, with important implications for defence contractors and MoD suppliers. These changes reflect the evolving threat landscape and the increasing importance of robust cybersecurity measures in the defence supply chain.
This guide will break down the key changes and provide practical steps for ensuring your organisation remains compliant with the updated requirements.
The 2021 updates to Cyber Essentials focus on three main areas:
With the increasing use of mobile devices in business operations, the new standards place greater emphasis on mobile device management (MDM) and bring-your-own-device (BYOD) policies. This reflects the growing recognition that mobile devices represent a significant attack vector.
Key changes include:
As businesses increasingly move to cloud-based systems, the 2024 standards include updated requirements for cloud security configurations and multi-factor authentication (MFA). These changes ensure that cloud environments are properly secured against common attack vectors.
** Notable updates: **
The new standards include enhanced requirements for understanding and managing supply chain security risks. This reflects the growing recognition that attackers often target organisations through their suppliers and partners.
These changes have important implications for businesses in the defence supply chain:
Many MoD contracts now require Cyber Essentials certification as a prerequisite. The updated standards mean that defence contractors must demonstrate compliance with these new requirements to maintain their eligibility for government contracts.
Cyber Essentials certification is no longer optional for defence contractors. It's become a fundamental requirement that demonstrates your commitment to protecting sensitive information and maintaining the security of the defence supply chain."
— Ministry of Defence Procurement Guidelines 2024
Existing Cyber Essentials certifications remain valid until their expiry date. However, when renewing, organisations will need to meet the new standards. It's recommended that defence contractors begin planning for these updates 3-6 months before their current certification expires.
If you're a defence contractor or MoD supplier, now is the time to:
The updated Cyber Essentials scheme represents an important step forward in protecting the defence supply chain. By staying ahead of these changes, defence contractors can ensure they remain competitive and compliant in an increasingly security-conscious marketplace.
Continue exploring our cybersecurity insights
The latest changes to Cyber Essentials certification and what they mean for MoD suppliers and contractors.
David Broadbent
23 Aug 2025
A comprehensive guide to GDPR requirements and how small businesses can achieve compliance without breaking the bank.
David Broadbent
15 Aug 2025
Ransomware attacks are increasing at an alarming rate. Learn the essential steps to protect your business from this growing threat.
David Broadbent
8 Aug 2025