Why October matters for Cyber Essentials: What MSPs need to know before the deadline

Written by Eve Oliver
Sept 29, 2026 - 4 minute read

The Cyber Essentials v3.3 transition window closes in October 2026. Eve from Cyber Tec Security explains what MSPs need to check now to keep clients on track.

If you're an MSP with clients working towards Cyber Essentials, October is a month you shouldn't let slip by unnoticed. There's a deadline landing this month, and if you're managing certification on behalf of several clients, it's worth getting ahead of it rather than fielding a panicked call in the last week of October.

The CyberTec team have put together a straightforward explainer - what's actually changing, who it affects and what I'd be checking if I were managing a client base through this right now.

What's actually happening

Cyber Essentials moved to a new version of its requirements - version 3.3 - in April 2026. That's not unusual in itself; the scheme is reviewed regularly and requirements change all the time to keep pace with how organisations actually work.

What matters for this October specifically is the transition arrangement that came with it. Organisations with an assessment account created before 26 April 2026 were given a six-month window to complete their certification under the previous requirements, rather than being switched onto v3.3 immediately. That window closes on 26 October 2026.

In practice, that means anyone who started an assessment before that date and hasn't yet finished has a hard deadline this month. After it passes, any unfinished assessment will need to move onto the current v3.3 requirements - which, depending on what's changed, could mean revisiting answers that were already prepared under the old question set.

Anyone starting a fresh assessment now is already working to v3.3, so there's no transition risk to worry about there. It's specifically the clients who started earlier in the year, and haven't crossed the finish line yet, who need attention.

Why this is particularly an MSP issue

If you're managing Cyber Essentials for one organisation, a deadline like this is relatively easy to keep on your radar. If you're an MSP supporting a portfolio of clients, some of whom may have started assessments months ago and quietly stalled, it's a different story.

In my experience, assessments don't usually stall because someone's decided not to bother. They stall because a self-assessment questionnaire landed with a client's IT contact, got partially filled in, and then got parked behind more urgent day-to-day priorities. Weeks turn into months, and nobody's actively tracking that a deadline is approaching in the background.

That's exactly the kind of gap an MSP is well placed to catch - but only if you're actively looking for it. I'd treat this month as a prompt to check, not assume.

What I'd be checking this month

If you're supporting clients through Cyber Essentials, here's where I'd start:

1. Identify who has an open or incomplete assessment. Pull together a list of every client with a Cyber Essentials assessment in progress, and check when their account was created. Anyone who started before 26 April 2026 and hasn't completed is the priority group.

2. Find out how close they actually are. "In progress" can mean anything from "a few questions left" to "barely started." A quick check-in with each client's IT contact will tell you whether they're on track to finish before the 26th, or whether they need a more direct push.

3. Flag it clearly and early - don't wait for them to ask. This is where MSPs genuinely add value beyond the technical side. A short, proactive message - "your Cyber Essentials window closes on 26 October, here's where things stand" - does two things: it protects the client from an avoidable setback, and it reminds them why having you involved matters.

4. Know what happens if they miss it. If a client doesn't complete before the deadline, they'll need to continue under the v3.3 requirements. That's not a failure, and it's not the end of the world, but it likely means going back through some of the questionnaire under the updated question set, so it's worth setting that expectation clearly rather than letting it come as a surprise.

5. For anyone not yet started, get them started on v3.3 now. There's no benefit in referencing the old requirements for a fresh start — they'll be assessed against v3.3 regardless of when they begin, so there's nothing to lose by starting straight away.

Beyond the deadline: the bigger opportunity

I'd also say this is a good moment to use Cybersecurity Awareness Month more broadly, not just to chase down a deadline. October gives you a natural, non-salesy reason to check in with clients about where they stand on the basics - MFA coverage, patch cycles, dormant access - the sort of things that Cyber Essentials is built around and that stop the vast majority of common, opportunistic attacks.

For clients who don't have Cyber Essentials at all yet, this is also a reasonable moment to raise it, particularly if they're chasing tenders or supply chain contracts where certification is increasingly expected rather than optional.

Where Cyber Tec fits in

At Cyber Tec Security, we work directly with MSPs supporting clients through Cyber Essentials - whether that's helping you track where clients stand against this transition deadline, clarifying how the v3.3 requirements apply to a specific environment, or supporting a client through Cyber Essentials Plus where the technical testing adds another layer to manage.

If you've got clients you're not entirely sure are on track for the 26 October deadline, it's worth finding out now rather than in the last few days of the month. Get in touch and we can help you work out where things stand.

Topics: Cyber Essentials, Partner Program, MSP

author

More by Eve Oliver

Related articles
How Cyber Certification Is Changing the MSP Role

An MSP that knows their client and their systems can help them achieve appropriate certification and improved security for their business.

Why DCC Matters Across the Entire Defence Supply Chain

The MOD wants all industry partners to reach DCC Level 0 by 31 December 2026. See what Defence Cyber Certification means for suppliers at every tier.

Why Your Suppliers Could Be Your Biggest Cyber Risk

Suppliers are a common route for attackers targeting enterprise organisations; if your suppliers don't have robust security, you may face a breach.