UK government-backed certification, required for many public-sector contracts. Five technical control themes. v3.3 applies to assessments registered from 26 April 2026 and defines passwordless authentication explicitly around "FIDO2 authenticators… security keys or tokens", with "a physically separate token" listed as an accepted MFA factor.
UK organizations, public-sector suppliers, MOD supply chain
4
control domains mapped
35
products applicable
11
other frameworks cross-mapped
UK NCSC Cyber Essentials — Requirements for IT Infrastructure v3.3 (April 2026)
Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.
Products that satisfy this control:
Hardened mobile OS with per-app sensor controls, verified boot, and no background telemetry. Satisfies mobile device management and bring-your-own-device security requirements.
Products that satisfy this control:
Measured boot chain verified on every power-on. Any firmware modification — supply chain implant, evil-maid attack, or malicious update — fails attestation before the OS loads.
Products that satisfy this control:
Stateful firewall with IPS at the network perimeter. All inbound/outbound traffic inspected with Suricata rule sets. VPN gateway replaces consumer VPN dependency.
Products that satisfy this control: