UK NCSC Cyber Essentials — Requirements for IT Infrastructure v3.3 (April 2026)

UK government-backed certification, required for many public-sector contracts. Five technical control themes. v3.3 applies to assessments registered from 26 April 2026 and defines passwordless authentication explicitly around "FIDO2 authenticators… security keys or tokens", with "a physically separate token" listed as an accepted MFA factor.

UK organizations, public-sector suppliers, MOD supply chain

4

control domains mapped

35

products applicable

11

other frameworks cross-mapped

Official doc

UK NCSC Cyber Essentials — Requirements for IT Infrastructure v3.3 (April 2026)

CE-4 User Access Control — passwordless authentication defined around FIDO2 authenticators and security keys; a physically separate token is an accepted MFA factor

Phishing-resistant MFA using hardware security keys. Software TOTP and SMS are explicitly excluded from "phishing-resistant" in NIST 800-63B and most modern framework guidance.

CE-1 Firewalls — boundary firewalls and internet gateways protecting in-scope devices

Stateful firewall with IPS at the network perimeter. All inbound/outbound traffic inspected with Suricata rule sets. VPN gateway replaces consumer VPN dependency.