Cyber Essentials Willow: What the April 2025 Requirements Mean for SMEs

IT administrator reviewing five security controls protecting a small business network

Version 3.2 of the Cyber Essentials requirements, known as Willow, took effect on 28 April 2025. It keeps the familiar five technical controls but updates the wording to reflect passwordless sign-in, remote work and the different ways vendors now fix security vulnerabilities.

The official NCSC Cyber Essentials resources remain the definitive reference. The practical message for SMEs is that security management must cover the complete working environment, not only computers inside the office.

The five controls have not changed

Cyber Essentials still focuses on firewalls, secure configuration, security update management, user access control and malware protection. These controls block many common attacks when they are implemented consistently across devices, cloud services and users.

What Willow added or clarified

Passwordless authentication

The guidance now explicitly recognises passwordless methods such as biometrics, physical security keys, one-time codes and push approvals. Passwordless does not mean authentication-free: the method must still provide strong assurance and be managed throughout the user lifecycle.

Vulnerability fixes are broader than patches

A vendor may fix a serious vulnerability with a configuration change, script, registry adjustment or another approved mechanism rather than a conventional software update. Willow makes it clear that these fixes are part of security update management. High-risk fixes still need prompt action, normally within the scheme’s 14-day window.

Software has a wider meaning

Operating systems and desktop applications are only part of the picture. Browser extensions, scripts, libraries, network software and router or firewall firmware can all be in scope. An accurate asset and software inventory is therefore essential.

Remote working is normal working

The updated terminology reflects hybrid organisations. Corporate and bring-your-own devices that access business data are generally in scope, wherever they are used. If the organisation does not control the network, the endpoint needs its own correctly configured firewall and appropriate security controls.

Prepare before starting the assessment

  1. Confirm the scope, including cloud services, mobile devices and remote workers.
  2. Remove unsupported software and record vendor support dates.
  3. Verify that critical vulnerability fixes are applied within policy.
  4. Review administrator accounts, third-party access and multi-factor authentication.
  5. Check firewall rules and remove services that no longer have a business purpose.
  6. Collect evidence as you work rather than immediately before submission.

Cyber Essentials is not a one-off tidy-up. The strongest approach is to make its controls part of normal managed IT operations.

MSP247 can assess your environment, close technical gaps and help maintain the controls across Windows, macOS, mobile devices, cloud services and networks. Explore our managed IT support or contact us to discuss Cyber Essentials readiness.

A practical technology partner

Clear ownership across your whole IT environment

MSP247 brings day-to-day support, security, connectivity and planning together so your team has one accountable route for help.

Whole-environment support

Windows, Mac, iPhone, iPad, Chromebook, servers, networks and cloud services supported as one working environment.

Yorkshire coverage

Responsive remote support with planned on-site assistance across York, Leeds and the wider Yorkshire region.

A clearly agreed scope

Responsibilities, priorities, escalation routes and available response arrangements are explained before service begins.

Security and continuity

Accounts, devices, backups and connectivity resilience are reviewed together instead of as isolated products.

This site uses analytics.