Cyber Essentials: Transitioning from the Montpelier to Willow Question Set

As of April 28, 2025, the Cyber Essentials certification process will undergo an update with the introduction of the Willow question set, replacing the previous Montpelier version. This new revision, conducted by the National Cyber Security Centre (NCSC) in collaboration with IASME and certification bodies, aims to ensure the scheme remains effective against evolving cyber threats.

In this blog, we’ll outline the key changes, their implications for your business, and how ramsac can assist you in navigating this transition seamlessly.

The Willow question set introduces several important updates to the Cyber Essentials requirements:

  • Home and Remote Working: The terminology has been updated from “home working” to “home and remote working” to encompass modern work environments, including untrusted networks like cafes and hotels.
  • Network Equipment Specification: Applicants are now required to list only relevant network equipment, specifically firewalls and routers, including their make and model. This change aims to prevent the unnecessary inclusion of devices such as hubs and switches.
  • Passwordless Authentication: The scheme now accepts passwordless authentication methods, provided they adhere to recognised standards. Acceptable methods include:
    • Biometric authentication
    • Security keys or tokens
    • One-time codes
    • Push notifications
  • Software Licensing and Updates: There is a new emphasis on ensuring all in-scope software and cloud services are properly licensed. Additionally, organisations must apply configuration changes or registry fixes, as advised by vendors, to mitigate high-risk vulnerabilities, not just standard software updates.
  • Access Control and Least Privilege: The updated requirements stress the implementation of the principle of least privilege, ensuring that staff have only the necessary access rights to perform their current job functions.

Organisations seeking to renew their Cyber Essentials certification after 28th April 2025, will be evaluated against the Willow question set.

There will be a grace period of 6 months so if Basic is purchased before the 28th April, clients will have until the 28th October 2025 to pass on Montpellier.

If you decide to go for plus after the 28th October this will also be honoured on the Montpellier question set and you will have until January 2026 to achieve plus, which is 3 months since you achieved Basic.   

The shift to the Willow question set reflects the dynamic nature of cybersecurity and the necessity for organisations to adapt accordingly and navigating these updates can be challenging, but we can support you through the transition.

We can complete a GAP analysis to evaluate your current cybersecurity posture against the Willow question set, including the technical controls in your environment as well as your written policies, to pinpoint areas requiring enhancement.

Then, with the output, we will work with you to put the steps in place necessary to achieve compliance with the new standards.

If you have questions or need support with the upcoming changes, please contact your Relationship Manager, and we can help you achieve or maintain your Cyber Essentials certification.

Related Posts

  • How to know if a Microsoft security alert is real

    How to know if a Microsoft security alert is real

    CybersecurityMicrosoft 365

    Microsoft security alert emails help you to know if someone is potentially trying to illegally access your Microsoft account. However, scammers and cybercriminals are well aware of this and [...]

    Read article

  • Infographic: Cybersecurity protection vs home protection

    Infographic: Cybersecurity protection vs home protection

    Cybersecurity

    Just like protecting your home requires more than a single lock, your business needs multiple layers of cybersecurity to stay resilient. Discover how home security principles apply to cyber [...]

    Read article

  • Hacker Misconceptions: The Good, The Bad, and The Grey

    Hacker Misconceptions: The Good, The Bad, and The Grey

    Cybersecurity

    When you hear the word hacker, you probably think of criminals in dark hoodies, but the reality is far more complex—some hackers protect us, some exploit us, and some [...]

    Read article

  • Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Cybersecurity

    Discover the top 7 social engineering tricks cybercriminals use to manipulate people into giving away sensitive information, and learn practical steps to protect yourself and your organisation from these [...]

    Read article

  • Protect your organisation with secure+ from ramsac

    Protect your organisation with secure+ from ramsac

    Cybersecurity

    Protect your organisation from evolving cyber threats with ramsac's secure+ A proactive monitoring solution designed to safeguard your systems, data, and reputation. [...]

    Read article

  • All you need to know about software vulnerabilities

    All you need to know about software vulnerabilities

    CybersecurityTechnical Blog

    Understanding software vulnerabilities is crucial for staying protected in an ever-evolving cyber landscape, where unpatched weaknesses can open the door to serious security threats for individuals and organisations alike. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?