- Effective
- 1 August 2026
- Requirement
- Annual Cyber Essentials
- Also new
- No ransom payments
- Applies to
- FE and sixth-form colleges
What changed
The Department for Education's College Financial Handbook 2026, effective from 1 August 2026, added cyber security requirements that were not in previous editions. Two paragraphs matter:
- Paragraph 6.15 — the requirement to maintain Cyber Essentials certification on an annual basis.
- Paragraph 6.16 — colleges must not pay any kind of ransom or extortion demand, including in relation to ransomware.
Compliance with the handbook is a condition of college accountability agreements with the DfE. This is not guidance, and it is not a standard you are encouraged to work toward. It is a requirement attached to your funding relationship.
It applies to further education and sixth-form college corporations, and to entities funded by DfE that conduct or control a designated institution. Academy trusts with post-16 provision follow the Academy Trust Handbook instead.
This did not come out of nowhere
The direction has been consistent for two years. From the 2024/25 funding year the DfE replaced the annual IT health check for colleges and specialist post-16 institutions with mandatory Cyber Essentials certification. Colleges were expected to demonstrate compliance by the end of that academic year.
What the 2026 handbook does is move the requirement from a funding-year condition into the financial handbook itself, and make the annual renewal explicit. A certificate obtained in 2025 and left to lapse does not satisfy paragraph 6.15.
Paragraph 6.16 is the one to think hardest about
The prohibition on paying ransoms is a bigger operational change than the certification requirement, and it has had far less attention.
Most organisations hit by ransomware make a decision under extreme pressure, weighing the ransom against the cost of rebuilding. Colleges no longer have that decision to make. Paying is prohibited, whatever the disruption, whatever the demand, whatever the state of your backups.
That removes the last resort. Which means recovery capability stops being an IT preference and becomes the only route back:
- Backups you have actually restored from. Not backups that report success — a documented restore test, with a known recovery time.
- Backups an attacker cannot reach. Immutable or genuinely offline copies. Backups on the same domain get encrypted with everything else.
- A recovery plan that works on paper. If your incident plan lives on the file share, you will not have it.
- Knowing your realistic recovery time. Governors will ask. "We have backups" is not an answer to "how long would we be closed?"
There is a governance point too. If a college suffers ransomware, cannot restore, and cannot pay, the question at the audit committee will be what was done in advance. That is a harder conversation than the certification requirement.
What Cyber Essentials actually asks of a college
Five technical control areas: firewalls, secure configuration, security update management, user access control, and malware protection. The scoping is where colleges spend most of their effort.
- Student and guest networks are out of scope. Student devices are not required to be in scope. This surprises people and usually reduces the work considerably.
- Staff networks are in scope, including devices connecting to them. A device on the student network is out; the same device on the staff network is in.
- Multi-factor authentication is required on all cloud services where it is available.
- Patching within 14 days for high and critical vulnerabilities, without exception. This is the requirement colleges most often fail on.
- Unsupported software in scope must be addressed. One end-of-life machine can fail the assessment.
Please verify current scoping against the live scheme requirements — the question set is revised periodically, and what passed last year may not pass this year.
Where schools and academy trusts stand
Schools are not covered by the College Financial Handbook, but they are not outside this direction of travel either.
The DfE's digital and technology standards for schools and colleges cover cyber security and reference achieving Cyber Essentials, and adherence to those standards is increasingly tied to grant funding. The Academy Trust Handbook requires trusts to maintain proper governance of risk, which now plainly includes cyber risk, and boards are expected to be able to evidence that.
The practical position for a school or trust today: Cyber Essentials is an expectation and a governance answer rather than a handbook clause. Given the FE requirement has now hardened into one, it would be reasonable to plan on the assumption that schools follow. Trusts that certify now will be answering a question that is coming rather than reacting to it.
The ransomware point applies regardless of sector. No handbook clause is needed to make an untested backup a bad position to be in.
What to do about it
If your college does not currently hold Cyber Essentials, or the certificate has lapsed:
- Gap review first. Most organisations have three or four real gaps. Finding them before you pay for an assessment is the difference between certifying and failing.
- Fix the usual blockers. Unsupported software, missing MFA on cloud administrator accounts, and patching that does not meet the 14-day requirement.
- Get the scope right. Excluding student networks correctly can substantially reduce both effort and cost.
- Certify, then diary the renewal. Annual means annual. We contact clients ahead of the anniversary rather than leaving it to be noticed.
- Separately, test a restore. Certification does not prove you can recover, and paragraph 6.16 means recovery is all you have.
How we help
We are a certified Cyber Essentials assessor and a CREST accredited penetration testing provider based in Albrighton, Shropshire. We take colleges through the gap review, the remediation and the assessment itself, and we will tell you plainly when something in your estate is going to fail before you pay to find out.
We also help colleges evidence the wider position — backup restore verification, network segmentation between student and staff environments, and independent testing where governors want assurance beyond a certificate.
Common questions
Is Cyber Essentials mandatory for colleges?
Yes. The College Financial Handbook 2026, effective 1 August 2026, requires colleges to maintain Cyber Essentials certification on an annual basis at paragraph 6.15. Compliance with the handbook is a requirement in college accountability agreements with the DfE, so it is tied to your funding relationship rather than being advisory.
Does it have to be renewed every year?
Yes. The handbook specifies maintaining certification on an annual basis. A certificate obtained previously and allowed to lapse does not satisfy the requirement. Certification is valid for twelve months.
Are student devices and networks in scope?
Generally not. Student and guest networks are out of scope, and student devices are not required to be in scope. Staff networks and the devices connecting to them are in scope — so the same device can be out of scope on the student network and in scope on the staff network. Confirm current scoping against the live scheme requirements.
What does paragraph 6.16 mean about ransomware?
Colleges must not pay any kind of ransom or extortion demand, including in relation to ransomware. In practice that removes paying as a recovery option entirely, which makes tested, isolated backups the only route back. It is worth treating as an operational requirement rather than a policy statement.
Does this apply to schools and academy trusts?
Not directly — the College Financial Handbook covers FE and sixth-form colleges. Academy trusts with post-16 provision follow the Academy Trust Handbook. However, DfE digital and technology standards reference Cyber Essentials for schools, and the Academy Trust Handbook requires governance of risk including cyber risk. The direction is consistent, and planning on the assumption that schools follow is reasonable.
What does Cyber Essentials replace?
For colleges and specialist post-16 institutions it replaced the annual IT health check from the 2024/25 funding year. The 2026 handbook moved the requirement into the financial handbook and made annual renewal explicit.
How long does certification take?
If you already meet the controls, days. Realistically most colleges need two to six weeks including remediation. The common delays are replacing unsupported software and rolling out multi-factor authentication, neither of which should be rushed. Start well before your funding deadline.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day