Cyber Essentials – What’s New in the Latest Willow Question Set?

IASME recently introduced their latest Willow question set for the NCSC Cyber Essentials Self-Assessment Certification. This will replace the current (Montpellier) questions on the 28th April, 2025. The updates in Willow reflect evolving cyber security needs. Willow incorporates more detailed and specific questions. These questions are designed to help organisations better protect themselves from cyber threats.

Cyber essentials

Here are some key changes that you can expect in the Willow question set. This is important if you’re renewing your Cyber Essentials certification or certifying for the first time from 28th April this year:

Clarification of Scope

The Willow question set introduces clearer guidelines on what must be included within the scope of assessment. In particular, the inclusion of end-user devices and mobile devices. The new set emphasises that all user devices that access organisational data or services must be included. Even if they connect to cloud services. Whereas Montpellier had fewer explicit references to cloud services.

Devices

Willow demands more granularity when listing device types, especially with the operating systems. For example, question A2.4 in Willow requests more specific versions of operating systems, including feature versions for Windows devices. This will includes guidance for listing thin clients and servers with operating systems. This change aims to ensure that organisations are fully transparent about the security configurations across all devices.

Thin Clients

Willow increases focus on thin clients. Thin clients are simplified devices used to connect to virtual desktops. Willow highlights the security risks associated with modifying thin clients and mandates that they be regularly supported with security updates.

Software Firewalls

Willow expands on the importance of software firewalls, especially for remote and home workers. This is to ensure that devices are protected when not connected to corporate networks. Willow stresses the importance of ensuring software firewalls are enabled and configured correctly on all end-user devices. This topic was addressed in Montpellier. However, there is now added focus on software configurations and remote work security.

Cloud Services

Willow sets a clearer mandate to include all cloud services in scope, regardless of their type (IaaS, PaaS, or SaaS). This ensures that organisations can’t exclude any cloud-based platforms. This aligns with the growing reliance on cloud infrastructure. Montpellier included cloud services but provided less comprehensive definitions or requirements on this aspect.

Password Policies and Authentication

Willow delves deeper into password management, requiring organisations to choose more secure password configurations. Multi-factor authentication (MFA) is now given greater prominence as a requirement for securing external services. The new set also introduces stricter guidance on blocking common passwords. It is stricter around throttling login attempts to protect against brute force attacks. These were part of the Montpellier set but more detail will be required.

Firewall Management

Both Montpellier and Willow discuss the configuration and management of firewalls. However, Willow has enhanced questions around boundary firewall configurations and reviews. It also insists on stronger documentation and approval processes for inbound firewall connections. This ensures that exceptions are carefully managed and justified.

Cyber Breach Reporting

Willow adds more explicit references to breach reporting and post-breach communication. This reflects an increased focus on learning from incidents to improve security posture. About time, you might think. The GDPR has demanded this for years, IASME is catching up.

Insurance Eligibility

One of the more subtle but important change in the Cyber Essentials Willow question set is the expansion of questions regarding eligibility for automatic cyber insurance. The new standard provides clear conditions under which an organisation can opt in to the insurance offer. The need for transparency in reporting turnover and other financial information is required.

Conclusion

The transition from Montpellier to Willow in the Cyber Essentials Self-Assessment shows a greater emphasis on transparency, modern infrastructure (including cloud and remote working), and more stringent security measures. Organisations undergoing certification will need to be more detailed in their reporting and ensure all aspects of their IT infrastructure. This especially relates to cloud services and end-user devices which are included within scope and protected by up-to-date security measures. These changes reflect the growing complexity of the cybersecurity landscape. This ensures that organisations adopting the Cyber Essentials standard are better equipped to handle modern cyber threats.

Conclusion

To find out more about what you can expect in the latest Willow Cyber Essentials question set and other changes to be expected from 28th April 2025, you can download the updated documents from the IASME website at the following links:

Get Cyber Essentials Certified Today

Fortis is proud to be a trusted partner for businesses looking to achieve Cyber Essentials or Cyber Essentials Plus certification. Our experienced team will guide you through every step of the process. Starting with the the initial assessment right through to the final certification. Whether it’s helping you navigate the self-assessment for Cyber Essentials or conducting the technical audit required for Cyber Essentials Plus, our team ensures that you meet all the necessary requirements for the Cyber Essentials Scheme.

Talk to us today. We can help you achieve the new standard painlessly. Contact us here or, be old skool and pick up the phone and dial 03333 22 1011. We offer a free 1 hour consultation to help you on your way.