Published:

Post-Tax Year IT Review: What UK SMEs Should Check After 6 April
The 6 April tax year changeover is one of the few dates every UK SME owner knows. But most businesses treat it as an accounting event, not an IT one. That's a missed opportunity — 6 April marks both a tax year change and a natural checkpoint for reviewing your entire IT estate.
A structured post-tax-year IT review takes about 90 minutes and covers four areas that directly affect your security posture, compliance standing and operational efficiency. Doing it in the first two weeks of April means you catch problems before they compound over the rest of the year.
1. Verify Your MTD-Compatible Software Is Live
Making Tax Digital for Income Tax becomes mandatory on 6 April for businesses above the £50,000 threshold (and voluntary for those between £10,000 and £50,000). By now, most SMEs have set up their MTD-compatible software — but has it actually been tested?
Check that:
Your chosen software is actively submitting (or ready to submit) quarterly records
Historical data has been migrated accurately from your previous system
Your accountant or bookkeeper has access and can verify submissions
The software integrates correctly with your accounting or payroll system
If you're still using spreadsheets or non-MTD-compatible software on 10 April, you're already non-compliant.
2. Review User Access and Leaver Accounts
A new tax year often brings structural changes — new hires, departures, role changes. Each of these creates an access management task that's easy to overlook in the April rush.
Run through this checklist:
All leavers' accounts have been disabled and access revoked within 24 hours of departure
New joiners have appropriate access from day one — no default admin accounts in use
Former contractors and temporary staff have had all system access removed
Shared or generic accounts (e.g., "admin@yourcompany.co.uk") have been reviewed and assigned to named individuals
Unresolved leaver accounts are one of the most common findings during security triage reviews. They represent a direct security risk and a compliance gap under Cyber Essentials.
3. Confirm Your Backup Restore Testing Has Run Since the New Tax Year
Backups are only useful if you can restore from them. Yet many SMEs set up backup software and never verify that the backups actually work.
Test a sample restore from each critical system:
File servers and shared drives
Email systems (pick a few representative folders)
Database-backed applications
Cloud backups (confirm you can access them independently of your primary system)
Document the test results — dates, systems tested, success or failure. This documentation is useful for your own peace of mind and serves as evidence during a Cyber Essentials assessment.
4. Check Your Cyber Essentials Certification Status
If you hold a Cyber Essentials certificate, verify that it's still valid. Certificates are valid for 12 months from the date of assessment, and many SMEs lose track of when theirs expires.
If your certificate is due for renewal within the next six months, start planning now. The transition to Cyber Essentials v3.3 (Danzell) means the assessment process may differ from what you experienced previously, and early preparation avoids the end-of-year rush.
Beyond the Checklist: A Broader Review
Once you've completed the four core checks, consider these additional items:
Patch compliance — Are all devices receiving security updates within your defined cadence?
Software licences — Have you reviewed licence counts against actual user numbers? Are you paying for unused seats?
Cloud service agreements — Have any of your SaaS providers changed terms, pricing or data handling practices?
Insurance coverage — Does your cyber insurance policy still reflect your current IT setup and risk profile?
Your Next Step
A post-tax-year IT review doesn't need to be a costly engagement. A Security Triage Call gives you a structured assessment of your current IT posture — including all the items above — with clear recommendations for any gaps found.
*This article is part of the Infinite Cloud IT retrospective blog series, filling publication gaps identified during our 2026 content audit.*

Cyber Security
September IT Security Review: A Practical Guide for UK SMEs

Managed IT Services
Back-to-Business IT Setup: A Practical Guide for UK SMEs in September

Managed IT Services
Post-Holiday IT Review: What UK SMEs Should Check When Returning from Summer Break

Cyber Security
Q4 IT Security Checklist: What UK SMEs Should Complete Before Year-End

Cyber Security