Business Wi-Fi in 2026 is not the same product it was in 2020. For any company, choosing the right business wifi solutions is essential. WPA3 is now the minimum security standard, while Wi-Fi 6 has become mainstream. At the same time, guest Wi-Fi requires proper GDPR handling, and poorly configured captive portals can create serious data protection risks. Therefore, if your last Wi-Fi contract predates these changes, this is the year to review it.

This guide is for UK businesses about to sign, renew or extend a Wi-Fi contract in 2026. It covers what has changed technically, the five questions to ask any provider, guest Wi-Fi compliance in , coverage sizing, and the mistakes that catch businesses out.

What has changed in business Wi-Fi since 2020

  • WPA3 is the minimum. WPA2 is still around but the Wi-Fi Alliance and NCSC both recommend WPA3 for new deployments. Every serious business access point sold in 2026 supports it.
  • Wi-Fi 6 is mainstream, Wi-Fi 7 is enterprise-only for now. Wi-Fi 6 (802.11ax) is the right target for a UK SME in 2026, with real performance gains in high-density environments. Wi-Fi 7 is worth paying for only in specific enterprise cases.
  • GDPR made captive portals a compliance issue. Any guest Wi-Fi that captures data (email, name, phone) has to meet UK GDPR’s consent, retention and access rules. Free hotel Wi-Fi that harvested emails for marketing without a clean consent flow now fails the ICO test.
  • Post-COVID density patterns changed. Meeting rooms need more capacity, open-plan desks less. Wi-Fi surveys designed for pre-2020 offices routinely under-provision new meeting rooms.

The five questions to ask any business Wi-Fi provider

  1. How many concurrent devices will each access point support at peak?
  2. Which Wi-Fi standard are the APs (Wi-Fi 6, 6E, or 7) and is WPA3 enabled by default?
  3. How is the guest network isolated from the corporate network (VLAN segmentation, separate SSID)?
  4. Additionally, if we run a captive portal, is the consent flow UK GDPR compliant, and where is guest data stored?
  5. What is the SLA for AP failure and how quickly is a replacement dispatched?

If any of those questions produces a vague answer, keep asking. A capable provider will give you concrete figures. Vague answers usually mean the provider is selling a boxed product and has not thought about your specific site.

Guest Wi-Fi and UK GDPR: what matters

Guest Wi-Fi is where most UK businesses trip over the compliance rules. The ICO’s expectations under UK GDPR are not complicated, but they need to be implemented, not assumed.

  • A privacy notice in  on the captive portal before the user connects, not buried in a linked terms page.
  • Explicit consent via an unticked checkbox for any data processing (email, name, marketing opt-in). Pre-ticked is not consent under UK GDPR.
  • Separate consent for Wi-Fi access and for marketing. Bundling them together fails the ICO test. A user has the right to use the Wi-Fi without agreeing to marketing.
  • A defined retention period for connection logs (typically 12 months, longer only if the business has a documented legal reason).
  • A withdrawal path. The user must be able to unsubscribe and request deletion later.

The maximum ICO penalty for a UK GDPR breach is £17.5 million or 4% of global turnover, whichever is greater. Although fines for poorly configured guest Wi-Fi may be relatively small, an ICO investigation can still be costly. In addition, those costs can be significant regardless of the final outcome.

Coverage: how to size Wi-Fi properly

The single most common Wi-Fi problem in UK offices is under-provisioned access points in meeting rooms. For businesses using Horizon Public Wi-Fi or planning a public-facing deployment, sizing matters even more. The pre-2020 rule of thumb (one AP per 50 to 75 square metres) was written for an office where twenty people at desks was normal and meeting rooms held four. Modern usage runs the other way.

For example, a useful working baseline for 2026 is one Wi-Fi 6 access point per 25 to 30 concurrent devices in high-use areas such as meeting rooms and break-out spaces. Meanwhile, general open-plan or corridor areas may only need one access point per 50 concurrent devices. However, a serious provider should still run a site survey rather than rely on a floor plan alone.

Security: the layers your Wi-Fi setup needs

A well-configured business Wi-Fi setup uses four security layers rather than one.

  1. WPA3-Enterprise on the corporate SSID, tied to your directory (Microsoft Entra ID or equivalent). Every user logs in with their own identity, not a shared password.
  2. A separate guest SSID on a VLAN-isolated network. Guest traffic cannot reach any corporate resource, only the internet.
  3. A captive portal for the guest SSID with GDPR-compliant consent flow and a defined retention period.
  4. Regular firmware updates on the access points. Wi-Fi APs are network devices. Old firmware equals known vulnerabilities.

This is the layout the NCSC recommends in its guidance for small organisations. Two SSIDs, VLAN separation, WPA3 on the corporate side, captive portal on the guest side. It is not new. It is just often not implemented.

Cost: what to expect in 2026

Business Wi-Fi pricing has two components: the initial rollout and ongoing management.

  • Access points: £150 to £400 per unit for Wi-Fi 6 business-grade, £500+ for Wi-Fi 7
  • Cloud controller / management platform: £3 to £10 per AP per month
  • Installation and site survey: £500 to £2,000 for a typical UK SME site, depending on cabling requirements
  • Captive portal software (for public-facing venues): £30 to £150 per month depending on features

For a 30-user UK SME office, expect £2,500 to £5,000 upfront, then £50 to £150 a month ongoing. Larger sites or multi-site rollouts scale from there. Managed Wi-Fi services bundle much of this into a per-AP monthly fee, which is often the cleaner OpEx choice.

Managed Wi-Fi vs self-managed: which suits UK SMEs in 2026

The decision between managed and self-managed Wi-Fi tracks how much internal IT capacity a business genuinely has, not what the marketing headline says.

  • Self-managed works where you have an internal IT team comfortable with cloud controllers (Ubiquiti UniFi, Cisco Meraki dashboard, Aruba Central), a documented Wi-Fi standard for your business, and someone whose named responsibility includes monitoring, firmware updates and site surveys. Kit cost is lower, ongoing management sits with you.
  • Managed Wi-Fi works where the internal team is small or generalist. The provider owns monitoring, updates, incident response and site surveys. You get a defined SLA and one contact for anything Wi-Fi related. Monthly fee is higher, operational load is close to zero.

The tipping point for most UK SMEs is around 25 to 50 users. Below that, self-managed with a competent internal person is fine. Above that, the operational overhead of self-managed usually exceeds the CapEx saving inside 18 months.

Multi-site Wi-Fi and roaming

Businesses with multiple sites (retail, hospitality, healthcare) need one more capability: consistent SSID and roaming across sites. Staff logging into the same corporate Wi-Fi in three different locations without re-entering credentials is table stakes in 2026, not a premium feature.

A cloud-managed Wi-Fi platform gives you a single dashboard for every site, one policy set, and centralised guest portal branding. Adding a new site is a matter of unboxing the APs, plugging them in, and letting the cloud controller push the configuration. This is where a managed service usually pays for itself on multi-site rollouts.

Common mistakes when buying business Wi-Fi

  • Treating Wi-Fi as a broadband add-on. The broadband or leased line gets the connection to the building. Wi-Fi distributes it inside the building. Different problem, different equipment, different provider often.
  • Skipping the site survey. APs on floor plans get 20 to 40% of the real-world signal wrong.
  • Running one SSID for staff and guests on the same VLAN. This is the compliance and security failure that gets flagged most often in Cyber Essentials assessments. This is the compliance and security failure that gets flagged most often in Cyber Essentials assessments.
  • Not planning for firmware updates. Set a cadence and stick to it. Six months without a firmware refresh is a security concern.
  • Buying consumer-grade APs at business scale. They will not handle the concurrent device load, and the management overhead outstrips the CapEx saving within a year.

A second look at your Wi-Fi setup

Finally, if you would like a second pair of eyes on your Wi-Fi setup before signing your next contract, get in touch. We can review what your existing kit is delivering, identify any coverage or compliance gaps and, as a result, help you decide whether the next step should be a refresh, a captive portal fix or a full rebuild.