Table of Contents

Cyber Essentials Changes 2026: From Willow to Danzell and What They Mean for You

Reviewed & Written by:

|

Published:

|

Updated:

October 7, 2026
Green certified badge representing the Cyber Essentials Danzell update in 2026
Table of Contents

The Cyber Essentials scheme underwent major updates in April 2026, and if your organisation is renewing certification this year, you need to understand what has changed. Version 3.3-codenamed Danzell-replaces the Willow question set with stricter marking criteria, tighter scoping rules, and new conditions that trigger automatic failure. This is for IT teams and security teams who want to ensure Cyber Essentials certification preparation goes ahead without any challenges and aim for a first-time pass.

Here is a practical breakdown of everything in terms of grace period, dates, and timelines.

Key Takeaways

  • Danzell (v3.3) has applied to all new Cyber Essentials and Cyber Essentials Plus assessments since 27 April 2026. It replaced the Willow question set (v3.2).
  • Basic assessments started under Willow must be submitted by 26 October 2026. Cyber Essentials Plus under Willow must be completed by 27 January 2027.
  • Certificates issued under Willow stay valid for their full 12 months. Your next renewal is assessed under Danzell.
  • Danzell has three automatic-failure areas: unsupported software, cloud services without multi-factor authentication, and high or critical security updates not applied within 14 days.
  • Cyber Essentials Plus verifies scope before testing starts, tests a second independent sample after fixes, and locks the self-assessment once testing begins.

If you searched for the upcoming changes to Cyber Essentials in 2026, they have already happened. Cyber Essentials is the UK government’s baseline cyber security certification, and Danzell is the question set every new Cyber Essentials and Cyber Essentials Plus assessment has used since 27 April 2026, marked against the National Cyber Security Centre (NCSC) Requirements for IT Infrastructure document v3.3, which serves as the standard for achieving Cyber Essentials certification.

The five technical controls that protect organisations against the most common cyber threats have not changed. What changed is how strictly they are assessed, and what happens when one is missing.

The live question for most organisations is whether they still have an assessment running under Willow, the version before Danzell. If you do, the basic assessment has to be submitted by 26 October 2026, and a Plus audit under Willow completed by 27 January 2027. This page covers those deadlines, then what Danzell changed and what it means for an assessment you start today.

This guide is for IT managers, compliance leads and business owners working towards achieving Cyber Essentials certification, or Cyber Essentials Plus, under the Danzell rules. It matters because three of the changes are automatic failures: miss one and the assessment fails outright, a Plus audit can restart from the beginning, and a lapsed certificate can cost you a UK government tender.

If you are new to the Cyber Essentials scheme, start with our guide to what Cyber Essentials is.

Key dates: Willow to Danzell

Date

What happens

13 February 2026

IASME published the Danzell question set (v3.3) for preview

Up to 26 April 2026

Last day a new assessment account could use Willow (v3.2)

27 April 2026

All new assessment accounts use Danzell

26 October 2026

Last day to submit a basic Cyber Essentials assessment under Willow

27 January 2027

Last day to complete a Cyber Essentials Plus audit under Willow

Do you still have a Willow assessment to finish?

Which question set applies depends on when your assessment account was created in the IASME portal, not on when you started preparing. Assessment accounts created before 27 April 2026 stay on the Willow question set (v3.2); assessment accounts created on or after that date use Danzell.

If you have an active assessment account created under Willow, the basic Cyber Essentials assessment must be submitted by 26 October 2026. If you then go on to Cyber Essentials Plus under Willow, the audit must be completed by 27 January 2027. After those dates, unfinished Willow assessments restart under Danzell’s updated requirements.

If you are mid-process, speak to your certification body this week. For most organisations, it is quicker to finish under Willow than to restart, but only if the outstanding work can realistically be submitted by 26 October (or, for Plus, completed by 27 January 2027).

If you have weak MFA or patching today, finishing under Willow buys time, but the renewal a year from now will be assessed against Danzell’s updated requirements, so start fixing those areas now.

Certificates already issued under Willow stay valid for their full 12 months. Renewal is a fresh assessment against whichever question set is current at the time, which from now on means Danzell.

What changed in the Cyber Essentials requirements (v3.3)?

The NCSC publishes the requirements; IASME turns them into the question set that certification bodies mark against. To help organisations prepare, IASME published the Danzell questions for preview on 13 February 2026, ten weeks before they went live. Version 3.3 of the Requirements for IT Infrastructure document lists six changes from the previous version:

  1. A definition of “cloud services” is provided.
  2. The definition of passwordless authentication is updated to include FIDO2.
  3. A definitive statement that cloud services cannot be excluded from scope.
  4. The Software Security Code of Practice is introduced in the software development section.
  5. The scope criteria no longer refer to “untrusted connections”.
  6. The importance of backing up data is emphasised.

The updated requirements give greater clarity rather than new technical controls; the five controls that protect organisations are the same. Two of those changes affect what gets marked: the cloud scope statement and the removal of “untrusted connections”, which widened what counts as in scope.

The others clarify or encourage. The backup change emphasises good practice without making it a requirement; the document now says so plainly and strongly recommends backups anyway.

The Software Security Code of Practice reference only matters if you do application development. Under v3.3, publicly available commercial web applications are in scope by default, bespoke and custom components of web applications built by your own application development team are out of scope, and the Code of Practice is secure development guidance rather than a Cyber Essentials requirement.

Danzell is best read as an enforcement update to the Cyber Essentials scheme rather than a new one. The same five technical controls apply: firewalls, secure configuration, security update management, user access control and malware protection. Our Cyber Essentials requirements guide covers each of the Cyber Essentials controls under v3.3.

From the assessor’s desk

Under Danzell, the automatic fail that catches most organisations is MFA on cloud services, because the long tail of SaaS tools is invisible until someone lists it. The 14 day patching rule is another one.

Harman Singh, IASME Cyber Essentials Plus assessor, Cyphere

How Danzell assessments are marked

The assessment rules themselves did not change. Basic Cyber Essentials certification is still a verified self-assessment: you answer IASME’s question set, a director or board member signs a declaration that the answers are true, and an assessor at your certification body marks each self-assessment question as compliant or non-compliant against the technical controls in v3.3.

The assessor may ask for evidence before certifying. If any answer is non-compliant, you have two working days to correct and resubmit at no extra charge; after that, you reapply and pay the fee again.

What Danzell changed is the number of answers that end the assessment on their own.

Three areas carry stricter marking criteria that are basically an automatic failure:

  1. unsupported software on an in-scope device,
  2. a cloud service in scope without MFA,
  3. high or critical security updates not applied within 14 days.

The certificate reflects a point-in-time assessment, valid for 12 months from the day the application is assessed and marked as a pass.

As a cyber security professional with several years of experience spent in assessing organisations of various scopes and sizes, I respect the fact that IASME improvements are based on realistic value add for businesses. These three areas are exactly where the real incidents start: unpatched software, credentials without a second factor, and end-of-life systems that can no longer be fixed are an open invitation to threat actors due to higher exploitation likelihood.

1. Cloud services requirements: nothing excluded, MFA everywhere

Three Cyber Essentials cloud rules with nothing excluded and MFA everywhere

Cloud scope

Cloud services have had to be in scope since version 3.0 of the requirements. What Danzell adds is a definition and a definitive statement, so there is no longer a way to read around it. The terms ‘untrusted’ and ‘user-initiated’ have been removed from scoping rules.

The NCSC’s wording: a cloud service is “an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet”, accessed through an account and storing or processing data for your organisation. And: “Cloud services cannot be excluded from scope.”

In reality, that means any SaaS application, and any of the cloud platforms (PaaS or IaaS) hosting your organisation’s data or services, counts. Typical examples we see in scope descriptions:

  • Microsoft 365 and Google Workspace
  • Salesforce, HubSpot and other CRM platforms
  • Xero, Sage Business Cloud and accounting software
  • Workday, SuccessFactors and HR or payroll systems
  • ServiceNow and operational platforms
  • Slack and collaboration tools
  • Microsoft Azure, AWS, Google Cloud and other cloud platforms, where they host your servers or data

These are our examples, not the NCSC’s; the definition is deliberately broad. This change reinforces a position that has existed since Evendine: if your organisation’s data sits in a cloud service, that service is in scope. Our scope guide covers whole-organisation and sub-set boundaries in detail.

MFA on every cloud service

The requirements say authentication to cloud services must always use multi-factor authentication (MFA). It is a mandatory requirement, not a recommendation, and under Danzell, a cloud service in scope without MFA is an automatic failure. That covers standard users, administrators and shared accounts, whether MFA is built into the service or provided through single sign-on with an identity provider such as Entra ID, Okta or Google Identity.

Limiting MFA to administrators or a few high-risk accounts does not meet the requirement, and cost or user pushback is not accepted as a reason.

The rest of the user access control requirement is unchanged and still expects least privilege: separate accounts used for administrative activities only, and special access privileges removed when no longer required. Assessors check it alongside MFA.

Passwordless authentication

Passwordless authentication methods count towards the MFA requirement. Version 3.3 defines passwordless authentication as establishing identity with a factor other than knowledge, and recognises these passwordless authentication methods: FIDO2 authenticators and passkeys, security keys or tokens, biometrics, one-time codes, QR codes and push notifications.

Where you still use passwords alongside a second factor, the password element must meet the scheme’s password rules. SMS codes still count as MFA, although the NCSC notes they are the least secure option.

Assessor tip

When you are preparing for CE, it’s worthwhile to have cloud app inventory in front of you. If you use Defender for cloud apps, it centralises SaaS and OAuth inventory; similarly, you may have other tools, and it’s worth checking around first.

Once you have a comprehensive list of cloud apps used across the business, do your review for the CE requirements, i.e. MFA.

Roll out MFA in phases if you need to, and run a short awareness campaign so adoption doesn’t get friction or other blockers.

If a cloud service genuinely cannot support MFA or passwordless methods, document it and ask whether that service should stay in use at all.

Harman Singh, Cyphere

2. Vulnerability fixes: the 14-day rule (A6.4 and A6.5)

Questions A6.4 and A6.5 are included under the security update management control and are automatic-failure questions under Danzell. They are the scheme’s most measurable enforcement points:

  • A6.4: high-risk or critical security updates for operating systems and router or firewall firmware must be installed within 14 days of release.
  • A6.5: high-risk or critical security updates for applications, including associated files and extensions, must be installed within 14 days of release.

The requirements give three triggers for the 14-day rule. It applies when the vendor describes the fix as critical or high risk, when the vulnerability has a CVSS v3 base score of 7 or above, or when the vendor gives no details of the severity at all. That third trigger matters: a vendor update with no severity information has to be treated as urgent, not ignored.

The NCSC also defines vulnerability fixes broadly. Willow replaced the word “patches” with “vulnerability fixes”, so software patches are only one kind of fix. The definition includes “patches, updates, registry fixes, configuration changes, scripts or any other mechanism approved by the vendor to fix a known vulnerability”. If the vendor’s answer to high-risk or critical vulnerabilities comes as configuration changes rather than a patch, the 14 days still apply.

The window runs from the date the vendor releases the fix, not from when your organisation notices it. That needs monitoring of vendor advisories, not a monthly review. The 14-day rule for vulnerability fixes covers:

  • operating systems (Windows, macOS, Linux)
  • router and firewall firmware
  • applications and productivity suites
  • browsers and VPN clients
  • browser extensions, which are the most frequently overlooked item
  • network appliances and Wi-Fi controllers

This is also the change where software definition has been expanded to include operating systems, commercial off-the-shelf applications, extensions, interpreters, scripts, libraries, network software and firewall and router firmware

Unsupported software is the third automatic fail

All software on in-scope devices must be licensed and supported: properly licensed software you have a legal right to use, and that the vendor still supplies vulnerability fixes for. In-scope software the vendor no longer supports cannot receive fixes for new vulnerabilities, so it fails the same requirement.

Under v3.3 you have two options: remove it, or move it into a defined sub-set that prevents all traffic to and from the internet. Extra security products around it do not count.

The Cyber Essentials Plus Test Specification is explicit that virtual patching “will not be recognised as a mechanism for compliance”. Windows 10 is the common unsupported operating system case in 2026; our supported operating systems guide covers IASME’s position on Extended Security Updates.

Assessor tip

Prioritise high-risk and critical vulnerabilities rated CVSS 7 or above and set alerts against the 14-day window. Schedule maintenance windows for software patches fortnightly at least, not monthly. If a managed service provider applies vulnerability fixes for you, get the 14-day rule into their SLA, because a third party’s delay still fails your assessment and you won’t have to chase them every other month for accountability.

Harman Singh, Cyphere

3. Certification process changes at Cyber Essentials Plus

Cyber Essentials Plus tests the same five controls on a sample of your devices and every cloud service in scope. The current Test Specification (v3.2) tightened the process in three ways that still apply under the Danzell update, and IASME’s process adds a fourth.

Scope is verified before testing: The assessor must confirm that the Plus scope matches the scope on your basic certificate, verify by technical means that it matches the networks and systems being assessed, and check that any sub-set is genuinely segregated. Any issue found here has to be resolved before testing starts.

The self-assessment is locked: Once Plus testing begins, your self-assessment answers can no longer be tidied up in response to findings. They must be accurate before testing starts.

Double sampling: This applies to the internal vulnerability test. The assessor scans a first random sample of devices for missing updates. If any are found, they “must be fixed across the entire scope of the CE Verified Self-Assessment certificate, not just the sampled devices”, and “this must be completed within 30 days”. A second sample, drawn with the same calculation and declared to you “not more than 72 hours or 3 working days prior” to testing, is then tested inside the same 30 days to confirm the fixes reached the whole estate.

Second sample outcome

Result

All required updates installed

Cyber Essentials Plus awarded

The same updates still missing

Cyber Essentials Plus fails, and the Cyber Essentials certificate is revoked

Different, unrelated updates missing

Cyber Essentials Plus awarded, with an advisory to address them

Second sample refused

Cyber Essentials Plus cannot be achieved; “the CE Verified Self-Assessment certificate will remain valid”

The same revocation applies if updates are still missing when the 30 days end. Source: IASME Knowledge Hub, Danzell update: new CE+ internal vulnerability and remediation process

The 90-day window, with 30 days to fix. Cyber Essentials Plus must be completed within 90 days of the basic certificate. That is why we plan the Plus audit within about 30 days of the basic certificate. If the window expires, the whole process, including the self-assessment, restarts from the beginning.

Our Cyber Essentials Plus requirements guide covers the five tests and the sampling method in full.

Assessor tip

Engage your assessor early to align scope, and do not start CE Plus testing until you are confident in your patching. At Cyphere, we include a readiness phase for customers that can benefit from consultations and preparation before jumping into CE Plus tests. This ensures understanding of segregations if any, VLANs and firewall configurations and what you have versus what is expected by certification.

Harman Singh, Cyphere

4. Scope, BYOD and the declaration

How scope is described

Your scope is described by the business unit managing it, the network boundary and the physical location, which includes home and remote working staff, and it is agreed with your certification body before the assessment starts. If you certify only part of the organisation, that sub-set must be separated from the rest by a firewall or VLAN, and your assessor will ask you to justify the partial scope.

Excluded networks and devices are recorded by your assessor and are not made public.

Danzell update removed the references to “untrusted connections” from the scope criteria. The requirements now apply to any in-scope device or software that can accept incoming connections from the internet, can make outbound connections to the internet, or controls the flow of data between those devices and the internet. A scope that does not include end-user devices is not acceptable.

Home and remote working devices

The default position in v3.3 is that all corporate and BYOD home and remote working devices used for your organisation’s business are in scope. If you give a remote worker a router, that router is in scope too. All other home routers such as Sky, Virgin, Talktalk, etc ISP provided routers for your home internet connections are out of scope, which means the firewall control has to be met by a software firewall on the device itself, as that’s the boundary now.

Where a home working or remote user connects over a corporate VPN, the internet boundary is the company firewall or the virtual or cloud firewall. Danzell did not change these rules; they date from earlier versions and are listed here because home devices are the ones most often missing from scope descriptions.

BYOD is not a policy exercise

Personal laptops and mobile devices used for work email or cloud access are in scope, and they must meet the same cyber security controls as company devices: supported and updated software, a screen lock, malware protection where the operating system requires it, and MFA on the cloud services they reach. A written policy on its own is not enough, particularly at Plus, where sampled devices are tested.

Mobile device management or conditional access is the most practical way to enforce and evidence this, but the scheme does not mandate a tool, and encryption is not a Cyber Essentials requirement. The one exception in the requirements is a personal device used only for native voice calls, native text messages and MFA apps. Our BYOD guide sets out the options.

Legal entities and the declaration

Legal entities included in scope must be specified by organisations. Every legal entity in scope is listed with its name, address and company number. Where a group certifies several entities under one scope, each entity can receive its own certificate noting that it forms part of a wider scope, which helps groups with different IT environments.

The certificate is point-in-time: it reflects compliance on the date it was awarded. Alongside that, a director or board member signs a declaration that the answers are true and that the controls will be maintained for the certificate’s 12 months. That is a governance commitment to ongoing compliance, so brief whoever signs it.

Assessor tip

Don’t mistake it as just filling an application form for a quick certification; include the in-scope systems’ relevant information as much as you can to make it easier for assessors. This may include network diagrams, mapping the topology before you answer the scope questions and deciding early between one group certificate and individual entity certificates.

Harman Singh, Cyphere

5. What to expect from your assessor under the Danzell rules

Under Danzell, assessors read scope descriptions far more closely against the technical reality. Expect the following:

What to expect from your Cyber Essentials assessor under the Danzell rules

  • clarification requests for any unclear, contradictory or incomplete answers
  • scope descriptions checked against network topology and stated exclusions
  • evidence of compliance with the 14-day rule tested at Plus, not only recorded
  • account separation tested at Plus, so least privilege has to be real rather than written down
  • no changes to the self-assessment once Plus testing has started

Nominate one owner for the submission who understands the technical environment, run an internal dry run before you submit, and answer assessor queries within two working days so the timetable does not slip.

From the assessor’s desk

Since the Danzell update, there’s proper stress on scope descriptions, far more closely against the technical reality: which networks, which tenants, which services. A scope that sounds tidy but does not match the estate gets questioned now, where a few years ago it might have been accepted as written.

Harman Singh, IASME-licensed Cyber Essentials assessor, Cyphere

Danzell checklist

  1. List every cloud service that stores or processes organisational data; none can be excluded
  2. Enable multi-factor authentication, or passwordless authentication, on every cloud service, for every user, including shared accounts
  3. Keep least privilege: separate administrator accounts, and privileges removed when no longer needed
  4. Track vulnerability fixes against the 14-day rule for operating systems, firmware, applications and browser extensions
  5. Remove unsupported software, or isolate it in a sub-set with no internet traffic
  6. Describe scope by business unit, network boundary and location; segregate any sub-set by firewall or VLAN
  7. Bring remote working and personal devices under technical control, or block their access to work data
  8. List the legal entities in scope with name, address and company number
  9. Brief the director or board member who signs the declaration
  10. For Plus, finalise the self-assessment before testing, and plan fixes and retests inside the 90-day window
  11. Keep the certificate current: renewal is a fresh assessment against the requirements in force at the time

You can preview the Danzell questions on IASME’s self-assessment preview page and use them as a gap analysis of your cyber security controls before you open an assessment account. Our checklist covers both levels of Cyber Essentials certification, control by control.

Cyber Essentials version history

For anyone comparing against an older certificate or looking for a previous year’s requirements, these are the question sets since version 3.0.

Question set

Requirements version

In use from

What it changed

Evendine

v3.0

January 2022

Brought cloud services, home working, and stronger password and MFA expectations into the modern structure of the requirements

Montpellier

v3.1

24 April 2023

MFA for all users of cloud services, not only administrators; firmware counted as software; devices listed by make and operating system; third-party devices and device unlocking clarified; the zero trust statement added

Willow

v3.2

28 April 2025

Passwordless methods recognised as meeting the MFA requirement; “patches” broadened to “vulnerability fixes”; the Cyber Essentials Plus Test Specification v3.2 added scope, sub-set and sampling verification

Danzell

v3.3

27 April 2026

The current scheme, covered on this page

Cyber Essentials changes FAQs

When did Danzell take effect?

On 27 April 2026. Every assessment account created on or after that date uses the Danzell question set.

Can I still use Willow?

Only if your assessment account was created before 27 April 2026. Under the Willow question set, the basic assessment must be submitted by 26 October 2026, and Plus under Willow must be completed by 27 January 2027. After that, unfinished assessments restart under Danzell. Certificates already issued under Willow stay valid for their full 12 months, and your next renewal is assessed against Danzell’s updated requirements.

Do I have to enable MFA for every user, including shared and service accounts?

Yes. The NCSC requirements say authentication to cloud services must always use MFA, and that covers standard users, administrators and shared accounts. Passwordless authentication methods such as passkeys, security keys and authenticator app push notifications count. Limiting MFA to administrators or a few high-risk accounts does not meet the requirement.

For genuinely non-interactive service accounts, such as API connectors, use modern alternatives like app registrations, certificates or managed identities, and restrict them with network access controls. Review these designs with your identity provider so the controls do not break automation.

Are there cost implications?

The IASME fee for Cyber Essentials certification did not change with Danzell; the bands are the four set out in our cost guide. The cost implications sit in preparation and in Cyber Essentials Plus: allow for a full restart if the 90-day window expires or both samples fail, and budget time for fixes between samples. Preparing thoroughly before Plus testing starts avoids the most expensive outcome, a complete restart.

Can I still use personal devices (BYOD) under the Danzell rules?

Yes. Personal devices used for remote working that access work email or services are in scope and must meet the same controls as company devices: supported and updated software, a screen lock, malware protection and MFA on the cloud services they reach. Encryption is good practice but is not a Cyber Essentials requirement.

Mobile device management is the most practical way to enforce and evidence this, but it is not mandatory. A written policy on its own is not enough. See our BYOD guide.

Where can I preview the Danzell questions?

IASME publishes a free preview of the self-assessment questions. Read it alongside the NCSC’s Cyber Essentials requirements document, Requirements for IT Infrastructure v3.3, before you open an assessment account.

Will my scope exclusions be made public?

No. Your assessor records exclusions, and they are not published. Where the certificate does not cover the whole organisation, it names the sub-set that was assessed, so buyers can see the scope is partial, but not what was left out.

What are the automatic fails under Danzell?

Three areas: unsupported software on an in-scope device, a cloud service in scope without MFA, and high or critical vulnerability fixes (security updates) not applied within 14 days of release (questions A6.4 and A6.5). At the basic level you have two working days to correct answers and resubmit at no extra charge; an automatic-fail answer that cannot be corrected in that time means reapplying for Cyber Essentials certification.

Does Danzell apply to every organisation?

Yes. It has applied to every organisation certifying under the Cyber Essentials scheme since 27 April 2026, whatever your size or sector. The requirements are the same for a sole trader and a large organisation; what differs is the scale of the estate and the tooling needed to evidence the controls.

Do I need to redo a scope approved under Willow?

Your scope is agreed again at renewal. If your Willow scope left out any cloud service, it must come in under the updated requirements, because v3.3 states outright that cloud services cannot be excluded, and the boundary is described by business unit, network boundary and location.

How Cyphere helps with Danzell assessments

We are an IASME-licensed certification body, so we mark Cyber Essentials certification submissions and run Cyber Essentials Plus audits in-house, remotely for the vast majority of organisations.

From the assessor’s desk

Mostly, as an assessor, the change customers are least prepared for is the MFA requirements for cloud scope. For anyone with a Willow assessment still open, we look at what is outstanding and advise whether it can realistically be finished before the October deadline or whether restarting under Danzell is a more efficient route. For CE Plus, we plan remediation against the 90-day window from the start, because the second sample leaves no room for fixing only the devices that were tested.

Harman Singh, IASME-licensed Cyber Essentials assessor, Cyphere

Cyber Essentials Plus certification with Cyphere

Want a printable summary? Download the Cyphere Danzell update guide (PDF).

Related Cyber Essentials guides

Achieve Cyber Essentials Certification With Confidence

We handle the technical assessment, identify control gaps, and provide audit-ready evidence so you meet certification deadlines for a first-time pass.

Trusted by 150+ UK orgs

Related Reads

Join 1000+ subscribers getting the best tips on cybersecurity, security management, and more!

You may opt-out at any time. Read our privacy policy.

Request a Consultation

No obligations. Free retests included. Call us directly 0333 050 9002. View our privacy policy.

How "Defensible" is your firm compared to UK peers?

Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.