Serving Shropshire ยท Herefordshire ยท Welsh Borders ยท Est. 2014Helpdesk open ยท avg 14 min response01584 517 234
Fresh Tech
01584 517 234Book a call โ†’
Cyber EssentialsComplianceSecurity

Cyber Essentials 2026: What the Danzell Update Changed

S
Sam ยท Aug 9, 2026 ยท 8 min read
Cyber Essentials Danzell question set changes for UK businesses in 2026

The Cyber Essentials question set changed in April 2026. Two of the new rules fail you outright. Here is what changed and what to fix before you renew.

TL;DR: On 27 April 2026 the Cyber Essentials question set changed from Willow to Danzell, alongside version 3.3 of the NCSC requirements. Two rules now fail you outright: multi-factor authentication missing on a cloud service that offers it, and high or critical security updates not applied within 14 days. Cloud services are also defined more broadly than most businesses assume. If you passed last year and have not changed anything, there is a fair chance you would not pass today.

Cyber Essentials gets a refresh most years. Usually it is tidying: clearer wording, a reworded question, nothing that changes what you actually have to do.

This one is different. The April 2026 update moved two things from "expected" to "fail if you have not done it", and widened what counts as being in scope. Businesses coming up to renewal are the ones who will notice, because the questionnaire they filled in last year is not the questionnaire they will fill in this year.

Here is what changed, in plain English, and what it means for your renewal.

What actually changed

1. MFA on cloud services is now pass or fail

This is the big one. Multi-factor authentication, the code or prompt on top of your password, has been part of the scheme for years. What changed is the consequence.

Under Danzell, if a cloud service you use offers MFA and you have not turned it on, that is an automatic fail. Not a comment, not a point deducted. A fail.

The reason is simple enough: a stolen password on its own is the single most common way a small business gets broken into, and MFA is the control that makes a stolen password close to useless. Our MFA explainer covers how it works if you want the detail.

2. Fourteen days on high and critical updates, enforced

The 14-day patching window is not new. Applying high-risk and critical security updates within 14 days of release has been in the requirements for a long time. What is new is that missing it is now an automatic fail rather than something an assessor might query.

In practice this is less about attitude and more about whether anyone is checking. Most businesses that miss the window are not ignoring updates. They have three laptops that have not been switched on for a month, a server everyone is nervous about rebooting, and no report telling anyone about it. Automated patch management exists precisely because manual patching quietly fails at exactly this.

3. Cloud services are defined more broadly than you think

The updated requirements set out more clearly what counts as a cloud service in scope: broadly, any online service your team signs into with business credentials to store or process business data.

That is a wider net than most people picture. Microsoft 365 is obvious. The accounting package, the CRM, the file-sharing account someone set up years ago, the design tool one department pays for on a card, the project tracker the team adopted without telling anyone: these are in scope too, and each one needs MFA if it offers it.

The requirements now also say flatly that cloud services cannot be excluded from your scope. You do not get to leave one out because it is small, because a single department owns it, or because it is somebody else's subscription.

This tends to be where renewals come unstuck. Not the systems you know about, but the ones nobody has written down. If you have never done a proper inventory of what your team signs into, that is the first job.

4. Sign-in and passwords

The update leans further towards passwordless sign-in. Passkeys now get a proper definition in the requirements, FIDO2 security keys are named explicitly, and they count as multi-factor authentication in their own right.

One thing worth clearing up, because a lot of the coverage around this update got it wrong: the password rules did not change. You still satisfy the requirement by doing one of three things. Either the account is protected by multi-factor authentication, in which case the password itself needs to be at least 8 characters. Or you set a minimum password length of 12 characters. Or you set a minimum of 8 characters and automatically block common passwords using a deny list. A 12 character minimum is not suddenly compulsory: it is one route of three, and it has been for several versions.

The requirements are also still explicit about what not to do. No forced password expiry every 90 days, and no complexity rules demanding a capital, a number and a symbol. Both make passwords worse rather than better, and both are still in plenty of company policies.

Nobody is forcing you to abandon passwords tomorrow. But the direction of travel is unambiguous, and passkeys are genuinely easier for staff once they are set up, which is not something you can often say about a security change.

5. Backups: still not a control, but no longer ignored

Backups remain outside the five technical controls, so you are not certified or refused on them. The updated document does spell out sensible practice: keep a copy somewhere other than the device itself, and disconnect removable media when it is not being used.

Take that as the signal it is. Backups are the difference between a bad week and a closed business, whether or not a certificate depends on them. Our backup and disaster recovery page covers what good looks like.

What this means for your renewal

The five core controls are unchanged: firewalls, secure configuration, user access control, malware protection and security update management. If you have been doing those properly, Danzell is a tightening rather than a rewrite.

The timing matters, though. New assessment accounts created from 27 April 2026 use Danzell. Accounts opened before that date were given six months to finish certifying against the old requirements, which puts the end of that window in late October 2026. If you started an assessment earlier in the year and have let it drift, check with your certification body where you stand before assuming you can finish on the old paperwork.

If you want it from the source rather than from us, IASME's own summary of the April 2026 changes sets out what moved and why.

A five minute self-check

Run through these before you start the questionnaire:

  • Can you list every cloud service your business signs into? Including the ones bought on someone's card. If not, start there.
  • Does every one of them have MFA switched on where it is offered? Not just Microsoft 365. All of them.
  • Could you produce evidence that high and critical updates land within 14 days? Across every device, including the laptop belonging to whoever is on long-term leave.
  • Is anything still running an unsupported operating system? Windows 10 without Extended Security Updates fails outright, and that clock is running down too.
  • Does anyone use an admin account for everyday email and browsing? Still one of the most common reasons to fail.
  • Have leavers actually been removed, from everything rather than just from email?

If you answered badly to two or more of those, you are not in unusual company. Most businesses we assess fail on inventory rather than on effort: things nobody knew were in scope, on machines nobody was watching.

Is it worth the bother?

Cyber Essentials is not a magic shield, and we have never pitched it as one. What it is, is a floor. The controls it demands block a large share of the untargeted, opportunistic attacks that make up most of what actually hits small businesses.

It is also increasingly a commercial requirement rather than a nice-to-have. Government tenders require it. Larger customers are pushing it down their supply chains. Insurers ask about it. Whether or not you find the paperwork interesting, being unable to produce the certificate is starting to cost businesses work.

The tightening in Danzell is, if anything, overdue. MFA and prompt patching are not sophisticated asks in 2026. They are the two things that would have prevented most of the incidents we get called out to.

Where to start

If your renewal is coming up, do the cloud service inventory first. It is the least technical job on the list and it is where most of the surprises hide.

If you would rather someone else did it, we run a gap analysis against the current requirements before you go anywhere near the official questionnaire, so you find out where you would fail while it is still cheap to fix. Details on our Cyber Essentials service page, or get in touch and we will tell you honestly whether you are close or a long way off.

More reading
Related articles
Got an IT question?
Call us. We pick up.

20 minutes. No sales pitch. Just a straight answer to your IT question.

Book a 20-min call โ†’
Alex
Need help with your IT? Chat with me!