Support desk — Monday to Friday, 08:30 to 17:30Client AreaGet help now →

Cyber Essentials Danzell: What Changed, and Why 27 October Matters

The Cyber Essentials question set changed on 27 April 2026. The new version is called Danzell, it is version 3.3 of the scheme, and it is now what every new assessment uses.

If your assessment account was opened before that date, you have been able to carry on under the previous question set, Willow. That ends on 27 October 2026. After that, everyone is on Danzell.

Which makes the next few weeks the point at which a lot of businesses find out whether their certification reflected how their IT is actually run, or how it was described on a form.

What Danzell does and does not do

It adds no new controls. The five technical controls are the same as they have always been: firewalls, secure configuration, user access control, malware protection, and security update management.

What it changes is how rigorously those controls are assessed, and how much room there is to interpret your way to a pass. The questions are more precisely worded, the evidence expectations are higher, and several weaknesses that previously earned a note now fail you outright.

That last part is the important one. Under the old question set, an imperfect answer could still get you certified. Under Danzell, some answers end the assessment.

The two automatic failures

Multi-factor authentication, everywhere it is supported

If a cloud service supports MFA and you have not enabled it, you fail. There is no partial credit, no compensating-control argument, and no allowance for a senior person who found it inconvenient.

It covers Microsoft 365, Google Workspace, CRM systems and any cloud platform holding business data — and it applies to standard users, administrators and shared accounts alike. Shared and service accounts are where most businesses discover a problem, because they belong to nobody and MFA was never applied to them.

Patching inside fourteen days

High-risk and critical updates must be applied within 14 days of the vendor releasing them, across operating systems, applications, and firewall and router firmware.

A single missed high-risk patch on a single in-scope device, outside that window, is an automatic failure. “Automatic updates are switched on” is no longer a sufficient answer, because it is a description of a setting rather than evidence of an outcome.

Scope has tightened

If your organisation uses a cloud service to store or process its data, that service is in scope. Email platforms, file storage, software-as-a-service tools, remote access systems — all included.

A lot of businesses previously scoped cloud tools out on the reasoning that they did not own the infrastructure. That reasoning no longer holds, and scope errors are among the most common causes of a failed assessment.

Cyber Essentials Plus asks harder questions too

For Plus, assessors now validate that controls work in practice rather than on paper. Double sampling checks that remediation has been applied across the estate rather than only to the devices tested first — so fixing the three machines the assessor happened to look at will not carry you.

The 90-day completion window is a hard deadline. Miss it and the assessment restarts from the beginning.

Self-check

Would you pass Danzell today?

Tick only what you could evidence this afternoon — not what you intend to have sorted by the assessment.

0 of 8

Why 27 October is the date that matters

If your renewal falls close to it, when you open your assessment account decides which question set you are judged against. Opening in October and opening in November are two materially different assessments.

That is worth planning around, but it is not worth gaming. An organisation that scrapes through under Willow this year simply arrives at the same problem twelve months later, with less warning.

What to do between now and then

Deal with the two automatic-failure conditions first, because nothing else matters until they are closed. Audit where MFA actually is — not where you believe it is — paying particular attention to shared mailboxes, service accounts and third-party applications. Then establish whether you can demonstrate fourteen-day patching across everything, including the laptop belonging to someone who has been on leave for a fortnight.

After that, build an accurate inventory of in-scope devices and cloud services. Almost every remaining failure traces back to something nobody knew was there.

The wider point

Cyber Essentials is increasingly asked for in government contracts and in ordinary supply chain due diligence, and it is used by insurers and larger customers as a rough proxy for whether a business is serious. Losing it is considerably more disruptive than gaining it was.

Danzell is, on balance, a reasonable change. It closes the gap between businesses that hold the certificate and businesses that are actually protected. If those two things were already the same for you, this renewal will feel like paperwork. If they were not, it is better to find out now than in October.

If you would like an honest read on where you would currently stand, we do that assessment regularly and it carries no obligation to do anything about what we find.

Found this useful?

We write these because the same questions keep coming up. If one of them is yours, the answer is usually a short conversation away.

Keep reading