Cyber Essentials changed on 27 April 2026. The current question set is called Danzell, built on version 3.3 of the NCSC requirements. If your last certification, or the article you are reading, predates it, several things you think you know may now be wrong.
An active assessment account created before 27 April 2026 has six months to attain certification using the previous requirements. Accounts created from 27 April 2026 use Danzell.
1. Cloud services are fully in scope
Under Danzell, if your organisation's data or services live in a cloud service, that service is in scope. Microsoft 365, Google Workspace, your CRM, accounting platform, cloud storage, project tools, and HR system all count when they hold organisational data or services.
In practice, before any technical question, you need a complete list of the cloud services holding company data. Review subscriptions, invoices, browser bookmarks and supplier lists; this can reveal cloud services missing from a central inventory.
2. Missing cloud MFA is now an automatic fail
Where a cloud service offers MFA, or can be linked to a service that provides it, MFA must be applied to every administrator and user account. The assessment fails if either requirement is not met.
"MFA is available" and "most people have it" are both weak answers. Enforcement is what counts, evidenced from policy settings or conditional access reports rather than from one user's phone. Rolling MFA out across a company takes longer than people expect, so start weeks before you apply.
3. Patching has auto-fail questions of its own
Two auto-fail questions cover security updates: one for operating systems and firmware, one for applications. The substance is familiar: high-risk updates within 14 days. The assessment consequence is now sharper.
The 14-day rule covers vendor high or critical updates, anything with a CVSS v3 base score of 7.0 or above, and updates where the vendor gives no severity details at all. Cumulative updates inherit the highest severity of the fixes they contain.
"Updates are automatic" is a mechanism, not evidence. The failing pattern is edge cases: a laptop with updates paused, router firmware never touched, or a browser waiting weeks for a restart.
4. The responsible-person declaration now points beyond assessment day
The declaration approved by a board-level representative, business owner or equivalent now acknowledges the organisation's responsibility to maintain all Cyber Essentials controls throughout the certification period.
Cyber Essentials is still a point-in-time assessment at the certificate issue date. The practical change is that the named responsible person is also acknowledging responsibility for maintaining the controls through the certification period. The sensible response is a small maintenance rhythm: monthly checks on updates and unsupported software, quarterly reviews of accounts and admin access, and a scope update whenever the business adds sites, systems, or suppliers.
5. Smaller changes worth knowing
IASME removed "untrusted" and "user-initiated" from the internet-connection scoping language. For Cyber Essentials Plus, an update-management retest checks the original and a new random sample, and the verified self-assessment cannot be altered after Plus testing starts. Plus is a separate assessment route: the test itself is carried out by a certification body's assessor, who chooses the sample and decides the outcome. RightCyber's In-house workspace helps you prepare for Cyber Essentials Plus. It keeps the self-assessment record the assessor samples from, and reads your own answers back as a list of what the assessor will test.
What to actually do
First, rebuild your cloud service list. Second, verify MFA is enforced for every user on every service that offers it. Third, check patching at the edges: paused devices, firmware, browsers, and supplier-managed systems. Fourth, find unsupported software. Fifth, if you certified last year, do not copy last year's answers without reviewing the changed wording.
Renewal is where the renumbering and rewording matter most. RightCyber's In-house workspace can take last year's answers from the IASME portal's own answer export or assessment report. It works out which question set the document came from, maps a previous-set document through to the current questions, and refuses a document whose question set it cannot identify rather than guessing. Every row is confirmed one at a time, and on a renewal each question that was renumbered, reworded or given a changed requirement carries one line saying what changed, above IASME's own guidance.
For an end-to-end view of where these checks sit, read the current Cyber Essentials self-assessment walkthrough.