Skip to main content
Scheme updateCyber Essentials6 min read

Cyber Essentials Changes in 2026: Danzell and v3.3 Explained

What changed with the Danzell question set and v3.3 requirements from 27 April 2026: full cloud scope, MFA auto-fails, 14-day patching questions, and the responsible-person declaration.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 7 November 2026

At a glance

Recheck cloud scope, MFA and 14-day patching against Danzell rather than carrying forward old answers.

On this pageArticle contents

Share this article

LinkedInEmail

Cyber Essentials changed on 27 April 2026. The current question set is called Danzell, built on version 3.3 of the NCSC requirements. If your last certification, or the article you are reading, predates it, several things you think you know may now be wrong.

An active assessment account created before 27 April 2026 has six months to attain certification using the previous requirements. Accounts created from 27 April 2026 use Danzell.

1. Cloud services are fully in scope

Under Danzell, if your organisation's data or services live in a cloud service, that service is in scope. Microsoft 365, Google Workspace, your CRM, accounting platform, cloud storage, project tools, and HR system all count when they hold organisational data or services.

In practice, before any technical question, you need a complete list of the cloud services holding company data. Review subscriptions, invoices, browser bookmarks and supplier lists; this can reveal cloud services missing from a central inventory.

2. Missing cloud MFA is now an automatic fail

Where a cloud service offers MFA, or can be linked to a service that provides it, MFA must be applied to every administrator and user account. The assessment fails if either requirement is not met.

"MFA is available" and "most people have it" are both weak answers. Enforcement is what counts, evidenced from policy settings or conditional access reports rather than from one user's phone. Rolling MFA out across a company takes longer than people expect, so start weeks before you apply.

3. Patching has auto-fail questions of its own

Two auto-fail questions cover security updates: one for operating systems and firmware, one for applications. The substance is familiar: high-risk updates within 14 days. The assessment consequence is now sharper.

The 14-day rule covers vendor high or critical updates, anything with a CVSS v3 base score of 7.0 or above, and updates where the vendor gives no severity details at all. Cumulative updates inherit the highest severity of the fixes they contain.

"Updates are automatic" is a mechanism, not evidence. The failing pattern is edge cases: a laptop with updates paused, router firmware never touched, or a browser waiting weeks for a restart.

4. The responsible-person declaration now points beyond assessment day

The declaration approved by a board-level representative, business owner or equivalent now acknowledges the organisation's responsibility to maintain all Cyber Essentials controls throughout the certification period.

Cyber Essentials is still a point-in-time assessment at the certificate issue date. The practical change is that the named responsible person is also acknowledging responsibility for maintaining the controls through the certification period. The sensible response is a small maintenance rhythm: monthly checks on updates and unsupported software, quarterly reviews of accounts and admin access, and a scope update whenever the business adds sites, systems, or suppliers.

5. Smaller changes worth knowing

IASME removed "untrusted" and "user-initiated" from the internet-connection scoping language. For Cyber Essentials Plus, an update-management retest checks the original and a new random sample, and the verified self-assessment cannot be altered after Plus testing starts. Plus is a separate assessment route: the test itself is carried out by a certification body's assessor, who chooses the sample and decides the outcome. RightCyber's In-house workspace helps you prepare for Cyber Essentials Plus. It keeps the self-assessment record the assessor samples from, and reads your own answers back as a list of what the assessor will test.

What to actually do

First, rebuild your cloud service list. Second, verify MFA is enforced for every user on every service that offers it. Third, check patching at the edges: paused devices, firmware, browsers, and supplier-managed systems. Fourth, find unsupported software. Fifth, if you certified last year, do not copy last year's answers without reviewing the changed wording.

Renewal is where the renumbering and rewording matter most. RightCyber's In-house workspace can take last year's answers from the IASME portal's own answer export or assessment report. It works out which question set the document came from, maps a previous-set document through to the current questions, and refuses a document whose question set it cannot identify rather than guessing. Every row is confirmed one at a time, and on a renewal each question that was renumbered, reworded or given a changed requirement carries one line saying what changed, above IASME's own guidance.

For an end-to-end view of where these checks sit, read the current Cyber Essentials self-assessment walkthrough.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is an independent cyber security organisation and is not affiliated with or endorsed by IASME or the NCSC. This article is general guidance, not legal or professional advice. Official IASME and NCSC documentation remains authoritative.

Clarifications

Frequently asked questions

When did Cyber Essentials v3.3 take effect?
New Cyber Essentials assessments use the Danzell question set, aligned to the v3.3 requirements, from 27 April 2026.
What are the automatic fails in the 2026 question set?
The headline auto-fails include not applying MFA to every administrator and user account where a cloud service offers it or can link to an MFA provider, and failing the 14-day patching questions for operating systems, firmware, or applications.
Can I exclude cloud services from Cyber Essentials scope?
No. Under Danzell, cloud services that hold organisational data or services are in scope and cannot simply be excluded.
Is my old certification still valid?
Yes, until its expiry date. Your renewal should be prepared against the current Danzell question set rather than last year's wording.

Relevant RightCyber product

RightCyber Certification Workspace — In-house

The In-house workspace holds the current question set, with IASME’s own guidance shown per question where IASME publishes it. On a renewal it marks each question that was renumbered, reworded or given a changed requirement, so you review the new wording instead of copying last year’s answer.

Keep exploring

Browse the RightCyber Blog