Cyber Essentials is the UK government-backed scheme that certifies a business has the basic controls in place to stop the common, opportunistic attacks. It is run by the National Cyber Security Centre (NCSC) with IASME as the delivery partner, and increasingly it is a condition of public-sector contracts, supply-chain questionnaires and cyber insurance.
Each year the question set is updated and given a name. The current one, Danzell, was published on 13 February 2026 and applies to every assessment account created on or after 26 April 2026. Businesses that already had an assessment account open on that date were given six months to move across, so from late October 2026 everyone is on the new rules.
Most of the changes are tightening rather than new territory. Two of them, though, are now automatic fails — you answer "no" and the assessment stops — and they are the ones catching people out.
Change 1: MFA is mandatory on all cloud services
Previously, multi-factor authentication was required for administrator accounts and strongly expected elsewhere. Under Danzell it is required for every user on every cloud service where the service offers it — Microsoft 365, Google Workspace, Xero, Sage, your CRM, your VoIP portal, your backup console, the lot. Answer "no" for any of them and it is a fail.
Two practical points:
- "Where it is available" is not an escape hatch. Almost every business cloud service offers MFA now; the assessor will expect you to have turned it on, not to argue that it is optional.
- The guidance now explicitly encourages passwordless methods such as passkeys as the preferred approach. They are also the only kind of second factor that a fake login page cannot capture, which we covered in our post on phishing.
Change 2: critical and high-risk updates within 14 days — twice
There are now two separate auto-fail questions on patching:
- Are operating system and firmware updates rated critical or high-risk installed within 14 days of release?
- Are application updates rated critical or high-risk installed within 14 days of release?
The 14-day rule itself is not new. What is new is that it is asked as a hard yes/no, twice, and that firmware — routers, firewalls, switches, wireless access points — is called out explicitly. The box in the comms cupboard that nobody has logged into since 2021 is now a certification problem, not just a security one.
It follows that every device and piece of software in scope must still be supported by its vendor. A Windows 10 computer that has not been enrolled for extended updates is unsupported and fails the test outright; our Windows 10 post explains the fix.
Change 3: scope has to be honest and complete
Danzell removes the old character limit on the scope description and requires you to state clearly what is out of scope and why, and which legal entity is being certified. Cloud services are now formally defined and cannot be excluded — if your staff log into it, it is in.
Larger organisations can have individual certificates for each legal entity inside a group scope, which tidies up a long-standing awkwardness for groups of companies.
Change 4: no quiet tidying-up before the Plus audit
For Cyber Essentials Plus (the audited version):
- Your self-assessment answers are locked before testing begins, so they cannot be adjusted once the auditor starts finding things.
- Retests draw a new sample of devices, so fixing only the machines the auditor looked at last time does not work.
- "Point in time" now formally means the date the certificate is issued.
What has not changed
The five control areas are the same: firewalls, secure configuration, user access control, malware protection, and security update management. The scheme still costs a few hundred pounds for the basic certificate (the exact fee depends on your size and the certification body) and a Plus audit on top of that. Certificates still last twelve months.
A short readiness checklist
- MFA on, for everyone, on every cloud service — preferably passkeys or app-based with number matching.
- A list of every device, including firmware on network kit, with an owner and an update process that meets 14 days.
- No unsupported software or operating systems in scope (or a documented, segregated exception that the assessor will accept).
- Local administrator rights removed from day-to-day accounts.
- A written scope: what is in, what is out, why, and which company it is.
- Malware protection and automatic updates verified on every laptop, including the ones that live at home.
Where businesses actually fail
In our experience it is rarely the firewall. It is the three staff who "prefer not to have the app on their personal phone", the accountancy package whose MFA was never switched on because it lives on one person's desktop, the switch that has never had a firmware update, and the two laptops from the old office that still work and are still on Windows 10. Each is a five-minute conversation now and an automatic fail in the assessment.
If you would like a pre-assessment — we go through the Danzell questions with you, fix the obvious gaps and tell you honestly whether you would pass — that is a fixed-price piece of work, and it is far cheaper than a failed assessment and a resubmission. See our managed IT support page or get in touch.