Cyber Essentials Danzell – What’s New?

In this article, we take a closer look at the most recent changes introduced in the 2026 Cyber Essentials Danzell question set, what they mean for your organisation, how these updates impact Cyber Essentials Plus (CE+) assessments, and what adjustments assessors may make when reviewing your submission this year.

Timeline

While Danzell officially comes into force on 27 April 2026, organisations already working towards the previous version, Willow, will have a 6-month grace period, until 27 October 2026, to complete their Cyber Essentials application. For those also applying for CE+, an additional 3 months is allowed, giving them until 27 January 2027 to finish their CE+ assessment. If you’re applying for Cyber Essentials certification through Evolve North, our consultants will advise you on which version of the questionnaire is most appropriate, based on your renewal dates and any other relevant deadlines.

The Cyber Essentials assessment is always aligned with the official Requirements for IT Infrastructure standard. With the release of Danzell, IASME has updated the question set to match version 3.3 of the requirements, ensuring businesses follow the latest best practices for securing their systems.

Recent Cyber Essentials Versions
Question Set Version Assessment Release Date Requirements Document Version
Danzell From 27 April 2026 v3.3
Willow April 2025 v3.2
Montpellier April 2023 v3.1
Beacon April 2021 v2.1

What’s Changed?

Scoping

One of the biggest updates in Cyber Essentials Danzell is around legal entities and organisational clarity. Danzell requires that applicants list all connected legal entities in scope, including addresses and registration numbers. This supports assessors in understanding exactly what is being certified and makes the process clearer when applying for certification for a collective group of organisations.

New questions about organisational structure include:

  • A1.3 How many employees are there in the organisation?
  • A1.5 What is your organisation’s registered address?
  • A1.5.1 Please provide the operational addresses, if different to your registered address.
  • A1.6 Do you have more than one legal entity, including subsidiaries, within the scope of this assessment?

Individual certificates will also be provided for each entity certified within a group, as opposed to the current approach to listing each entity on one collective certificate.

In addition to this, scoping has been completely overhauled. Applicants are now expected to clearly document:

  • Which networks are included
  • Which networks are excluded
  • How those exclusions (“subsets”) are technically segregated
  • How many sites exist and how they interconnect
  • How remote users connect to organisational systems

New questions about scoping include:

  • A2.2 If you are certifying part of your organisation please write a detailed description of the scope here.
  • A2.2.1 Please provide a description of any networks that have been excluded from the assessment by creating a sub-set.
  • A2.3 Are the networks included in the scope of this assessment being used at the company locations you provided earlier?
  • A2.3.1 Do you have an internet connection for each site in your organisation?
  • A2.3.2 If no, please describe the way that your sites are connected.
  • A2.4.2 How are home/remote workers connecting to your organisational data and services?
  • A2.5.1 If you are certifying as partial organisation, please list the equipment used to create any sub-sets.

Multi-Factor Authentication

MFA has long been part of the Cyber Essentials framework. However, from April 2026, the marking criteria will change for both Cyber Essentials Danzell, and those still completing a Cyber Essentials Willow certification. If a cloud service offers MFA and it is not enabled for all users, the applicant will automatically fail the assessment.

This applies regardless of whether MFA is:

  • Free or paid
  • Built into the service or added via another tool (e.g. SSO with Microsoft 365)

IASME is now maintaining a list of cloud services and their MFA capability status, although this list is far from exhaustive.

It is worth highlighting the impact of the change around MFA on Education, particularly schools and colleges. Education has struggled to meet Cyber Essentials requirements because mandatory MFA is difficult to implement in schools where pupils are not permitted mobile devices in the classroom to receive authentication codes, and since the NCSC removed IP allow‑listing as an acceptable form of MFA in 2024, the only viable solutions left are to rely on managed/enterprise devices, an app on a trusted device, or to descope student networks (descoping is probably not as simple as it sounds). Contact us to discover how we guide education clients through the Cyber Essentials process and overcome the challenges unique to the sector.

Cloud Services

As well as changes to MFA, Cyber Essentials Danzell clarifies that social media accounts (e.g. Facebook, LinkedIn) are to be considered as cloud services.

Passwordless Authentication

Danzell also introduces clearer, more modern authentication guidance, reflecting the shift away from traditional password‑only security. The update recognises passwordless authentication, such as passkeys, biometrics, and hardware‑based authenticators, as a valid method for meeting login requirements across firewalls and external services, something that was not mentioned at all in previous versions.

Patching

Cyber Essentials Danzell makes it mandatory that organisations install high-risk or critical security updates for operating systems, router, firewall firmware and applications within 14 days of release. While the questions haven’t changed, it will become an automatic fail if you answer ‘No’ to either of the following:

  • A6.4 Are all high-risk or critical security updates and vulnerability fixes for operating systems and router and firewall firmware installed within 14 days of release?
  • A6.5 Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?

Cyber Essentials Plus

In addition to changes to the Cyber Essentials standard and self-assessment questionnaire, the Cyber Essentials Plus process will also be updated.

Non-compliances can no longer be accepted in Cyber Essentials basic if the applicant wishes to proceed to Cyber Essentials Plus. 

Stricter rules will be imposed on retesting. Where devices have been found to be missing required updates, Assessors will now have to test a new random sample of devices, to ensure the updates identified have been applied to all devices, and not just those in the random sample.

Looking Ahead

While the 2026 Cyber Essentials Danzell update brings some interesting changes to scoping, we don’t expect a significant impact on the majority of our customers.

There are hints that more substantial changes may be on the way next year. The repositioning of backup guidance to a more prominent place in the Requirements for Infrastructure document could be an indication that resilience and recovery will take on greater importance in future versions of the scheme.

We also anticipate that Bring Your Own Device (BYOD) may be reworked in the 2027 update. At present, BYOD can be challenging for many organisations to implement within the Cyber Essentials framework. As remote and hybrid working continue to evolve, clearer expectations around BYOD are likely to become necessary.

Stay Informed

To keep up with the latest developments:

We do not expect these changes to have a major impact on most of existing customers, although some in Education will need to consider a new approach to meeting their MFA requirements. We are ready to support those who need to make adjustments. As always, we will continue to monitor the scheme and provide timely advice as further updates are announced.

Want to know more? Get in touch with our expert team today at 01748 905 002  or info@evolvenorth.com. We’re here to make Cyber Essentials achievable and to help you stay protected.

Cyber Essentials Danzell FAQs

What is Cyber Essentials Danzell?

Cyber Essentials Danzell is the 2026 version of the Cyber Essentials question set, coming into force on 27 April 2026. Released by IASME, it replaces the previous Willow question set and aligns with version 3.3 of the NCSC Requirements for IT Infrastructure. Key updates cover scoping, multi-factor authentication, cloud services, passwordless authentication and patching.

When does Cyber Essentials Danzell come into force?

Cyber Essentials Danzell officially launches on 27 April 2026. Organisations already working towards the previous Willow question set have a 6-month grace period until 27 October 2026 to complete their Cyber Essentials application. Those also pursuing Cyber Essentials Plus get an additional 3 months, giving them until 27 January 2027 to finish their CE+ assessment.

What's the difference between Cyber Essentials Willow and Danzell?

Danzell introduces stricter requirements in several areas compared with Willow. The biggest changes are around scoping (applicants must now list all legal entities, addresses and registration numbers in scope), mandatory multi-factor authentication for any cloud service that offers it, explicit recognition of passwordless authentication, and automatic failure for missing critical patches beyond 14 days. Danzell also clarifies that social media accounts count as cloud services.

How does the new MFA rule affect Cyber Essentials certification?

From April 2026, if a cloud service offers multi-factor authentication and it is not enabled for all users, the applicant will automatically fail the assessment. This applies whether MFA is free or paid, built into the service or added through another tool such as SSO with Microsoft 365. IASME maintains a list of cloud services and their MFA capability, though it is not exhaustive.

How quickly do security updates need to be installed under Danzell?

Organisations must install all high-risk or critical security updates within 14 days of release to pass Cyber Essentials Danzell. This covers operating systems, router and firewall firmware, and applications including associated files and extensions. Answering ‘No’ to either of the patching questions (A6.4 or A6.5) is now an automatic fail, so effective patch management processes are essential before submitting your assessment.

Why is Cyber Essentials harder for schools under Danzell?

Schools and colleges struggle with the new MFA rules because pupils are often not permitted mobile devices in classrooms to receive authentication codes. Since the NCSC removed IP allow-listing as acceptable MFA in 2024, the remaining options are managed or enterprise devices, an app on a trusted device, or descoping student networks (which is rarely straightforward). Evolve North specialises in guiding education clients through these challenges. Contact us to discuss your situation.

How is Cyber Essentials Plus changing in 2026?

Under Danzell, non-compliances can no longer be accepted in the basic Cyber Essentials assessment if the applicant wishes to proceed to Cyber Essentials Plus. Retesting rules are also stricter: where devices are found missing required updates, assessors must now test a new random sample of devices to confirm fixes have been applied across the estate, not just to the originally sampled devices.

Which version of Cyber Essentials should I apply for in 2026?

The right version depends on your renewal date and whether you are pursuing Cyber Essentials Plus. If you start before 27 April 2026, you can still use Willow and have until 27 October 2026 to complete it (or 27 January 2027 for CE+). After that date, Danzell becomes mandatory. Evolve North consultants will advise which question set suits your timeline. Call 01748 905 002 or email info@evolvenorth.com.


 
 

Arrange a FREE Consultation

Want to learn more about improving your organisation's security? Our team is here to answer your questions and explain the options available. In a free consultation, we'll help you understand the services we offer and how they can support your goals. It's a simple, no-obligation way to start exploring the right approach for your business.