In this article, we take a closer look at the most recent changes introduced in the 2026 Cyber Essentials Danzell question set, what they mean for your organisation, how these updates impact Cyber Essentials Plus (CE+) assessments, and what adjustments assessors may make when reviewing your submission this year.
Timeline
While Danzell officially comes into force on 27 April 2026, organisations already working towards the previous version, Willow, will have a 6-month grace period, until 27 October 2026, to complete their Cyber Essentials application. For those also applying for CE+, an additional 3 months is allowed, giving them until 27 January 2027 to finish their CE+ assessment. If you’re applying for Cyber Essentials certification through Evolve North, our consultants will advise you on which version of the questionnaire is most appropriate, based on your renewal dates and any other relevant deadlines.
The Cyber Essentials assessment is always aligned with the official Requirements for IT Infrastructure standard. With the release of Danzell, IASME has updated the question set to match version 3.3 of the requirements, ensuring businesses follow the latest best practices for securing their systems.
| Question Set Version | Assessment Release Date | Requirements Document Version |
|---|---|---|
| Danzell | From 27 April 2026 | v3.3 |
| Willow | April 2025 | v3.2 |
| Montpellier | April 2023 | v3.1 |
| Beacon | April 2021 | v2.1 |
What’s Changed?
Scoping
One of the biggest updates in Cyber Essentials Danzell is around legal entities and organisational clarity. Danzell requires that applicants list all connected legal entities in scope, including addresses and registration numbers. This supports assessors in understanding exactly what is being certified and makes the process clearer when applying for certification for a collective group of organisations.
New questions about organisational structure include:
- A1.3 How many employees are there in the organisation?
- A1.5 What is your organisation’s registered address?
- A1.5.1 Please provide the operational addresses, if different to your registered address.
- A1.6 Do you have more than one legal entity, including subsidiaries, within the scope of this assessment?
Individual certificates will also be provided for each entity certified within a group, as opposed to the current approach to listing each entity on one collective certificate.
In addition to this, scoping has been completely overhauled. Applicants are now expected to clearly document:
- Which networks are included
- Which networks are excluded
- How those exclusions (“subsets”) are technically segregated
- How many sites exist and how they interconnect
- How remote users connect to organisational systems
New questions about scoping include:
- A2.2 If you are certifying part of your organisation please write a detailed description of the scope here.
- A2.2.1 Please provide a description of any networks that have been excluded from the assessment by creating a sub-set.
- A2.3 Are the networks included in the scope of this assessment being used at the company locations you provided earlier?
- A2.3.1 Do you have an internet connection for each site in your organisation?
- A2.3.2 If no, please describe the way that your sites are connected.
- A2.4.2 How are home/remote workers connecting to your organisational data and services?
- A2.5.1 If you are certifying as partial organisation, please list the equipment used to create any sub-sets.
Multi-Factor Authentication
MFA has long been part of the Cyber Essentials framework. However, from April 2026, the marking criteria will change for both Cyber Essentials Danzell, and those still completing a Cyber Essentials Willow certification. If a cloud service offers MFA and it is not enabled for all users, the applicant will automatically fail the assessment.
This applies regardless of whether MFA is:
- Free or paid
- Built into the service or added via another tool (e.g. SSO with Microsoft 365)
IASME is now maintaining a list of cloud services and their MFA capability status, although this list is far from exhaustive.
It is worth highlighting the impact of the change around MFA on Education, particularly schools and colleges. Education has struggled to meet Cyber Essentials requirements because mandatory MFA is difficult to implement in schools where pupils are not permitted mobile devices in the classroom to receive authentication codes, and since the NCSC removed IP allow‑listing as an acceptable form of MFA in 2024, the only viable solutions left are to rely on managed/enterprise devices, an app on a trusted device, or to descope student networks (descoping is probably not as simple as it sounds). Contact us to discover how we guide education clients through the Cyber Essentials process and overcome the challenges unique to the sector.
Cloud Services
As well as changes to MFA, Cyber Essentials Danzell clarifies that social media accounts (e.g. Facebook, LinkedIn) are to be considered as cloud services.
Passwordless Authentication
Danzell also introduces clearer, more modern authentication guidance, reflecting the shift away from traditional password‑only security. The update recognises passwordless authentication, such as passkeys, biometrics, and hardware‑based authenticators, as a valid method for meeting login requirements across firewalls and external services, something that was not mentioned at all in previous versions.
Patching
Cyber Essentials Danzell makes it mandatory that organisations install high-risk or critical security updates for operating systems, router, firewall firmware and applications within 14 days of release. While the questions haven’t changed, it will become an automatic fail if you answer ‘No’ to either of the following:
- A6.4 Are all high-risk or critical security updates and vulnerability fixes for operating systems and router and firewall firmware installed within 14 days of release?
- A6.5 Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?
Cyber Essentials Plus
In addition to changes to the Cyber Essentials standard and self-assessment questionnaire, the Cyber Essentials Plus process will also be updated.
Non-compliances can no longer be accepted in Cyber Essentials basic if the applicant wishes to proceed to Cyber Essentials Plus.
Stricter rules will be imposed on retesting. Where devices have been found to be missing required updates, Assessors will now have to test a new random sample of devices, to ensure the updates identified have been applied to all devices, and not just those in the random sample.
Looking Ahead
While the 2026 Cyber Essentials Danzell update brings some interesting changes to scoping, we don’t expect a significant impact on the majority of our customers.
There are hints that more substantial changes may be on the way next year. The repositioning of backup guidance to a more prominent place in the Requirements for Infrastructure document could be an indication that resilience and recovery will take on greater importance in future versions of the scheme.
We also anticipate that Bring Your Own Device (BYOD) may be reworked in the 2027 update. At present, BYOD can be challenging for many organisations to implement within the Cyber Essentials framework. As remote and hybrid working continue to evolve, clearer expectations around BYOD are likely to become necessary.
Stay Informed
To keep up with the latest developments:
- Visit the IASME website
- Check Evolve North’s Resources page
- Or sign up to our newsletter for updates and guidance
We do not expect these changes to have a major impact on most of existing customers, although some in Education will need to consider a new approach to meeting their MFA requirements. We are ready to support those who need to make adjustments. As always, we will continue to monitor the scheme and provide timely advice as further updates are announced.
Want to know more? Get in touch with our expert team today at 01748 905 002 or info@evolvenorth.com. We’re here to make Cyber Essentials achievable and to help you stay protected.
Cyber Essentials Danzell is the 2026 version of the Cyber Essentials question set, coming into force on 27 April 2026. Released by IASME, it replaces the previous Willow question set and aligns with version 3.3 of the NCSC Requirements for IT Infrastructure. Key updates cover scoping, multi-factor authentication, cloud services, passwordless authentication and patching.
Cyber Essentials Danzell officially launches on 27 April 2026. Organisations already working towards the previous Willow question set have a 6-month grace period until 27 October 2026 to complete their Cyber Essentials application. Those also pursuing Cyber Essentials Plus get an additional 3 months, giving them until 27 January 2027 to finish their CE+ assessment.
Danzell introduces stricter requirements in several areas compared with Willow. The biggest changes are around scoping (applicants must now list all legal entities, addresses and registration numbers in scope), mandatory multi-factor authentication for any cloud service that offers it, explicit recognition of passwordless authentication, and automatic failure for missing critical patches beyond 14 days. Danzell also clarifies that social media accounts count as cloud services.
From April 2026, if a cloud service offers multi-factor authentication and it is not enabled for all users, the applicant will automatically fail the assessment. This applies whether MFA is free or paid, built into the service or added through another tool such as SSO with Microsoft 365. IASME maintains a list of cloud services and their MFA capability, though it is not exhaustive.
Organisations must install all high-risk or critical security updates within 14 days of release to pass Cyber Essentials Danzell. This covers operating systems, router and firewall firmware, and applications including associated files and extensions. Answering ‘No’ to either of the patching questions (A6.4 or A6.5) is now an automatic fail, so effective patch management processes are essential before submitting your assessment.
Schools and colleges struggle with the new MFA rules because pupils are often not permitted mobile devices in classrooms to receive authentication codes. Since the NCSC removed IP allow-listing as acceptable MFA in 2024, the remaining options are managed or enterprise devices, an app on a trusted device, or descoping student networks (which is rarely straightforward). Evolve North specialises in guiding education clients through these challenges. Contact us to discuss your situation.
Under Danzell, non-compliances can no longer be accepted in the basic Cyber Essentials assessment if the applicant wishes to proceed to Cyber Essentials Plus. Retesting rules are also stricter: where devices are found missing required updates, assessors must now test a new random sample of devices to confirm fixes have been applied across the estate, not just to the originally sampled devices.
The right version depends on your renewal date and whether you are pursuing Cyber Essentials Plus. If you start before 27 April 2026, you can still use Willow and have until 27 October 2026 to complete it (or 27 January 2027 for CE+). After that date, Danzell becomes mandatory. Evolve North consultants will advise which question set suits your timeline. Call 01748 905 002 or email info@evolvenorth.com.
Cyber Essentials Danzell FAQs
What is Cyber Essentials Danzell?
When does Cyber Essentials Danzell come into force?
What's the difference between Cyber Essentials Willow and Danzell?
How does the new MFA rule affect Cyber Essentials certification?
How quickly do security updates need to be installed under Danzell?
Why is Cyber Essentials harder for schools under Danzell?
How is Cyber Essentials Plus changing in 2026?
Which version of Cyber Essentials should I apply for in 2026?
