- Version
- Requirements v3.3
- Question set
- Danzell (replaces Willow)
- Live from
- 27 April 2026
- Headline
- First automatic-fail rules
What changed, and when
Requirements for IT Infrastructure v3.3 applies to all assessment accounts created on or after 27 April 2026, using the new Danzell question set (which replaces the previous ‘Willow’ set / v3.2). Accounts opened before that date finish under the old requirements. The five technical controls are unchanged — but how they're marked has tightened.
The changes that catch people out
- MFA is now decisive. Multi-factor authentication must be used wherever it's available, and it's mandatory on cloud services. Missing MFA on an in-scope cloud service is an automatic fail. The scheme is pushing toward passwordless and passkeys as the direction of travel.
- Patching within 14 days. Failing to apply high-risk or critical updates within 14 days — for operating systems, applications, and router/firewall firmware — is an automatic fail.
- All cloud services in scope. A clearer definition of ‘cloud service’ has been added, and all of them are in scope. Vague or convenient exclusions no longer wash.
- Tighter scope and network rules. Ambiguous ‘untrusted connection’ language is gone; devices that can reach the internet are in scope, and excluded segments need clear justification and evidence of segregation.
- Backup elevated. Recovery guidance now sits earlier in the document, reflecting how much ransomware impact comes down to whether you can restore.
Stricter Cyber Essentials Plus
The audited level tightened too: your self-assessment answers are locked before technical testing begins and can't be amended afterwards; if the device sample fails, the re-test now includes both the original and a fresh random sample; and a second failure can revoke the underlying certificate. In short, there's less room to fix things on the day.
What to do about it
Most organisations pass if they get three things right before submitting: MFA everywhere (especially cloud), critical patching inside the 14-day window, and honest, complete scope. We assess you against v3.3 as it's actually marked, tell you plainly what to fix, and get you through — first time. This page is refreshed each April as the scheme updates.
Common questions
Do the April 2026 changes affect me if I'm already certified?
At your next renewal, yes — any assessment account created on or after 27 April 2026 uses v3.3 and the Danzell question set. It's worth checking MFA and patching against the new auto-fail rules before you renew.
What are the new automatic fails?
The main two: missing MFA on an in-scope cloud service, and failing to apply critical or high-risk patches within 14 days. Either one now fails the assessment outright.
What is the Danzell question set?
It's the 2026 self-assessment question set that maps to Requirements v3.3, replacing the previous ‘Willow’ set. The changes are billed as clarifications, but the stricter marking makes them significant in practice.
Did the five controls change?
No — firewalls, secure configuration, security update management, user access control and malware protection remain. What changed is the definitions, scope and how strictly they're marked.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day