Cyber Essentials: April 2026 Changes (v3.3 / Danzell)

Cyber Essentials updates every year, and April 2026 brought the biggest shift in three years. Here's what changed under Requirements v3.3 and the new ‘Danzell’ question set — and what it means for passing.

Version
Requirements v3.3
Question set
Danzell (replaces Willow)
Live from
27 April 2026
Headline
First automatic-fail rules

What changed, and when

Requirements for IT Infrastructure v3.3 applies to all assessment accounts created on or after 27 April 2026, using the new Danzell question set (which replaces the previous ‘Willow’ set / v3.2). Accounts opened before that date finish under the old requirements. The five technical controls are unchanged — but how they're marked has tightened.

The changes that catch people out

  • MFA is now decisive. Multi-factor authentication must be used wherever it's available, and it's mandatory on cloud services. Missing MFA on an in-scope cloud service is an automatic fail. The scheme is pushing toward passwordless and passkeys as the direction of travel.
  • Patching within 14 days. Failing to apply high-risk or critical updates within 14 days — for operating systems, applications, and router/firewall firmware — is an automatic fail.
  • All cloud services in scope. A clearer definition of ‘cloud service’ has been added, and all of them are in scope. Vague or convenient exclusions no longer wash.
  • Tighter scope and network rules. Ambiguous ‘untrusted connection’ language is gone; devices that can reach the internet are in scope, and excluded segments need clear justification and evidence of segregation.
  • Backup elevated. Recovery guidance now sits earlier in the document, reflecting how much ransomware impact comes down to whether you can restore.

Stricter Cyber Essentials Plus

The audited level tightened too: your self-assessment answers are locked before technical testing begins and can't be amended afterwards; if the device sample fails, the re-test now includes both the original and a fresh random sample; and a second failure can revoke the underlying certificate. In short, there's less room to fix things on the day.

What to do about it

Most organisations pass if they get three things right before submitting: MFA everywhere (especially cloud), critical patching inside the 14-day window, and honest, complete scope. We assess you against v3.3 as it's actually marked, tell you plainly what to fix, and get you through — first time. This page is refreshed each April as the scheme updates.

Common questions

Do the April 2026 changes affect me if I'm already certified?

At your next renewal, yes — any assessment account created on or after 27 April 2026 uses v3.3 and the Danzell question set. It's worth checking MFA and patching against the new auto-fail rules before you renew.

What are the new automatic fails?

The main two: missing MFA on an in-scope cloud service, and failing to apply critical or high-risk patches within 14 days. Either one now fails the assessment outright.

What is the Danzell question set?

It's the 2026 self-assessment question set that maps to Requirements v3.3, replacing the previous ‘Willow’ set. The changes are billed as clarifications, but the stricter marking makes them significant in practice.

Did the five controls change?

No — firewalls, secure configuration, security update management, user access control and malware protection remain. What changed is the definitions, scope and how strictly they're marked.

Related

Certify cleanly under the 2026 rules

Tell us your setup and we'll check it against v3.3 as it's actually marked — MFA, patching and scope — so you pass first time.