Cyber Essentials v3.3: what changed in April 2026, and why it matters
From 27 April 2026, Cyber Essentials assessments use the updated v3.3 requirements and the new Danzell question set. The five controls are unchanged, but the marking is tougher, and some things now mean an automatic fail.
From 27 April 2026, Cyber Essentials assessments use the updated v3.3 requirements and the new Danzell question set. The five controls are unchanged, but the marking is tougher, and some things now mean an automatic fail.
What changed on 27 April 2026
Cyber Essentials is updated every year by IASME, the NCSC's delivery partner. From 27 April 2026, new assessment accounts follow Requirements for IT Infrastructure v3.3 and a new self-assessment question set called Danzell, which replaces the previous Willow set. Accounts created before that date keep the earlier version and have up to six months to finish. The five core controls are the same, but several areas are now marked more strictly, and the scope rules are clearer.
MFA is now a hard fail
This is the big one. If multi-factor authentication is available on a cloud service that is in scope and you have not enabled it, that is now an automatic fail, with no partial credit. MFA must be used wherever it is offered, and cloud sign-in must always use it. It reflects how most real attacks now start: with stolen or guessed credentials.
Critical updates: 14 days, or fail
Missing high-risk or critical security updates is also now an automatic fail. Fixes for operating systems, router and firewall firmware, and applications need to be applied within 14 days of release. Patching that quietly slips is one of the most common reasons a business is exposed, and now one of the clearest ways to fail.
Cloud is in scope, with no exceptions
v3.3 adds a formal definition of a cloud service, and makes clear that any internet-accessible service that stores or processes your data is in scope and cannot be excluded. That accountability stays with you even when the service is run by a third party. The old scoping language around untrusted and user-initiated connections has been removed to reduce ambiguity.
What it means for you
If your renewal or first certification falls after 27 April 2026, you are assessed under v3.3. In practice: switch MFA on everywhere it is offered, apply critical updates within 14 days, and make sure you have a clear list of every cloud service you use. The businesses that treat last year's answers as still valid are the ones that fail first time.
How we help
As a Cyber Essentials Certification Body, we assess against the current version and tell you plainly where you stand. Under v3.3 a gap analysis first is well worth it: we check your setup against the new marking before you submit, so a missing MFA setting or an out-of-date system is something we fix together, not a surprise fail.
Common questions
Does v3.3 change the five controls?
No. The five control themes are the same. What has changed is that the marking is stricter and the scope and cloud rules are clearer.
Will missing MFA really fail me?
Yes. If MFA is available on an in-scope cloud service and it is not enabled, that is now an automatic fail.
I certified before April 2026, am I affected?
Your certificate stays valid, but your next renewal after 27 April 2026 will be assessed under v3.3, so it is worth preparing now.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Certifying or renewing under v3.3? Let's get you ready.
Cyber Essentials to set the baseline, testing to prove it, honest advice throughout.