Insights › Guide

Cyber Essentials v3.3 (Danzell): what changed in April 2026

Version 3.3, a new name, mandatory MFA, a stricter patch clock and cloud in scope - what UK organisations need to do before they re-certify.

The most significant refresh of Cyber Essentials in years is already live. Version 3.3 of the Requirements for IT Infrastructure took effect on 27 April 2026, and the question set behind the verified self-assessment now carries a new name: Danzell, published on 13 February 2026. The headline theme is fewer soft edges - several requirements that were previously graded now fail an assessment outright. If you have not re-certified since April, these are the changes that will decide the outcome.

Already in force. The revised requirements apply to every assessment account created on or after 27 April 2026; the Danzell question set went live the day before, on 26 April. Assessments started before those dates ran under the previous version, so a certificate issued earlier in 2026 was not tested against any of this. Your existing certificate stays valid for its term - the new rules bite at renewal.

The five changes that matter most

Auto-fail
Mandatory MFA on cloud services. Multi-factor authentication must be enabled wherever it is available - across SaaS, email, identity providers and remote access. The cost of an MFA add-on is explicitly not an acceptable reason to skip it. Not enabling available MFA fails the assessment.
Auto-fail
Two new auto-fail patching questions. The 14-day window itself is unchanged, but it is now enforced through two new questions - A6.4 for operating systems and router and firewall firmware, and A6.5 for applications, including their associated files and extensions. A "No" to either ends the assessment.
New scope
Cloud services formally defined and always in scope. For the first time the requirements define what a cloud service is, and such services can no longer be excluded from the assessment boundary.
CE Plus
No adjusting the self-assessment from CE Plus results. Organisations can no longer amend their verified self-assessment answers based on what the CE Plus audit finds - closing a long-standing loophole.
CE Plus
Retesting covers the whole estate, not the sample. Where the audit finds problems, they have to be fixed across all in-scope devices within 30 days, and a second sampling round - drawing both original and newly selected devices - confirms it. Certification can be revoked if the vulnerabilities are still there.

Mandatory MFA, in detail

MFA has been recommended for years; since April 2026 it has been enforced. The requirement is to enable MFA wherever the cloud service supports it - not only for administrators, and not only where it happens to be free. If a platform offers MFA as a paid tier, the expectation is that you pay for and enable it. The practical task is to inventory every cloud service that stores or processes your data and confirm MFA is on for all accounts.

Patching: same clock, no safety net

The 14-day rule itself is unchanged. High-risk and critical updates - vendor-rated "critical" or "high risk", carrying a CVSS v3 base score of 7.0 or above, or shipped with no severity detail at all - must be applied within 14 days of the vendor releasing them. What changed is the consequence, and the granularity.

Danzell splits the requirement into two questions, and makes both of them assessment-ending:

  • A6.4 - high-risk and critical security updates and vulnerability fixes for operating systems, and for router and firewall firmware, installed within 14 days of release.
  • A6.5 - the same 14-day obligation for applications, including any associated files and extensions.

That second one is worth reading twice. "Associated files and extensions" pulls in the browser plug-ins, runtimes, add-ins and bundled libraries that sit inside applications and almost never appear on a patch report. Most estates have a reliable process for Windows and a much weaker one for the long tail of third-party software - and the long tail is now explicitly named in an auto-fail question.

Practically, a monthly patch window is no longer a defensible policy on its own, because the clock runs from each vendor's release date rather than your calendar. Continuous patch visibility, and an out-of-band lane for high and critical fixes, move from good practice to necessary. See our 14-day patching guide for the full detail on scope and timing.

CE Plus: the sample is no longer the finish line

The change with the sharpest teeth sits in the Cyber Essentials Plus audit, in the authenticated vulnerability scanning test case. Previously, when the assessor found missing patches on a sampled device, remediation and re-scanning focused on that sample. The devices that were never picked stayed as they were.

That gap is closed. Findings now have to be remediated across every in-scope device, within 30 days, and a second round of sampling - which deliberately includes devices that were not in the first sample - verifies it. If the vulnerabilities are still present, certification can be revoked.

The practical effect is that a fix-the-sample scramble no longer works, in either direction. You cannot patch twelve laptops for audit day, and you cannot quietly let them drift back afterwards, because the second sample is drawn from devices you did not choose.

Alongside this, organisations can no longer amend their verified self-assessment answers on the basis of what the CE Plus audit turns up. The self-assessment has to stand on its own, which means the honest answer at submission time needs to be the answer that survives an audit.

Cloud is no longer optional scope

Bringing cloud services formally into scope reflects how organisations actually operate. Email, file storage, identity and line-of-business SaaS all now count, and each has to meet the same controls - MFA, secure configuration, user access control and patching of anything you are responsible for. The days of scoping cloud out of a Cyber Essentials submission are over.

How to prepare before you re-certify

  • Inventory your cloud services and confirm MFA is enabled everywhere it is available, including paid-for MFA options.
  • Tighten your patch process so high and critical updates are tracked against vendor release dates and applied within 14 days, estate-wide - not just on sampled devices.
  • Close the loopholes early. Assume your self-assessment answers must stand on their own and be provable against the whole estate.
  • Move to continuous evidence. With auto-fail conditions replacing graded tolerances, a point-in-time snapshot the week of the audit is a risk. Being able to show compliance on any given day is the safer position.

Note: This is a practical summary of publicly announced changes, not legal or certification advice. The definitive source is the Cyber Essentials Requirements for IT Infrastructure v3.3 published by IASME and the NCSC - always confirm the current wording with your certification body.

Frequently asked questions

What is "Danzell"?

Danzell is the new name for the verified self-assessment under the April 2026 update, replacing the previous question-set naming.

Do the changes apply to my existing certificate?

Your current certificate remains valid for its term. The new requirements apply when you create a new assessment on or after 27 April 2026.

Is paid MFA really required?

Yes - if a cloud service only offers MFA at additional cost, the cost is not an accepted reason to leave it disabled.

Has the 14-day patch window changed length?

No. It is still 14 days from the vendor's release date. What changed is that it is now enforced through two auto-fail questions - A6.4 for operating systems and router and firewall firmware, and A6.5 for applications and their associated files and extensions.

Do I have to fix findings on every device, or just the ones the assessor sampled?

Every in-scope device, within 30 days, and a second sampling round including devices that were not in the first sample checks that you did. Certification can be revoked if the vulnerabilities remain.

Sources: IASME - upcoming changes to the Cyber Essentials scheme and the official Cyber Essentials Requirements for IT Infrastructure (v3.3).

Walk into your 2026 assessment already compliant

APaaS Assure tracks MFA, patch status and cloud scope continuously across your estate, and ships the fixes to Intune or Configuration Manager - so re-certification is a formality, not a fire drill.

Book a demo