Version 3.3, a new name, mandatory MFA, a stricter patch clock and cloud in scope - what UK organisations need to do before they re-certify.
The most significant refresh of Cyber Essentials in years is already live. Version 3.3 of the Requirements for IT Infrastructure took effect on 27 April 2026, and the question set behind the verified self-assessment now carries a new name: Danzell, published on 13 February 2026. The headline theme is fewer soft edges - several requirements that were previously graded now fail an assessment outright. If you have not re-certified since April, these are the changes that will decide the outcome.
Already in force. The revised requirements apply to every assessment account created on or after 27 April 2026; the Danzell question set went live the day before, on 26 April. Assessments started before those dates ran under the previous version, so a certificate issued earlier in 2026 was not tested against any of this. Your existing certificate stays valid for its term - the new rules bite at renewal.
MFA has been recommended for years; since April 2026 it has been enforced. The requirement is to enable MFA wherever the cloud service supports it - not only for administrators, and not only where it happens to be free. If a platform offers MFA as a paid tier, the expectation is that you pay for and enable it. The practical task is to inventory every cloud service that stores or processes your data and confirm MFA is on for all accounts.
The 14-day rule itself is unchanged. High-risk and critical updates - vendor-rated "critical" or "high risk", carrying a CVSS v3 base score of 7.0 or above, or shipped with no severity detail at all - must be applied within 14 days of the vendor releasing them. What changed is the consequence, and the granularity.
Danzell splits the requirement into two questions, and makes both of them assessment-ending:
That second one is worth reading twice. "Associated files and extensions" pulls in the browser plug-ins, runtimes, add-ins and bundled libraries that sit inside applications and almost never appear on a patch report. Most estates have a reliable process for Windows and a much weaker one for the long tail of third-party software - and the long tail is now explicitly named in an auto-fail question.
Practically, a monthly patch window is no longer a defensible policy on its own, because the clock runs from each vendor's release date rather than your calendar. Continuous patch visibility, and an out-of-band lane for high and critical fixes, move from good practice to necessary. See our 14-day patching guide for the full detail on scope and timing.
The change with the sharpest teeth sits in the Cyber Essentials Plus audit, in the authenticated vulnerability scanning test case. Previously, when the assessor found missing patches on a sampled device, remediation and re-scanning focused on that sample. The devices that were never picked stayed as they were.
That gap is closed. Findings now have to be remediated across every in-scope device, within 30 days, and a second round of sampling - which deliberately includes devices that were not in the first sample - verifies it. If the vulnerabilities are still present, certification can be revoked.
The practical effect is that a fix-the-sample scramble no longer works, in either direction. You cannot patch twelve laptops for audit day, and you cannot quietly let them drift back afterwards, because the second sample is drawn from devices you did not choose.
Alongside this, organisations can no longer amend their verified self-assessment answers on the basis of what the CE Plus audit turns up. The self-assessment has to stand on its own, which means the honest answer at submission time needs to be the answer that survives an audit.
Bringing cloud services formally into scope reflects how organisations actually operate. Email, file storage, identity and line-of-business SaaS all now count, and each has to meet the same controls - MFA, secure configuration, user access control and patching of anything you are responsible for. The days of scoping cloud out of a Cyber Essentials submission are over.
Note: This is a practical summary of publicly announced changes, not legal or certification advice. The definitive source is the Cyber Essentials Requirements for IT Infrastructure v3.3 published by IASME and the NCSC - always confirm the current wording with your certification body.
Danzell is the new name for the verified self-assessment under the April 2026 update, replacing the previous question-set naming.
Your current certificate remains valid for its term. The new requirements apply when you create a new assessment on or after 27 April 2026.
Yes - if a cloud service only offers MFA at additional cost, the cost is not an accepted reason to leave it disabled.
No. It is still 14 days from the vendor's release date. What changed is that it is now enforced through two auto-fail questions - A6.4 for operating systems and router and firewall firmware, and A6.5 for applications and their associated files and extensions.
Every in-scope device, within 30 days, and a second sampling round including devices that were not in the first sample checks that you did. Certification can be revoked if the vulnerabilities remain.
APaaS Assure tracks MFA, patch status and cloud scope continuously across your estate, and ships the fixes to Intune or Configuration Manager - so re-certification is a formality, not a fire drill.
Book a demo