Cyber Essentials Just Got Its Teeth: What the Danzell Update Actually Changes

UK Compliance & Regulation

Cyber Essentials Just Got Its Teeth: What the Danzell Update Actually Changes

Hello, Mauven here. For years, businesses have been able to tell Cyber Essentials assessors that multi-factor authentication was “in progress” or “planned” and still walk away with a pass. As of 27 April 2026, that particular comfort blanket has been taken away, and frankly, it should have gone years ago.

What Actually Changed on 27 April 2026

The updated Requirements for IT Infrastructure, version 3.3, went live on 27 April 2026, assessed against a new question set informally known as “Danzell,” replacing the previous “Willow” set tied to version 3.2. Organisations with an assessment account created before that date have up to six months to complete certification under the older requirements. Everyone starting fresh after that date is assessed against the new standard.

The headline change is the scheme’s first ever automatic-fail questions. If a cloud service you use supports multi-factor authentication and you haven’t enabled it, that used to be a point for conditional remediation. Under the new rules, it’s a straight fail. No more “we’re getting round to it.”

Alongside that, a handful of other tightenings matter:

  • Cloud services can no longer be excluded from scope. The old “untrusted” and “user-initiated” qualifiers around internet connections have been removed, closing a gap where organisations quietly scoped their most exposed cloud tools out of the assessment.
  • Minimum password length rises to 12 characters, alongside explicit recognition of passwordless authentication methods including FIDO2 authenticators, biometric data, security keys, and push notifications.
  • Phishing-resistant MFA is expected for administrator accounts, reflecting the reality that admin credentials are the single most valuable target in almost every breach investigated.
  • The Cyber Essentials Plus audit methodology has also been tightened, catching the selective-patching habits some organisations were quietly relying on to pass the independent technical check.

Why This Update Actually Matters

The scheme’s five core controls, firewalls, secure configuration, access control, malware protection and security update management, haven’t changed. What’s changed is the assessment’s tolerance for the gap between what a business claims and what it’s actually done, specifically on identity.

That gap matters because of what the evidence keeps showing. Industry incident response data from 2026 consistently identifies missing or unenforced MFA as a primary root cause in the majority of investigated breaches involving compromised credentials, and a striking number of those cases involved organisations where MFA existed as an available setting but was never actually switched on. The Danzell update is a direct regulatory response to that specific, well-documented failure pattern, not a theoretical tightening for its own sake.

What This Means If You’re Certifying or Recertifying

If your business already holds Cyber Essentials and your current assessment account predates 27 April 2026, you have up to six months on your existing certificate cycle before the new rules bite. If you’re certifying for the first time, or recertifying after that date, budget time to actually enable MFA everywhere it’s available, not just document an intention to. An assessor under the new rules will fail you outright rather than flag it for later.

For a small business, this is genuinely good news dressed up as an inconvenience. The control that stops the largest share of credential-based attacks is now mandatory to actually implement, not just intend.

How to Turn This Into a Competitive Advantage

Businesses that certify cleanly under the tightened Danzell requirements can credibly tell clients their MFA coverage has been independently verified, not merely claimed. As more procurement questionnaires ask specifically whether MFA is enforced organisation-wide, a genuine Danzell-era certificate answers that question with evidence rather than assurance.

How to Sell This to Your Board

  1. The cost of compliance hasn’t risen. The cost of half-hearted compliance has. Enabling MFA that’s already available in your existing cloud tools costs nothing beyond staff time.
  2. This closes the gap insurers are already pricing against. Underwriters are increasingly applying premium loadings for organisations without current Cyber Essentials certification, specifically citing MFA and patching warranties.
  3. It’s a genuinely low-cost fix for the single most common root cause in credential-based breaches.

What This Means for Your Business

  1. Audit every cloud service you use for available MFA settings this week, and enable it everywhere it exists, not just on the systems an assessor is most likely to check.
  2. Move administrator accounts to phishing-resistant MFA specifically, since password-only or SMS-based codes no longer meet the spirit of the updated standard.
  3. Check your current assessment account creation date against the 27 April 2026 cut-off to understand which rule set actually applies to you.
  4. Review password policy for the new 12-character minimum, and consider passwordless options where your systems support them.
SourceArticle
IASMEImportant update: changes to Cyber Essentials for April 2026
IASMEUpcoming changes to the Cyber Essentials scheme: April 2026 update
NCSCCyber Essentials overview and requirements
SophosThe State of Ransomware 2026

Filed under

  • uk-business
  • smb-security
  • compliance-failure
  • credential-theft
  • vendor-risk