Cyber Essentials Danzell (v3.3): Every 2026 Change Explained
The Danzell question set replaced Willow on 27 April 2026. Mandatory cloud MFA, new password rules, and the 26 October deadline for the old set.
Nerdster Team
Cyber Essentials is still the UK government’s baseline security certification, and v3.3 has raised the bar again. You might already hold Cyber Essentials or Cyber Essentials Plus. You might be certifying for the first time. Either way, here is exactly what changed and what it means in practice.
Which question set you are on: Montpellier, Willow or Danzell
Before the changes themselves, the naming — because this is where most of the confusion sits, and getting it wrong can cost you a renewal.
IASME gives each Cyber Essentials self-assessment question set a name rather than a number, and the names have run in alphabetical order: Montpellier, then Willow, and now Danzell. So “Cyber Essentials 3.3”, “the Danzell question set” and “the April 2026 update” all describe the same thing — which is why searching for one often does not surface the other.
What matters in practice is which set your assessment account sits on:
- Danzell — published 13 February 2026, and applies to every assessment account created after 27 April 2026.
- Willow — the previous set. If your account was opened before that date, you may still complete under Willow, but IASME’s grace period closes on 26 October 2026. After that, everything moves to Danzell.
- Montpellier — the set before Willow. Retired; relevant only if you are comparing historical requirements.
If you certified last year and your renewal falls after October, you are renewing against a stricter standard than the one you passed. That is the single most common surprise we see, and it is worth checking now rather than in the assessment window.
Two dates to verify on the day you act: IASME’s own published articles have carried slightly different effective dates for the April change, so confirm against iasme.co.uk before you plan a renewal around a deadline.
What changed in Cyber Essentials v3.3
The National Cyber Security Centre (NCSC) updates the Cyber Essentials requirements every year. The v3.3 release took effect on 27 April 2026 through the Danzell question set, which replaces Willow. It closes the gaps attackers keep finding in already-certified organisations. Here are the headline changes.
MFA on every cloud service, no exceptions
Earlier versions asked for multi-factor authentication (MFA) on cloud services where it was available. Version 3.3 removes the wriggle room. MFA is now mandatory on every cloud service that stores, processes or transmits your data. That covers SaaS apps, cloud storage, and any web platform your team uses for work.
This one catches people out. Most firms enforced MFA on Microsoft 365 and their core line-of-business apps, then stopped there. The secondary tools got missed — project management software, CRM, accounting systems, file sharing. Under v3.3 every one of those needs MFA too.
The password rules, without over-engineering them
Cyber Essentials does not set one password length. The minimum depends on what else protects the account. Use at least 8 characters where MFA is enforced, or at least 12 characters where the password is the only control, paired with an automatic deny list of commonly breached passwords. There is no maximum length. There is no 14-character requirement anywhere in the scheme. And because v3.3 makes MFA mandatory across cloud services, most of your accounts will sit in the 8-character group.
Want the full picture? Our guide to Cyber Essentials password requirements covers the three password-quality options, the no-expiry and no-complexity guidance, the separate brute-force controls, and the lower bar for device-unlock PINs.
Own your cloud configuration, because v3.3 now tests it
Version 3.3 says plainly that you are responsible for configuring your cloud services securely, not just your on-premise kit. That means you:
- Secure or disable every default admin account
- Cut user permissions back to the minimum each person needs
- Configure cloud storage so nothing is publicly reachable by accident
- Turn on logging and audit trails wherever the platform offers them
All of that was implied before. Under v3.3 an assessor can test it during Cyber Essentials Plus.
BYOD controls, not just a BYOD policy
Bring Your Own Device rules have tightened. If personal devices touch your data, they either meet the full Cyber Essentials technical controls, or you limit them to a managed, sandboxed environment such as a virtual desktop or a managed mobile app. A BYOD policy document on its own no longer passes. You have to show the technical controls working.
Home workers and their routers in scope
Home working infrastructure now sits fully in scope. You do not have to manage home routers centrally. You do have to make sure they meet a minimum bar: default passwords changed, firmware current. Expect assessors to ask during a Plus assessment.
The work that now expects Cyber Essentials Plus
Cyber Essentials Plus certification is a contractual requirement across much of the government supply chain. NHS suppliers, for example, need it under PPN 014 alongside the separate Data Security and Protection Toolkit. Private sector clients in financial services, legal and professional services increasingly ask for it too.
The v3.3 changes follow where the attacks went. Breaches now run through cloud misconfigurations, weak authentication and unmanaged endpoints rather than the old network perimeter. The NCSC’s 2025 Annual Review makes the same point: most incidents still come back to the basics — unpatched systems, weak passwords and misconfigured cloud environments. Version 3.3 targets all three.
Prepare for your renewal with this checklist
If your certification renewal is coming up, work through this list with your IT team or provider:
MFA audit:
- Inventory every cloud service used by your organisation
- Confirm MFA is enabled for all user accounts on every service
- Migrate any services that do not support MFA to alternatives that do
Password policy update:
- Set a minimum of 12 characters for any account not covered by MFA, and at least 8 characters where MFA is enforced
- Implement a breached password blocklist (Microsoft Entra ID and most modern directory services support this natively)
- Disable legacy authentication protocols that bypass MFA
Cloud configuration review:
- Audit admin accounts across all cloud platforms
- Review sharing and access permissions on cloud storage
- Enable audit logging on Microsoft 365, Google Workspace, and other core platforms
- Check that no storage buckets or SharePoint sites are publicly accessible
Device management:
- Confirm all corporate devices are enrolled in your mobile device management (MDM) or endpoint management solution
- Establish technical controls for any BYOD access
- Document home working arrangements and minimum router security requirements
Patching:
- Confirm all operating systems and applications are patched within 14 days of critical updates (unchanged from v3.2 but frequently failed during assessments)
Expect a longer Cyber Essentials Plus assessment this year
Standard Cyber Essentials still runs as a self-assessment questionnaire, verified by a licensed assessor. Cyber Essentials Plus adds hands-on technical testing of your environment. Under v3.3 that testing now covers MFA on a sample of your cloud services, plus your cloud configuration controls.
So budget for a slightly longer Plus assessment than last year. Assessors have more scope to work through. Our Cyber Essentials Plus qualifier sets out the stages, the indicative IASME fees and a realistic turnaround.
Pass Cyber Essentials first time, with the gaps found first
We take London firms through Cyber Essentials and Cyber Essentials Plus, from the first gap analysis through readiness and assessment. Our managed IT service already enforces the MFA, password policies, cloud configuration and endpoint management that v3.3 asks for, so the day-to-day environment supports the certification work.
Not sure where you stand against v3.3 today? Take the free Cyber Essentials readiness check. It scores you against the five controls in a few minutes and shows you which gaps to close first.