Compliance · Last updated

Cyber Essentials Danzell (v3.3): Every 2026 Change Explained

The Danzell question set replaced Willow on 27 April 2026. Automatic fail for missing cloud MFA, passkeys, and the 26 October deadline for Willow.

Nerdster Team

Cyber Essentials is still the UK government’s baseline security certification, and v3.3 has raised the bar again. You might already hold Cyber Essentials or Cyber Essentials Plus. You might be certifying for the first time. Either way, here is exactly what changed and what it means in practice.

Which question set you are on: Montpellier, Willow or Danzell

Before the changes themselves, the naming — because this is where most of the confusion sits, and getting it wrong can cost you a renewal.

IASME gives each Cyber Essentials self-assessment question set a name as well as tying it to a version of the NCSC requirements: Montpellier (v3.1, from April 2023, replacing Evendine), then Willow (v3.2, from April 2025), and now Danzell (v3.3). So “Cyber Essentials 3.3”, “the Danzell question set” and “the April 2026 update” all describe the same thing — which is why searching for one often does not surface the other.

What matters in practice is which set your assessment account sits on:

  • Danzell — published 13 February 2026, and applies to every assessment account created from 27 April 2026.
  • Willow — the previous set. If your account was opened before that date, you have six months to complete under Willow, and IASME’s grace period closes on 26 October 2026. After that, everything moves to Danzell.
  • Montpellier — the set before Willow. Retired; relevant only if you are comparing historical requirements.

If you are comparing the two older sets, Willow’s changes over Montpellier were modest: it added guidance on passwordless authentication, defined what counts as a vulnerability fix, and brought fixes applied by a configuration change, not only by a patch, into the 14-day update rule.

If you last certified under Willow, your renewal will be assessed against Danzell, which is stricter on cloud MFA than the standard you passed. It catches people out, and it is worth checking now rather than in the assessment window.

What changed in Cyber Essentials v3.3

The National Cyber Security Centre (NCSC) reviews the Cyber Essentials requirements regularly. The v3.3 release took effect on 27 April 2026 through the Danzell question set, which replaces Willow. Here are the changes that matter.

Missing MFA on a cloud service is now an automatic fail

The written rule is not new: the requirements already said that authentication to cloud services must always use multi-factor authentication (MFA). What changed in April 2026 is how IASME marks it. MFA is “a mandatory requirement for all cloud services where it is available”, and an organisation that has not switched it on — “whether it is free, included, or a paid option” — now automatically fails the assessment. That covers SaaS apps, cloud storage, and any web platform your team uses for work.

This one catches people out. Most firms enforced MFA on Microsoft 365 and their core line-of-business apps, then stopped there. The secondary tools got missed — project management software, CRM, accounting systems, file sharing. Under Danzell, any of those that offers MFA without it being enforced is a fail, even where MFA is a paid upgrade.

The password rules, which did not change

Cyber Essentials does not set one password length. The minimum depends on what else protects the account. Use at least 8 characters where MFA is enforced. Where the password is the only control, use either at least 12 characters, or at least 8 characters with an automatic deny list that blocks common passwords. None of the options may cap the maximum length. There is no 14-character requirement anywhere in the scheme. And because MFA is required on cloud services, most of your accounts will sit in the 8-character group.

What v3.3 did change is passwordless sign-in: its definition now includes FIDO2 passkeys, which the requirements regard as MFA.

Want the full picture? Our guide to Cyber Essentials password requirements covers the three password-quality options, the no-expiry and no-complexity guidance, the separate brute-force controls, and the lower bar for device-unlock PINs.

Cloud services are defined, and cannot be left out of scope

Version 3.3 gives the scheme its first definition of a cloud service: an on-demand, scalable service on shared infrastructure, reached over the internet, accessed through an account (which can be credentials your organisation issues or a business email address) and storing or processing data for your organisation. It also states plainly that cloud services “cannot be excluded from scope”.

That definition reaches the tools staff sign up to with a work email address, not just the platforms IT runs. As before, you remain responsible for making sure every control is in place on them, even where the provider handles part of it. In practice that means you:

  • Change or disable default admin accounts, and protect admin access with MFA
  • Remove accounts that are no longer needed
  • Cut user permissions back to the minimum each person needs
  • Use separate accounts for administrative work

The smaller changes

Version 3.3 also points software developers to the Software Security Code of Practice, drops the reference to “untrusted connections” from the scope criteria, and puts more emphasis on backing up data. Backup is still recommended rather than required: it is not one of the five technical controls.

What did not change, but still trips people up

Personal devices (BYOD)

The BYOD rules were not rewritten in v3.3, and they remain one of the most misunderstood parts of the scheme. Personal devices that access your organisational data or services are in scope; devices used only for native calls, texts or MFA apps are not. So the practical choice is to bring those devices up to the Cyber Essentials controls, or to stop them accessing organisational data and services. A BYOD policy document on its own does not change what is in scope.

Home and remote workers

Every device used for your business at home or on the move, corporate or personal, is in scope. A router you give a home worker is in scope too. Other home routers, including the one the broadband provider supplied, are out of scope, which means the firewall control has to be applied on the device itself, usually with a software firewall. If staff connect through a corporate VPN, their internet boundary is the company firewall.

The work that expects Cyber Essentials

Cyber Essentials certification is a requirement across much of the government supply chain. PPN 014, which applies to central government departments, their agencies and NHS bodies, asks suppliers on contracts that handle personal or government information to hold Cyber Essentials or Cyber Essentials Plus. NHS suppliers handling patient data also need the separate Data Security and Protection Toolkit. Private sector clients in financial services, legal and professional services increasingly ask for it too.

The v3.3 changes follow where the attacks went: cloud services and the accounts that reach them. The NCSC’s 2025 Annual Review makes the wider point, noting that “cyber criminals continue to exploit basic weaknesses in systems”, and it cites insurer data showing that organisations with Cyber Essentials are 92% less likely to make a claim on their insurance.

Prepare for your renewal with this checklist

If your certification renewal is coming up, work through this list with your IT team or provider:

MFA audit:

  • Inventory every cloud service used by your organisation
  • Confirm MFA is enabled for all user accounts on every service
  • Migrate any services that do not support MFA to alternatives that do

Password policy update:

  • Require at least 8 characters where MFA is enforced; where it is not, require at least 12 characters, or at least 8 characters with a deny list of common passwords
  • Remove any maximum password length cap
  • If you use the deny-list option, switch on a banned-password list (Microsoft Entra ID and most modern directory services support this natively)
  • Disable legacy authentication protocols that bypass MFA

Cloud configuration review:

  • List every cloud service that stores or processes your data, and include it in scope
  • Audit admin accounts across all cloud platforms
  • Review sharing and access permissions on cloud storage
  • Check that no storage buckets or SharePoint sites are publicly accessible

Device management:

  • Confirm all corporate devices are enrolled in your mobile device management (MDM) or endpoint management solution
  • Establish technical controls for any BYOD access
  • Make sure home workers’ devices run a software firewall wherever the router is not one you supplied

Patching:

  • Confirm operating systems, firmware and applications get security updates within 14 days of release where the update fixes vulnerabilities the vendor rates critical or high risk, or scores CVSS v3 7 or above, or where the vendor gives no severity (unchanged from v3.2, and the control an authenticated vulnerability scan tests most directly)

What changed for Cyber Essentials Plus

Standard Cyber Essentials still runs as a self-assessment questionnaire, verified by an assessor. Cyber Essentials Plus adds hands-on technical testing of your environment, including a check that users are challenged for MFA on your cloud services. That MFA test is not new: it is already in the current Plus test specification, v3.2, published in April 2025.

What changed for Plus in April 2026 is the retest. If sampled devices fail, you must remediate, and the assessor then retests the original sample plus a new random sample, so fixing only the devices that were tested no longer works. A second failure revokes the underlying Cyber Essentials certificate. Your self-assessment answers must also be finalised before Plus testing starts, and cannot be changed afterwards. Our Cyber Essentials Plus qualifier sets out the stages, the indicative IASME fees and a realistic turnaround.

Pass Cyber Essentials first time, with the gaps found first

We take London firms through Cyber Essentials and Cyber Essentials Plus, from the first gap analysis through readiness and assessment. Our IT support in London already enforces the MFA, password policies, cloud configuration and endpoint management that v3.3 asks for, so the day-to-day environment supports the certification work.

If you supply the Ministry of Defence or a prime contractor, Cyber Essentials is also the first step to Defence Cyber Certification Level 0, which the MOD has asked its industry partners to hold by 31 December 2026.

Not sure where you stand against v3.3 today? Take the free Cyber Essentials readiness check. It scores you against the five controls in a few minutes and shows you which gaps to close first.

Cyber EssentialsDanzellWillow question setcertificationMFAcompliance

FAQ

Cyber Essentials Danzell (v3.3): your questions answered

What is Cyber Essentials 3.3?

Cyber Essentials 3.3 is the April 2026 version of the NCSC's Cyber Essentials requirements, assessed through IASME's Danzell question set from 27 April 2026. It defines cloud services for the first time, states that they cannot be excluded from scope and adds FIDO2 passkeys to passwordless authentication. It arrived with stricter IASME marking: a cloud service without MFA, where MFA is available, is an automatic fail.

What changed in Cyber Essentials 3.3?

The headline changes in Cyber Essentials 3.3 are: a formal definition of cloud services and a statement that they cannot be excluded from scope; FIDO2 passkeys added to passwordless authentication; the Software Security Code of Practice referenced for software development; and more emphasis on backups, which remain recommended rather than required. IASME's marking also changed, so missing MFA on a cloud service that offers it is now an automatic fail. The password rules did not change: at least 8 characters where MFA protects the account, otherwise at least 12 characters, or 8 characters with a deny list of common passwords.

When did Cyber Essentials 3.3 come into effect?

Cyber Essentials 3.3 has been in effect since 27 April 2026, applying to assessment accounts created from that date, whether for a first certification or a renewal. Assessment accounts created before then kept six months to certify under the previous Willow requirements.

Does Cyber Essentials 3.3 require MFA on every service?

On cloud services, yes. The requirements say authentication to cloud services must always use MFA, and since April 2026 the assessment fails automatically if MFA is available on a cloud service — whether free, included or a paid option — and is not switched on. That includes secondary tools like CRM, accounting and file-sharing platforms, not just Microsoft 365. The requirements also say you should always use MFA on administrative accounts and on accounts accessible from the internet.

What is the minimum password length under Cyber Essentials 3.3?

The scheme requires one of three alternatives, not a combination: multi-factor authentication with a password of at least 8 characters; or a minimum of 12 characters on its own; or a minimum of 8 characters plus a deny list that blocks common passwords. You do not have to apply the same option everywhere — MFA on cloud services and a 12-character minimum on a legacy system is compliant. There is no 14-character requirement anywhere in the scheme.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report