Compliance · Last updated

Cyber Essentials Danzell (v3.3): Every 2026 Change Explained

The Danzell question set replaced Willow on 27 April 2026. Mandatory cloud MFA, new password rules, and the 26 October deadline for the old set.

Nerdster Team

Cyber Essentials is still the UK government’s baseline security certification, and v3.3 has raised the bar again. You might already hold Cyber Essentials or Cyber Essentials Plus. You might be certifying for the first time. Either way, here is exactly what changed and what it means in practice.

Which question set you are on: Montpellier, Willow or Danzell

Before the changes themselves, the naming — because this is where most of the confusion sits, and getting it wrong can cost you a renewal.

IASME gives each Cyber Essentials self-assessment question set a name rather than a number, and the names have run in alphabetical order: Montpellier, then Willow, and now Danzell. So “Cyber Essentials 3.3”, “the Danzell question set” and “the April 2026 update” all describe the same thing — which is why searching for one often does not surface the other.

What matters in practice is which set your assessment account sits on:

  • Danzellpublished 13 February 2026, and applies to every assessment account created after 27 April 2026.
  • Willow — the previous set. If your account was opened before that date, you may still complete under Willow, but IASME’s grace period closes on 26 October 2026. After that, everything moves to Danzell.
  • Montpellier — the set before Willow. Retired; relevant only if you are comparing historical requirements.

If you certified last year and your renewal falls after October, you are renewing against a stricter standard than the one you passed. That is the single most common surprise we see, and it is worth checking now rather than in the assessment window.

Two dates to verify on the day you act: IASME’s own published articles have carried slightly different effective dates for the April change, so confirm against iasme.co.uk before you plan a renewal around a deadline.

What changed in Cyber Essentials v3.3

The National Cyber Security Centre (NCSC) updates the Cyber Essentials requirements every year. The v3.3 release took effect on 27 April 2026 through the Danzell question set, which replaces Willow. It closes the gaps attackers keep finding in already-certified organisations. Here are the headline changes.

MFA on every cloud service, no exceptions

Earlier versions asked for multi-factor authentication (MFA) on cloud services where it was available. Version 3.3 removes the wriggle room. MFA is now mandatory on every cloud service that stores, processes or transmits your data. That covers SaaS apps, cloud storage, and any web platform your team uses for work.

This one catches people out. Most firms enforced MFA on Microsoft 365 and their core line-of-business apps, then stopped there. The secondary tools got missed — project management software, CRM, accounting systems, file sharing. Under v3.3 every one of those needs MFA too.

The password rules, without over-engineering them

Cyber Essentials does not set one password length. The minimum depends on what else protects the account. Use at least 8 characters where MFA is enforced, or at least 12 characters where the password is the only control, paired with an automatic deny list of commonly breached passwords. There is no maximum length. There is no 14-character requirement anywhere in the scheme. And because v3.3 makes MFA mandatory across cloud services, most of your accounts will sit in the 8-character group.

Want the full picture? Our guide to Cyber Essentials password requirements covers the three password-quality options, the no-expiry and no-complexity guidance, the separate brute-force controls, and the lower bar for device-unlock PINs.

Own your cloud configuration, because v3.3 now tests it

Version 3.3 says plainly that you are responsible for configuring your cloud services securely, not just your on-premise kit. That means you:

  • Secure or disable every default admin account
  • Cut user permissions back to the minimum each person needs
  • Configure cloud storage so nothing is publicly reachable by accident
  • Turn on logging and audit trails wherever the platform offers them

All of that was implied before. Under v3.3 an assessor can test it during Cyber Essentials Plus.

BYOD controls, not just a BYOD policy

Bring Your Own Device rules have tightened. If personal devices touch your data, they either meet the full Cyber Essentials technical controls, or you limit them to a managed, sandboxed environment such as a virtual desktop or a managed mobile app. A BYOD policy document on its own no longer passes. You have to show the technical controls working.

Home workers and their routers in scope

Home working infrastructure now sits fully in scope. You do not have to manage home routers centrally. You do have to make sure they meet a minimum bar: default passwords changed, firmware current. Expect assessors to ask during a Plus assessment.

The work that now expects Cyber Essentials Plus

Cyber Essentials Plus certification is a contractual requirement across much of the government supply chain. NHS suppliers, for example, need it under PPN 014 alongside the separate Data Security and Protection Toolkit. Private sector clients in financial services, legal and professional services increasingly ask for it too.

The v3.3 changes follow where the attacks went. Breaches now run through cloud misconfigurations, weak authentication and unmanaged endpoints rather than the old network perimeter. The NCSC’s 2025 Annual Review makes the same point: most incidents still come back to the basics — unpatched systems, weak passwords and misconfigured cloud environments. Version 3.3 targets all three.

Prepare for your renewal with this checklist

If your certification renewal is coming up, work through this list with your IT team or provider:

MFA audit:

  • Inventory every cloud service used by your organisation
  • Confirm MFA is enabled for all user accounts on every service
  • Migrate any services that do not support MFA to alternatives that do

Password policy update:

  • Set a minimum of 12 characters for any account not covered by MFA, and at least 8 characters where MFA is enforced
  • Implement a breached password blocklist (Microsoft Entra ID and most modern directory services support this natively)
  • Disable legacy authentication protocols that bypass MFA

Cloud configuration review:

  • Audit admin accounts across all cloud platforms
  • Review sharing and access permissions on cloud storage
  • Enable audit logging on Microsoft 365, Google Workspace, and other core platforms
  • Check that no storage buckets or SharePoint sites are publicly accessible

Device management:

  • Confirm all corporate devices are enrolled in your mobile device management (MDM) or endpoint management solution
  • Establish technical controls for any BYOD access
  • Document home working arrangements and minimum router security requirements

Patching:

  • Confirm all operating systems and applications are patched within 14 days of critical updates (unchanged from v3.2 but frequently failed during assessments)

Expect a longer Cyber Essentials Plus assessment this year

Standard Cyber Essentials still runs as a self-assessment questionnaire, verified by a licensed assessor. Cyber Essentials Plus adds hands-on technical testing of your environment. Under v3.3 that testing now covers MFA on a sample of your cloud services, plus your cloud configuration controls.

So budget for a slightly longer Plus assessment than last year. Assessors have more scope to work through. Our Cyber Essentials Plus qualifier sets out the stages, the indicative IASME fees and a realistic turnaround.

Pass Cyber Essentials first time, with the gaps found first

We take London firms through Cyber Essentials and Cyber Essentials Plus, from the first gap analysis through readiness and assessment. Our managed IT service already enforces the MFA, password policies, cloud configuration and endpoint management that v3.3 asks for, so the day-to-day environment supports the certification work.

Not sure where you stand against v3.3 today? Take the free Cyber Essentials readiness check. It scores you against the five controls in a few minutes and shows you which gaps to close first.

Cyber EssentialsDanzellWillow question setcertificationMFAcompliance

FAQ

Cyber Essentials Danzell (v3.3): your questions answered

What is Cyber Essentials 3.3?

Cyber Essentials 3.3 is the 2026 update to the UK Government's NCSC-backed Cyber Essentials scheme. Effective from 27 April 2026 via the new Danzell question set, it tightens the requirements around cloud services, multi-factor authentication and passwords to reflect how modern cyber attacks actually happen.

What changed in Cyber Essentials 3.3?

The headline changes in Cyber Essentials 3.3 are: mandatory MFA across every cloud service, explicit responsibility for secure cloud configuration, tighter BYOD rules, and home-working infrastructure brought fully into scope. Password rules are unchanged in substance: at least 8 characters where the account is also protected by MFA, at least 12 characters where a password is the only control.

When did Cyber Essentials 3.3 come into effect?

Cyber Essentials 3.3 has been in effect since 27 April 2026, applying to new certifications and to renewals from that date. Assessment accounts created before 27 April 2026 kept six months to certify under the previous Willow requirements.

Does Cyber Essentials 3.3 require MFA on every service?

Yes. Under Cyber Essentials 3.3, multi-factor authentication is mandatory for every cloud service that stores, processes or transmits your organisation's data — including secondary tools like CRM, accounting and file-sharing platforms, not just Microsoft 365.

What is the minimum password length under Cyber Essentials 3.3?

The scheme requires one of three alternatives, not a combination: multi-factor authentication with a password of at least 8 characters; or a minimum of 12 characters on its own; or a minimum of 8 characters plus a deny list that blocks common passwords. You do not have to apply the same option everywhere — MFA on cloud services and a 12-character minimum on a legacy system is compliant. There is no 14-character requirement anywhere in the scheme.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report