Cyber Essentials Just Got Tougher: What Changed
If your business holds a Cyber Essentials certificate, or you have been thinking about getting one, there is something you need to know. The rules changed in April 2026, and the goalposts have shifted enough that businesses renewing their certification could now fail on things that were previously fine.
Here is what changed, why the timing still matters, and what you should do next.
What is Cyber Essentials?
Cyber Essentials is a government-backed certification scheme run by the National Cyber Security Centre (NCSC). It checks that your business has five core security controls in place: firewalls, secure configuration, user access control, malware protection, and patch management. Holding a certificate shows you have done the security basics correctly, and it is required by many government and public sector contracts. It is also increasingly expected by larger clients as a condition of working together.
What happened in April 2026?
On 27 April 2026, the certification body IASME replaced the previous Cyber Essentials question set — known as “Willow” — with a new version called “Danzell.” This is now version 3.3 of the NCSC’s requirements for IT infrastructure, and it introduced two changes that are catching businesses out.
Change 1: MFA is now a hard pass or fail
Multi-factor authentication (MFA) means using more than just a password to log in — for example, an authenticator app code or a text message. Under the new Danzell rules, if a cloud service you use offers MFA and you have not switched it on for every single user, you will automatically fail the User Access Control section of the assessment. Not a partial mark. An outright fail of the entire section.
What makes this particularly significant is what counts as a “cloud service.” Under Danzell, a cloud service is any externally hosted platform your organisation uses to store, process, or access data. That means:
- Microsoft 365 and Exchange Online
- Google Workspace
- Your CRM system
- Accounting software (Xero, QuickBooks, Sage Online)
- HR platforms
- Cloud file storage such as OneDrive, SharePoint, or Dropbox
- Project management tools
- Business social media accounts
If MFA is available on any of these — even as a paid add-on — and you have not enabled it for all users, you fail. No exceptions.
Change 2: Everything is now in scope
Earlier versions of Cyber Essentials allowed organisations to exclude certain cloud platforms from their assessment, provided they met specific conditions. Danzell closes that loophole. If your staff use a service for work and it handles company data, it is in scope. Full stop.
This forces businesses to properly map every cloud tool in use — which often turns out to be a longer list than expected, particularly when staff have signed up to apps without IT’s knowledge.
Why this matters even more now: the ICO connection
The ICO (the UK’s data protection regulator) published guidance in May 2026 making an explicit link between Cyber Essentials and GDPR compliance. The ICO stated that the five CE controls now represent what it considers “appropriate technical measures” under UK GDPR Article 32 — the legal requirement to protect personal data with appropriate security.
In plain terms: if the ICO investigates a data breach and finds you do not have the Cyber Essentials controls in place, that will be held against you. The ICO has indicated that future penalty notices will reference CE compliance as evidence of whether or not a business took reasonable steps to protect data.
This is a significant shift. Cyber Essentials is no longer just about the badge or winning public sector work. Under current guidance, it is part of how you demonstrate to a regulator that you take data security seriously under existing law. For information on your data protection obligations, our IT security page has more detail.
What we have already done for managed clients
If System Force IT manages your Microsoft 365 environment, MFA will already be enabled across your user accounts. We configure multi-factor authentication as a baseline default, so the Danzell MFA requirement should not catch you out on the Microsoft 365 side of things.
For clients going through a Cyber Essentials assessment, we can work through the full scope exercise with you — identifying every cloud service that falls under assessment and making sure each one is correctly configured before you submit. Passing first time is always the goal, and with the new rules it is worth taking the time to prepare properly.
What to check if you manage this yourself
If you look after your own IT, here is a practical starting checklist before your next Cyber Essentials assessment or renewal:
- Is MFA enabled on every cloud service that supports it? Check Microsoft 365, your accounts package, CRM, file storage, and project tools. If MFA is available anywhere and not switched on, you will fail.
- Have you mapped every tool your team uses for work? Apps people have signed up to without IT’s knowledge (“shadow IT”) can put you out of scope unexpectedly.
- Are high and critical patches being applied within 14 days? The patching window has not changed, but the assessment interprets it more strictly under Danzell.
- Do you know when your certificate is due for renewal? If it falls in the next six months, now is the time to run through the new requirements.
Our IT support team can run a readiness check with you before you submit your assessment. It is considerably easier — and less stressful — to close gaps before the assessment than to explain a failed result.
Need help with Cyber Essentials?
Whether you are going for Cyber Essentials for the first time or renewing under the new Danzell rules, we can help you prepare properly and avoid the common failure points. Get in touch with the team and we will take a look at where you stand.
If you are a business in Gloucestershire or across the UK looking for managed IT support that keeps your security and compliance on track, we would be happy to have a conversation.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


