CyberSpec

Cyber Essentials v3.3 (Danzell): what changed

From late October 2026 every Cyber Essentials assessment runs on v3.3. Two patching questions and cloud MFA became automatic fails. Here is the full list.

Mayank Tripathi · Founder, CyberSpec

5 min read

If your organisation started a Cyber Essentials assessment before 27 April 2026, it is running on the old "Willow" question set, and the window to finish it closes six months after that. From around 27 October 2026, every basic Cyber Essentials assessment is marked against version 3.3 of the requirements and the "Danzell" question set. The five controls have not changed. What has changed is how strictly some of them are marked, and which systems you are allowed to leave out.

This post lists what moved, what stayed the same, and what to check before you submit. For the controls themselves, start with the Cyber Essentials overview.

The dates that matter

IASME published the Danzell question set on 13 February 2026. It applies to assessment accounts created after 26 April 2026. Accounts created before that date keep the previous requirements for six months, which puts the end of the transition in late October. If you bought an assessment in early 2026 and have not finished it, check the creation date of your account in the IASME portal. That date, not the date you submit, decides which rules you are marked against.

The requirements document itself is the NCSC's Cyber Essentials: Requirements for IT Infrastructure v3.3, dated April 2026. The question set is the self-assessment form you answer; the requirements document is the standard the answers are judged against.

Three questions that now fail the whole assessment

Under Danzell, three areas are automatic fails. Get any one of them wrong and the assessment fails, however well you answer everything else.

Question area What it requires
MFA on cloud services MFA turned on for every cloud service where it is available, whether the service is free, included with something else, or paid for
A6.4: operating systems and firmware High-risk or critical updates for operating systems and router or firewall firmware installed within 14 days of release
A6.5: applications The same 14-day rule for applications, including their associated files and extensions

The 14-day rule is not new. It has been in the security update management control for years. What is new is that missing it now fails the assessment outright. The rule applies when the vendor describes the fix as critical or high risk, when the update fixes a vulnerability with a CVSS v3 base score of 7 or above, or when the vendor gives no severity information at all. If a single update bundles several fixes and any one of them is critical or high, the whole update falls under the 14-day rule.

Scope got harder to trim

Several changes stop organisations from shrinking the assessment until it describes something smaller than the real business.

  • Cloud services are in scope and cannot be excluded. v3.3 adds a new definition of cloud services, and they now sit inside the boundary by default.
  • Every legal entity in scope must be named, with its address and company number. Each one can get its own certificate for a small fee, marked as part of the wider scope.
  • Exclusions must be justified, and any network you exclude has to be shown to be separated from the systems that are in scope.
  • The scope description is now public. It appears on the digital certificate with no length limit. What you left out still has to be described, but that part is not published.
  • Publicly available commercial web applications are in scope by default. The old "web applications" section is now called "application development" and points to the UK Government's Software Security Code of Practice. Bespoke and custom components remain out of scope.

There is also a change to the declaration. The director or senior leader who signs the self-assessment now also confirms that the organisation will keep meeting the controls for the whole certification period, not only on the day the certificate is issued.

What did not change

The five technical controls are the same: firewalls, secure configuration, security update management, user access control, and malware protection. The definition of "critical" or "high risk" is still a CVSS v3 base score of 7 or above, or the vendor's own label. Unsupported software still has to be removed from devices, or moved into a separate part of the network that has no traffic to or from the internet. That last rule is the one we covered in end-of-life software fails Cyber Essentials, and Danzell does not soften it.

The user access control section now mentions passwordless methods such as passkeys, and the guidance on backups has moved earlier in the document. Neither adds a new requirement.

Cyber Essentials Plus: stricter on a second failure

There is no v3.3 version of the Cyber Essentials Plus test specification. IASME's own preparation page links its Danzell section to the v3.2 specification from April 2025, so that is the method assessors use today. Two things did change for Plus under the April 2026 update:

  • If a sample device fails the update management test, you remediate and the assessor retests the original sample plus a new random one. A second failure revokes your basic Cyber Essentials certificate as well.
  • Your self-assessment answers are locked before Plus testing starts and cannot be changed afterwards.

The external part of the Plus test was already strict, and it is worth restating because it is often described wrongly. The assessor scans every internet-facing service in scope, and any service with a vulnerability scoring 7.0 or more fails on the spot. There is no 14-day allowance at that step. The 14-day window only applies to the authenticated scan of sampled devices. We go through the full flowchart in what the Cyber Essentials scan has to pass.

What to check before you submit

  1. Find your assessment account's creation date and work out which question set applies.
  2. List every cloud service the business uses, including free ones, and confirm MFA is switched on for each one that offers it.
  3. Pull the date of the last critical or high update for each operating system, firewall, router and application, and confirm none is more than 14 days behind.
  4. Write the scope description as if a customer will read it, because one can.
  5. Check that every internet-facing service is running supported software.

What CyberSpec does about it

Steps 3 and 5 are the ones an outside scan can help with. Continuous scanning of your internet-facing assets flags known vulnerabilities with their CVSS scores and how long each one has been open, and an end-of-life check compares every fingerprinted service version against its vendor's support dates. Neither can see inside your network, check your cloud MFA settings, or log in to anything. Those stay with you.

For a quick look at what anyone on the internet can already see, the free website security check reads your TLS setup, certificate and security headers without scanning ports. Those are good-practice checks, not Cyber Essentials requirements, and the tool says so.

If your assessment account predates 27 April, the decision in front of you is simple: finish under Willow before the window closes, or plan to answer Danzell's stricter questions.

Sources: NCSC Requirements for IT Infrastructure v3.3, NCSC Cyber Essentials Plus Test Specification v3.2, and IASME's summary of the April 2026 changes. Where this page and those documents disagree, the documents are right.

Related