New Cyber Essentials Standard 2026: What's Changing and How to Prepare

 If your Cyber Essentials certification is due for renewal — or you're applying for the first time — there's an important update you need to know about. From 27 April 2026, all new Cyber Essentials and Cyber Essentials Plus applications will be assessed against a new version of the standard: Requirements for IT Infrastructure v3.3, paired with a new self-assessment question set known as "Danzell."

As an IASME-accredited certification body, we've broken down exactly what's changing, what it means for your infrastructure, and where to download the official documents so you can prepare in advance.

 What Is Changing?

Each year, IASME — the delivery partner for the NCSC — reviews the Cyber Essentials scheme based on breach data, assessor feedback, and audit findings. The five core technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) remain the same. However, the marking criteria have become stricter, and a number of key areas have been clarified or tightened for 2026.

 1. Multi-Factor Authentication (MFA) Auto-Fail

MFA is no longer just "expected" — it's mandatory wherever a cloud service offers it. If a cloud service supports MFA and it hasn't been enabled for all users, the assessment will now automatically fail, regardless of whether MFA is free, bundled, or a paid add-on.

 2. 14-Day Patching Auto-Fail

Two new auto-fail questions require that all critical or high-risk security updates be installed within 14 days of release. Selective or partial patching across your estate is no longer sufficient — assessors are now looking for consistent patching across all in-scope devices.

 3. Cloud Services Are Explicitly in Scope

Cloud services now have a formal definition under v3.3, and cannot be excluded from scope. This includes Microsoft 365, Google Workspace, CRM systems, HR platforms, accounting software, and any other on-demand, internet-accessible service that stores or processes your organisation's data.

 4. Updated Scoping Language

The terms "untrusted" and "user-initiated" have been removed as qualifiers for internet connections, simplifying and clarifying what counts as in-scope infrastructure.

 5. Stronger Cyber Essentials Plus Verification

The technical audit process for Cyber Essentials Plus has been revised to close gaps such as selective device patching ahead of assessment, ensuring the audit reflects your actual security posture across your whole estate — not just a sample.

 When Do the Changes Take Effect?

  • Before 27 April 2026: Assessment accounts created before this date will continue to be assessed under the current requirements and question set.
  • From 27 April 2026 onward: All new assessment accounts will be assessed against Requirements for IT Infrastructure v3.3 and the Danzell question set.

Once an assessment account is created, you typically have six months to complete it under the version that applied at the time of purchase.

If your renewal or first application falls close to this date, now is the time to review your infrastructure against the new requirements.

 Download the Official Documents

You can prepare in advance by reviewing the official documents before you begin your application:

📄 Requirements for IT Infrastructure v3.3 (PDF) — the full standard detailing what must be met under each of the five technical controls. [Download from the NCSC website]


-
📊 Danzell Question Set (PDF or Excel) — a copy of the new self-assessment questionnaire, available to download for preparation purposes ahead of your application. [Preview and download the question set via IASME]

We recommend downloading the Excel version of the question set and running a dry-run self-assessment internally before opening your official assessment account. This lets you identify and close any gaps — particularly around MFA coverage and patching consistency — without the pressure of a live assessment.

 Requirements for Your Infrastructure: What to Check Now

Based on the v3.3 changes, here's what we recommend reviewing across your organisation:

- Audit every cloud service your business uses — including tools staff may have signed up for informally — and confirm they are documented in scope.
- Enable MFA everywhere it's available, not just on admin and privileged accounts, but across all user accounts accessing cloud services.
- Review your patch management process to ensure critical and high-risk updates are applied within 14 days across your entire device estate, not just a sample.
- Update your scope documentation to reflect home workers, BYOD devices, and any recently adopted cloud platforms.
- Check default credentials on routers, firewalls, and network devices, particularly for home and remote workers.

 Which Certification Do You Need?

If you're unsure whether you need Cyber Essentials, Cyber Essentials Plus, or both, our related guide on cyber Essentials vs Cyber Essentials Plus:

https://cybercompliance.org.uk/products/cyber-essentials-cyber-essentials-plus-combined

This explains the key differences and helps you choose the right route for your organisation and contract requirements.

Get certified for Cyber Essentials
 Get certified for Cyber Essentials 
Cyber Essentials + Cyber Essentials Plus combined package

 Get Help Preparing for the New Standard

As an IASME-accredited certification body, we can help you review your infrastructure against the new v3.3 requirements, identify gaps before you apply, and guide you through certification under the Danzell question set — with no jargon and no surprises during assessment.

📧 Get in touch: mailto:info@cybercompliance.org.uk

 

Back to blog