Cyber Essentials is the UK Government-backed cyber security certification. It updates its requirements every year. But the changes that took effect on 27 April 2026 are some of the most significant since the scheme launched. A new question set, known as Danzell, replaced the previous Willow set. It brings stricter marking, new automatic failure conditions, and a clear shift towards passwordless authentication. If your business is Cyber Essentials certified, renewing soon, or certifying for the first time, here is what has changed and what you need to do about it. Our team holds Cyber Essentials Plus certification ourselves. We help London businesses through the assessment process, so this is the same guidance we give our own clients.A Quick Recap: What Is Cyber Essentials?Cyber Essentials is a UK Government-backed certification scheme. It is run by the NCSC (National Cyber Security Centre) and administered by IASME. It verifies that a business has five fundamental technical controls in place: firewalls, secure configuration, user access control, malware protection, and security update management. Insurers, larger clients and public sector contracts increasingly ask for it as proof of baseline cyber hygiene. It remains one of the most cost-effective ways for a small or medium-sized business to show it takes security seriously.The New Danzell Question Set ExplainedWhat Replaced Willow, and WhenThe Danzell question set went live for all new assessment accounts created on or after 27 April 2026. It replaces the Willow question set, which had been in use since April 2025. The five core controls have not changed. But the questions used to assess them, and the standard you need to meet to pass, have been tightened considerably.The Six-Month Transition Window Is ClosingWas your assessment account created before 27 April 2026? Then you are still being assessed against the older Willow requirements. You have six months from account creation to complete certification under that version. For most businesses in that position, this window closes around late October 2026. If you are partway through an assessment, check exactly when your account was created. Make sure you can complete it in time. Anyone starting a fresh assessment now will be assessed under the new Danzell requirements from the outset.The Biggest Change: MFA and Patching Are Now Auto-FailThis is the change causing the most disruption for businesses renewing their certification.Multi-Factor AuthenticationUnder the new rules, one gap is enough to fail your entire assessment. If a cloud service you use offers multi-factor authentication, and you have not enabled it, that alone causes an automatic failure. There is no chance to fix it within that assessment cycle. Previously, gaps in MFA coverage could sometimes be addressed as part of the assessment process. That is no longer the case. Every cloud service in scope needs MFA switched on before you start, not just your primary email or file storage.The 14-Day Security Update RuleTimely security updates have always been one of the five core controls. But the marking around it has been tightened in the same way. Known vulnerabilities across your entire scope now need fixing within 14 days. This can mean patching, or in some cases configuration and registry changes. Falling short of this on a critical system is now a hard failure, not a point for discussion.Passwordless Authentication and Passkeys Take PriorityThe user access control section now puts much greater emphasis on passwordless authentication. Passkeys and FIDO2 hardware security keys are explicitly named as the preferred method going forward. SMS-based codes remain acceptable as a second factor for now. But the direction of travel is clear. Businesses that move towards passkeys and phishing-resistant MFA sooner will find future renewals easier, not harder.Work With Speedster ITWant IT support that actually works?Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.Talk to Our Team Cloud Services Can No Longer Be Excluded From ScopeWhat Counts as a Cloud Service NowDanzell adds a much clearer, and much broader, definition of what counts as a cloud service. Microsoft 365, Google Workspace, your CRM, HR platform, accounting software, project management tools, even your business social media accounts, all count now. None of them can be excluded from your assessment scope simply because a third party hosts them. Some businesses have historically drawn their scope narrowly, around on-premises infrastructure only. Those businesses are likely to find their real assessment scope has grown considerably.Stricter Rules for BYOD and Personal DevicesPersonal devices used to access business data or systems (bring your own device, or BYOD) must now have all five core controls applied to them. That means a software firewall, up-to-date patching, malware protection, and a documented, enforced BYOD policy. A personal phone or laptop, used to check work email over an unmanaged home network, can no longer sit quietly outside the assessment scope.Backups, Scoping and Certification TransparencyA handful of further changes round out the update. Guidance on backups has moved earlier in the requirements document. This reflects how central reliable backups are to recovering from an incident. Scoping rules have been tightened generally too, with clearer requirements for describing exclusions and legal entities. This closes loopholes that previously let some organisations certify without genuinely meeting the standard across their whole business. There is also greater emphasis on certification transparency. It is now easier to see exactly what was, and was not, covered by a given certificate.What This Means for Your BusinessIf You’re Already CertifiedDo not assume your last certification automatically carries over. When you renew, expect a materially tougher assessment than last time. This is especially true around MFA coverage and patching timelines. Review your MFA setup across every cloud service you use, not just your main email platform, well before your renewal date.If You’re Certifying for the First TimeYou will be assessed against Danzell from the start. There is no advantage in rushing to beat a deadline under the old rules, unless your account is already created. Build your scope definition around the new, broader cloud services definition from day one. Do not wait to discover gaps partway through the assessment.How Speedster IT Can HelpWe hold Cyber Essentials Plus certification ourselves. We support London businesses through their own Cyber Essentials assessments, from an initial gap analysis through to closing out the technical requirements around MFA, patching and secure configuration. If you have not yet started the process, our guide on how to get Cyber Essentials certification in the UK covers the practical steps. If AI tools are part of your day-to-day operations, it is also worth reading our companion piece on the 10 AI security risks every London business should know. This is an area the Cyber Essentials scheme does not yet directly address. For a straightforward assessment of where your business stands against the new requirements, get in touch with our cyber security team.LouiseWith over 15 years at Speedster IT, I’ve built a career around helping businesses navigate the evolving world of technology. I publish all the content for the IT Support London Blog and Cyber Security Blog, where I share practical insights on infrastructure upgrades, cybersecurity trends, and smart IT strategies for growing companies.Ready to Talk?Let’s fix this properly.Book a free consultation with one of our engineers and find out what better IT support actually looks like.Get In Touch