If you certified last year, your renewal will look familiar. Same five controls. Same kind of questions. It is easy to assume it is the same form.
But it is not! On 26 April 2026, IASME moved Cyber Essentials to a new question set, called Danzell, and to version 3.3 of the NCSC requirements. Very little was added to what you have to do. What changed is what happens when you get something wrong.
This is a plain-English walk through the changes, who they affect, and what to check before you open your next assessment.
In short
- Two requirements now carry a much bigger penalty. Multi-factor authentication on cloud services and installing serious security updates within 14 days were always part of Cyber Essentials. What is new is that answering no to either one now fails the whole assessment, however well you do everywhere else.
- Cloud services now have a formal definition, and they cannot be left out of scope.
- The director signing your declaration now confirms you will stay compliant for the whole year, not just on the day.
- If you opened an assessment before 26 April, you can finish it on the old question set until 26 October 2026. After that, everyone is on the new one.
The date that matters: 26 October
The new question set applies to every assessment account created after 26 April 2026. Organisations that opened an account before that date were given six months to certify against the previous requirements. That window closes around 26 October.
Cyber Essentials certificates last 12 months, and IASME asks you to enter everything again at each recertification. So in practice, every renewal from now on is a Danzell assessment. The grace period only helps if you started before April and have not yet submitted.
What actually changed
1. Two answers now fail you automatically
Neither of these is new. Both have been part of Cyber Essentials for years, and every certified business was already expected to do them. What changed in April is how they are marked. IASME now treats them as automatic fails: a no on either one fails the assessment on its own, with no room for the assessor to weigh it against the rest of your answers.
Multi-factor authentication on cloud services. MFA is mandatory on every cloud service where it is available. That covers free tools, tools bundled with something else, and paid subscriptions alike. If a cloud service you use offers MFA and you have not switched it on for your users, the assessment fails.
Security updates within 14 days. Two questions, numbered A6.4 and A6.5, now carry an automatic fail. The first covers operating systems and the firmware on routers and firewalls. The second covers applications, including their extensions and add-ons. Updates that fix vulnerabilities the vendor rates as critical or high risk, or that score 7 or above on the CVSS scale, must be installed within 14 days of release. Answer no to either question and the whole assessment fails, however well you do elsewhere.
In practice this is where most small businesses need to look hardest. Laptops usually update themselves. The office router, a browser extension someone installed two years ago, or a desktop app that only updates when asked, often do not.
2. Cloud services are firmly in scope
The scheme now defines a cloud service as an on-demand, scalable service, hosted on shared infrastructure and accessed over the internet. Microsoft 365, Google Workspace, Xero, Dropbox, your CRM, your booking system: all cloud services.
They cannot be excluded from scope. “We will leave the cloud tools out” was never a good plan. It is now plainly not an option.
3. The declaration covers the whole year
A board member or equivalent has always signed off the assessment. That declaration now includes a line acknowledging responsibility for keeping every Cyber Essentials control in place throughout the certification period.
For a small business this usually means the director. The practical point is simple. The certificate is no longer a snapshot you can pass on the day and forget. Somebody is on record as owning it for twelve months.
4. Smaller changes worth knowing
- Passwordless sign-in. The requirements now give more weight to passkeys and other passwordless methods. Passwords are still allowed.
- Clearer scope. You describe your scope in more detail, name the legal entity being certified, and privately describe anything left out. Organisations inside a larger scope can now get their own individual certificate.
- Point in time. The certificate reflects your position on the date it is issued.
- Backups. The guidance on backups has been moved to a more prominent place. It is still guidance rather than a scored control.
- Cyber Essentials Plus. If your sample fails on updates, you fix the issues and are retested on a fresh random sample. You also cannot change your self-assessment answers after seeing the Plus results.
If you are renewing
Before you open your renewal, check five things. Each takes minutes to confirm and hours to fix under pressure.
- List every cloud service you use. Include the free ones and the ones only one person uses.
- Check MFA is switched on for every user of each one. Where the service offers it, it must be on.
- Look at your router and firewall. When was the firmware last updated? Is automatic updating on?
- Look at applications and extensions. Browsers, PDF tools, accounting software, anything installed locally. Remove what nobody uses. Set the rest to update automatically.
- Tell whoever signs the declaration what it now says. It is a year-long commitment, and they should know that before they sign.
If all five come back clean, your renewal should be as straightforward as last year’s.
If you started before 26 April
You have until 26 October to finish on the old question set. If you are close, finishing is sensible. If you are not, it is usually better to prepare for the new questions properly than to rush the old ones. You will face Danzell at your next renewal anyway.
If this is your first time
Nothing here should put you off. Around a quarter of UK businesses already run all five Cyber Essentials controls without ever having certified. The two automatic fails are exactly the two things most worth doing for your security in any case.
How I help
I prepare businesses for Cyber Essentials. I do not certify anyone. IASME and its accredited certification bodies do that, and the body that assesses you is not allowed to prepare you, which is why readiness is a separate piece of work.
A readiness sprint maps you against the five controls, fixes what needs fixing, and gets you to submission. It starts from £395. The IASME assessment fee is separate and paid directly to the certification body: currently £320 plus VAT for organisations with up to 9 employees, and £440 plus VAT for 10 to 49.
If you are not sure where you stand, I offer a free 30-minute gap check. You will leave knowing what would pass today, what would not, and what the work looks like.
Sources
- IASME, Important update: changes to Cyber Essentials for April 2026
- IASME, Cyber Essentials frequently asked questions (pricing and recertification)
- NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3
- DSIT, Cyber Security Breaches Survey 2025/26