Published 27/02/2026 – est. 7 minutes to read.
Danzell Question Set and What you need to know
The National Cyber Security Centre (NCSC) and IASME have released their latest round of updates. The revised requirements for Cyber Essentials will apply to all assessments created on or after April 27th this year, based on a new Question Set called Danzell.
The 2026 update is not a complete overhaul of Cyber Essentials, but it does introduce certain clarifications and tighter controls that organisations will need to familiarise themselves with before beginning or renewing their certification.
The updates are being made to reinforce that Cyber Essentials has become a key part of the Government’s Cyber policy, and the NCSC has recently written to all FTSE 350 companies, encouraging them to embed Cyber Essentials into their supply chains. Reviews of certifications completed for larger organisations have also produced evidence that workarounds are being used to successfully complete Cyber Essentials Plus certifications, highlighting the need to strengthen the requirement to install security updates within 14 days and to enforce multi-factor authentication.
The changes to Cyber Essentials are important and welcome, making the certification even more valuable and helping certified organisations further strengthen their cybersecurity protections. Here are the key changes and what they’ll mean in practice.
Stronger enforcement of patching and MFA
Multi-factor authentication (MFA) has long been a core expectation. Under the updated rules, MFA must now be enabled wherever it is available for cloud services, even if only at an additional cost. If MFA is available, it must be enabled for all users; otherwise, the self-assessment will automatically fail.
Security update requirements have also been strengthened. Organisations must apply all high-risk or critical security updates within 14 days of release. This applies to operating systems, applications and network devices such as routers and firewalls, along with associated files and extensions.
Clarification of scope and certification boundaries
The 2026 update introduces changes to clarify scoping requirements. Applicants can now choose whether the scope applies to the whole organisation or part of it. They can then provide a detailed scope description with no character limit, which will be shown on their certificates. They will also be required to describe and justify areas of their infrastructure that are excluded from their scope, although this information will remain private.
Furthermore, all legal entities within scope must be formally declared on the self-assessment prior to certification. For larger group structures, there is also the option to request separate Cyber Essentials certificates for individual legal entities within a broader certified scope.
Clearer definition of “point in time” and ongoing compliance
Under the new update, the relevant point in time is defined as the certificate issue date. Organisations must ensure that all systems in scope are certified as compliant on that specific date. This “point in time” issue has caused some confusion in the past.
Also, the verified self-assessment declaration signed by a director or board-level representative will now explicitly acknowledge the organisation’s responsibility to maintain the controls throughout the whole certification period, not just at the point of certification.
New requirements for Cyber Essentials Plus
If the sample of devices fails the initial Cyber Essentials Plus technical assessment due to missing security updates, assessors will complete a technical vulnerability scan on a second sample of devices. If further inconsistencies are identified, organisations will be awarded a fail for Cyber Essentials Plus and may have their verified self-assessment certificate revoked.
In addition, organisations will no longer be permitted to amend their verified self-assessment answers based on the outcome of their Cyber Essentials Plus assessment. Self-assessments must be complete and accurate before the technical audit stage starts.
Updates to the IT Infrastructure Requirements (v3.3)
The latest edition of the Requirements for IT Infrastructure document (v3.3) will also apply to assessments started from April 27th. Several changes to the Infrastructure Requirements document make clarifications rather than impose new obligations.
Cloud services are more clearly defined as on-demand, scalable services accessible via the internet using shared infrastructure. Any cloud services used to store or process business data must be included within scope.
The language around scoping has also been simplified, with terms such as “untrusted” and “user-initiated” removed for clarity. The section previously labelled “web applications” has been renamed “application development”, bringing it more in line with the UK Government’s Software Security Code of Practice.
Guidance on backups, meanwhile, has been moved closer to the front of the document to underscore its importance in resilience and recovery planning. The user access control section now places greater emphasis on passwordless technologies such as passkeys.
Preparing for the 2026 Cyber Essentials standard
The 2026 update to Cyber Essentials does not radically change its structure, but it does seek to strengthen safeguards in areas frequently exploited by attackers: namely, weak authentication, delayed patching, and confusion around infrastructure.
Enabling MFA wherever possible, demonstrating that critical updates have been applied within 14 days, and ensuring the scope is clearly defined and documented will help ensure a smoother certification process once the new requirements come into force in April.
Get Cyber Essentials Certified!
We are an accredited Cyber Essentials Certification Body and provide unlimited support to help organisations achieve Cyber Essentials and Cyber Essentials Plus certification.
To discuss the updates of Cyber Essentials or to discuss our other services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
