IT Blog » Cybersecurity » Cyber Essentials changes 2026: What the new Danzell rules mean for your business
,

Cyber Essentials changes 2026: What the new Danzell rules mean for your business

A plain-English guide to the new requirements, based on the areas we’ve been helping clients review since the April changes

Cyber Essentials moved to the new Danzell question set on 27th April 2026, replacing Willow. A few months on, we’re helping clients work through the practical impact of those changes as they prepare for Cyber Essentials Basic and Plus assessments.

The five core controls haven’t changed: firewalls, secure configuration, user access control, malware protection, and patch management. What has changed is how strictly you’re marked.

In several areas, a gap that was previously recorded as a non-conformity may not have stopped you passing Cyber Essentials Basic, provided you had no more than two non-conformities. Under the new question set, that same gap would now result in an automatic failure, because non-conformities are no longer accepted.

For organisations preparing for Cyber Essentials Basic or Plus, the biggest changes are stricter patching requirements, wider MFA coverage, broader cloud service scope and less tolerance for gaps.

Here’s what’s different, the areas we’re reviewing with clients as they prepare for or go through assessment under the new rules, and how ramsac is helping.

What are the new Cyber Essentials patching requirements?

Patch management now needs continuous vulnerability visibility, not just automated Windows updates

Danzell is the name of the Cyber Essentials question set introduced in April 2026, replacing Willow. Under the previous Willow rules, missing the 14-day deadline for installing a high or critical security update would usually be recorded by the assessor as an issue to fix. For Cyber Essentials Basic, this was treated as a non-conformity rather than an automatic failure, provided you were not also certifying for Cyber Essentials Plus.

Under the Danzell Cyber Essentials question set, that flexibility has gone. If even one device or piece of software included in the assessment misses the 14-day window, the assessment fails immediately. Assessors no longer have discretion to overlook it, whether you are applying for Cyber Essentials Basic or Cyber Essentials Plus.

The key change for many organisations is that patching can no longer be treated as a basic Windows Update housekeeping task. To stay on top of the 14-day requirement, businesses need a reliable way to identify vulnerabilities across their estate continually, understand which are high or critical, and confirm that fixes have actually been applied.

What this looks like in practice: A business may have automated updates switched on for laptops, but still have out-of-date third-party applications, missed server updates, unsupported software, or vulnerabilities that Windows Update will never see. Network equipment still matters too: firewalls, routers, and similar infrastructure may need firmware updates that require planning and scheduled downtime.

How ramsac is helping: We’re helping clients move from reactive patching to continual vulnerability management. ramsac’s VMaaS is a key part of that approach, providing continuous visibility of live vulnerabilities and automatically fixing many of them through our remote monitoring and management tools. But effective vulnerability management is not just about automation. Some fixes need human judgement, planned maintenance, application compatibility checks, or careful handling where a change could affect a business-critical system. In those cases, ramsac can manage the intervention so vulnerabilities are addressed properly and gaps are not left open.

What are the Cyber Essentials MFA requirements?

Multi factor authentication is now all or nothing

Previously, MFA was expected on admin accounts, and user accounts but had more room for manoeuvre. Under Danzell, if any cloud service you use offers MFA, whether it’s free, included in your licence, or a paid extra, and it isn’t switched on for every user, the assessment fails immediately.

What this looks like in practice: A business may have MFA enabled on its main email and finance systems but use a smaller cloud tool elsewhere in the organisation that also offers MFA. Under the Cyber Essentials Danzell requirements, those less obvious services need the same level of attention.

How ramsac is helping: We’re helping clients review every cloud service in use, not just the obvious ones, and confirm MFA is switched on for every user wherever it’s available. This is a straightforward but essential housekeeping task ahead of assessment, and one we recommend completing well before renewal.

ramsac MFA image blog

Which cloud services are included in Cyber Essentials?

Cloud services can no longer be left out of the assessment, and the definition now includes social media

Under Danzell, any cloud service that handles business data must be included in the assessment, with no exclusions. The definition now explicitly includes business social media accounts too.

What this looks like in practice: Client-facing Facebook, LinkedIn, and other social media accounts can now fall within the cloud services included in the assessment. That means access control and MFA need to be reviewed for these accounts alongside the more obvious business systems.

How ramsac is helping: We’re helping clients build a fuller picture of the cloud services used across the business, including social media accounts, and check them against the MFA requirements above. This helps make sure the assessment reflects how the organisation actually works day to day.

The assessment now asks for more detail about your organisation

The Danzell Cyber Essentials question set asks for more organisational detail than Willow, including who has access to business data, which companies or trading entities are included, registered and operational addresses, how different sites are connected, and how remote workers connect.

What this looks like in practice: For groups with multiple trading entities, sites, or remote workers, the assessment now needs a clearer explanation of what is included and how people connect to company systems.

How ramsac is helping: We’re helping clients pull this information together ahead of renewal, so the assessment can be completed accurately and without last-minute uncertainty. This often includes confirming which entities, sites, users, and remote working arrangements should be reflected in the submission.

office people

A new question about NCSC Early Warning

Danzell explicitly asks whether you’ve signed up to the National Cyber Security Centre’s free Early Warning service, which sends real time alerts if malware or vulnerabilities are detected affecting your network.

What this looks like in practice: NCSC Early Warning is free and useful, but it is not always something businesses have already considered as part of their Cyber Essentials preparation. Danzell now asks about it directly.

How ramsac is helping: We’re encouraging clients to sign up to NCSC Early Warning ahead of assessment where appropriate. It is free, straightforward to set up, and a useful additional source of security visibility regardless of certification timing.

Passwordless authentication is now formally recognised

Danzell is the first version of the question set to formally recognise passwordless methods, such as passkeys, biometrics, and hardware-based authenticators, as valid ways of meeting login requirements. Previous versions didn’t mention them at all.

What this looks like in practice: Some organisations are already moving towards passkeys, biometrics, or hardware-based authenticators for security and convenience. Under Danzell, these methods are now explicitly recognised, but they still need to be planned carefully rather than treated as something that can simply be switched on.

How ramsac is helping: Where clients are already using or considering passwordless methods, we’re helping them understand how these fit with Cyber Essentials and how to describe them clearly in the assessment. Passwordless can be a strong option, but it should sit alongside proactive security monitoring, such as ramsac’s secure+ service, so unusual sign-in activity, compromised accounts, and risky behaviour can still be spotted and acted on quickly.

Cyber Essentials Plus checks are being done more thoroughly

For Cyber Essentials Plus, the technical checks are stricter too. Danzell introduces a second round of device checking, making it harder for inconsistent patching to go unnoticed.

Cyber Essentials Certified Plus Logo

For Cyber Essentials Plus, the technical checks are stricter too. Danzell introduces a second round of device checking, making it harder for inconsistent patching to go unnoticed.

What this looks like in practice: For Cyber Essentials Plus, it is important that patching is consistent across the full device estate, not just the most commonly used laptops and desktops. The additional checks mean older or less frequently used devices need to be kept in line too.

How ramsac is helping: We’re helping clients make sure patching is consistent across the whole estate before Cyber Essentials Plus checks take place. VMaaS provides continuous automated coverage, while ramsac can handle the scheduled maintenance and judgement calls that need a person involved before assessment.

Nothing carries over automatically from your last assessment

It’s tempting to assume answers that passed under Willow will still be fine under Danzell. They may not be. The update is stricter, with much less tolerance for gaps that were previously noted and forgiven.

What this looks like in practice: A renewal that felt routine under Willow may need a closer review under Danzell, particularly around patching, MFA coverage, and cloud services. The safest approach is to check against the current rules rather than rely on last year’s answers.

How ramsac is helping: We’re treating renewals as fresh assessments against the current Danzell question set. ramsac can run a gap analysis, give clients a clear view of where they stand, and help put the right fixes in place before submission.

The bottom line

The five controls at the heart of Cyber Essentials haven’t moved. What’s changed is the level of detail and consistency now expected: patching and MFA need to be complete, cloud services now include things like social media, and the assessment itself asks for more information than before.

None of this is unmanageable, but it does make proactive preparation more important.

If you’re not sure how your current setup compares with the Danzell requirements, ramsac can help you review the key areas, identify any gaps early, and put the right fixes in place before your assessment.

Understand your cybersecurity posture

Download our cybersecurity brochure to see how ramsac supports your organisation across the six core elements of cyber resilience: Govern, Identify, Protect, Detect, Respond and Recover. Discover how our services work together to reduce risk, strengthen security and help your business stay resilient.

FAQs: Cyber Essentials changes FAQ’s

What changed with Cyber Essentials in April 2026?

Cyber Essentials moved from the Willow question set to Danzell in April 2026. The five core controls remain the same, but the assessment is stricter in several areas, including patching, multi factor authentication, cloud services and the information organisations need to provide about their setup.

Do the Danzell changes affect both Cyber Essentials Basic and Cyber Essentials Plus?

Yes. The new question set applies to both Cyber Essentials Basic and Cyber Essentials Plus. Cyber Essentials Plus also includes more thorough technical checks, so organisations need to make sure controls are applied consistently across their estate.

What is the 14-day patching rule for Cyber Essentials?

High and critical security updates need to be installed within the required 14-day window. Under the new assessment approach described in the blog, organisations need better visibility of vulnerabilities across devices, applications and infrastructure, rather than relying only on standard Windows updates.

Does Cyber Essentials require MFA for every user?

Where a cloud service offers multi factor authentication, organisations need to make sure it is enabled appropriately across the users of that service. This means businesses should review smaller or less obvious cloud applications as well as core systems such as Microsoft 365.

Are social media accounts included in Cyber Essentials?

Business social media accounts can fall within the cloud services considered as part of the assessment. Organisations should therefore review who has access to them and whether appropriate authentication controls, including MFA where available, are in place.

Should we reuse the answers from our previous Cyber Essentials assessment?

It is better to review your environment against the current Danzell requirements rather than assume that previous answers still apply. Areas such as patching, MFA and cloud service coverage may need closer attention than they did during an earlier assessment.