IT Security
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Cyber Essentials 2026 Question Set Changes - Willow to Danzell Explained

The Cyber Essentials scheme changed on 27 April 2026. All assessment accounts created from that date are assessed against the new Danzell question set, which sits alongside version 3.3 of the NCSC's Requirements for IT Infrastructure document. IASME, the scheme's delivery partner, published the Danzell question set on 13 February 2026 after announcing the update in November 2025.

A quick note on names, because they cause confusion. Willow is not the new 2026 question set. Willow is the outgoing set, in use since 28 April 2025, when it replaced Montpellier. Danzell replaces Willow.

The five technical controls are unchanged. What has changed is how strictly some of them are marked, and how clearly scope is defined. Multi-factor authentication on cloud services is now an automatic failure point, two security update questions carry the same auto-fail status, cloud services have a formal definition and cannot be excluded from scope, and passwordless authentication now explicitly covers FIDO2 passkeys.

Organisations that created an assessment account on or before 26 April 2026 can still certify against Willow, with six months from account creation to complete. Everyone else, including every renewal purchased from 27 April 2026 onwards, answers the Danzell questions. That means most certified organisations will meet the new requirements at their next renewal.

Primary sources for this article:

Why This Matters

Cyber Essentials is a pass or fail assessment, and Danzell introduces automatic failure marking on specific questions. Under the previous approach, a weak answer might have prompted a query from the assessor. Under the 2026 rules, a single eligible cloud account without MFA fails the whole assessment.

Many UK SMEs hold certification because a contract demands it. Public sector frameworks, MOD supply chains and a growing number of commercial clients require Cyber Essentials or Cyber Essentials Plus as a condition of doing business. A failed renewal can therefore interrupt revenue as well as security posture.

The changes also affect documentation. Question wording has moved on, scope definitions have tightened, and assessors expect answers that reflect the v3.3 requirements. Policies and asset registers written for Willow or Montpellier need reviewing before you next submit.

1. From Willow to Danzell, the 2026 Timeline

IASME names each question set release. Montpellier ran from April 2023, Willow (aligned to Requirements v3.2) ran from 28 April 2025, and Danzell (aligned to Requirements v3.3) applies to assessment accounts created from 27 April 2026.

The transition follows the same pattern as previous years. Buy your assessment on or before 26 April 2026 and you answer the Willow questions, with six months to complete. Buy from 27 April 2026 and you answer Danzell. In practice, the last Willow certificates will be issued in late October 2026.

The NCSC's Requirements for IT Infrastructure v3.3, dated April 2026, is the technical standard behind Danzell. Its own change log lists six updates, all covered in the sections below.

2. MFA on Cloud Services Becomes an Automatic Failure

Version 3.3 states that authentication to cloud services must always use MFA where it is available. That requirement existed under Willow. What changes under Danzell is the marking: IASME has confirmed that an organisation which has not enabled MFA on a cloud service that supports it will automatically fail the assessment.

This applies to standard user accounts as well as administrator accounts. Where a password forms part of the MFA approach, it must be at least 8 characters with no maximum length. Acceptable second factors include a managed device, an app on a trusted device, a physically separate token or a known trusted account.

The practical task for SMEs is an account sweep. Every cloud service the business uses, from Microsoft 365 to accounting and HR platforms, needs MFA enforced for every user before the assessment is submitted.

3. Two Security Update Questions Become Auto-Fail

The 14 day patching rule itself has not changed. All software in scope must receive vulnerability fixes within 14 days of release where the update fixes issues the vendor rates critical or high risk, where the vulnerability has a CVSS v3 base score of 7 or above, or where the vendor gives no severity information at all.

What changes is enforcement. IASME has designated two security update questions as automatic failures in the Danzell marking scheme. Unsupported software on in-scope devices, or high-risk updates left uninstalled beyond 14 days, will now end the assessment rather than trigger a discussion.

Software must also be licensed and supported, with automatic updates enabled where possible. Where a vendor bundles fixes of mixed severity into one update, the whole update must go on within 14 days if any part of it is critical or high risk.

4. Cloud Services Are Formally Defined and Locked Into Scope

Version 3.3 adds a formal definition: a cloud service is an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet. For Cyber Essentials purposes it is accessed via an account, which may be credentials issued by your organisation or an email address used for business purposes, and it stores or processes data for your organisation.

The document then makes a definitive statement: if your organisation's data or services are hosted on cloud services, those services must be in scope. Cloud services cannot be excluded from scope. That captures SaaS platforms such as Microsoft 365, Dropbox and Gmail alongside IaaS and PaaS environments.

Responsibility for the five controls is shared with the provider depending on service type, but the applicant organisation is always responsible for making sure the controls are implemented. Where the provider implements a control on your behalf, you need contractual commitments or published security statements that confirm it.

5. Scope Wording Simplified and Partial Scope Must Be Justified

The scoping criteria no longer refer to untrusted connections. Under v3.3, the requirements apply to all in-scope devices and software that can accept incoming connections from internet-connected devices, can establish outbound connections to the internet, or control the flow of data between such devices and the internet. Removing the old qualifiers takes the ambiguity out of what counts.

Whole-organisation scope remains the recommended approach. Where parts of the infrastructure are excluded, you must justify the reason for a partial scope to your assessor, and a scope that leaves out end-user devices is not acceptable.

Home and remote working rules carry over from Willow. Corporate and BYOD devices used for business are in scope by default, a router you give a home worker is in scope, and other home routers are out of scope provided user devices run a software firewall. Accounts your organisation owns remain in scope even when a managed service provider uses them.

6. Passwordless Authentication Now Includes FIDO2

The definition of passwordless authentication has been updated to include FIDO2 authenticators. The standard treats FIDO2 authenticators as passkeys, and because user authentication is performed, they are regarded as MFA.

Other recognised passwordless methods include biometric authentication, physical security keys or tokens, push notifications and one-time codes. For SMEs moving away from passwords, this confirms that a well-implemented passkey deployment satisfies the user access control requirements.

Password rules for accounts that still use them are unchanged: brute-force protection plus either MFA, a minimum of 12 characters, or a minimum of 8 characters with a deny list of common passwords. Regular forced password expiry is still discouraged.

7. Software Development and Backups

The section previously focused on web applications now addresses software development and points to the UK Government's Software Security Code of Practice. Publicly available commercial web applications are in scope by default, while bespoke and custom components remain out of scope.

Backing up data is still not a technical requirement, but v3.3 emphasises its importance and moves the guidance earlier in the document. The NCSC recommends an appropriate backup solution, automatic backups where available, and disconnecting USB or external drive backups between uses.

8. What Stays the Same

The five technical controls are untouched: firewalls, secure configuration, security update management, user access control and malware protection. The two certification levels, Cyber Essentials self-assessment and the audited Cyber Essentials Plus, also continue as before.

Firewall requirements, device locking rules, admin account separation and the malware protection options (anti-malware software or application allow listing) are materially the same as under Willow. IASME has also clarified that the point in time a certificate refers to is the date it is issued.

For most well-run organisations, Danzell is a tightening of marking rather than a new standard. The risk sits with organisations that scraped through previous assessments with gaps an assessor let pass with caveats.

Cyber Essentials 2026 Changes at a Glance

AreaWas (Willow, v3.2)Now (Danzell, v3.3)
Question setWillow, from 28 April 2025Danzell, accounts created from 27 April 2026
Cloud service MFARequired where available, standard markingAutomatic assessment failure if not enabled where available
Security updates14 day rule for critical and high-risk fixesSame rule, two questions now marked as automatic failures
Cloud services in scopeRequired in scopeFormal definition added, explicit statement that cloud services cannot be excluded
Scope criteriaReferred to untrusted internet connectionsQualifiers removed, any in-scope device with inbound or outbound internet connectivity counts, partial scope must be justified
Passwordless authenticationRecognisedDefinition updated to include FIDO2, passkeys regarded as MFA
Software developmentWeb applications sectionReferences the Software Security Code of Practice, commercial web apps in scope by default
BackupsRecommendedStill not mandatory, guidance emphasised and moved earlier
Five technical controlsFirewalls, secure configuration, updates, access control, malware protectionUnchanged

What Organisations Must Do Before Recertifying

  1. Confirm which question set applies to you. If your assessment account was created on or before 26 April 2026, you certify against Willow and have six months from account creation. Any account created after that date uses Danzell and v3.3.
  2. Review your scope. List every cloud service that stores or processes organisational data, every corporate and BYOD device used for business, and any home working equipment you have issued. Check the list against the v3.3 scope conditions and prepare a justification if you intend anything less than whole-organisation scope.
  3. Switch on MFA across every cloud service. Audit every user account, standard and administrative, on every platform. One account without MFA where the service supports it is now an automatic fail.
  4. Check your patching against the 14 day rule. Confirm automatic updates are enabled where possible, remove unsupported software from in-scope devices, and evidence that critical and high-risk fixes are applied within 14 days of release.
  5. Update your documentation. Access control policies, asset registers, firewall rule records and BYOD policies should reference the v3.3 requirements, the cloud service definition and your passwordless or MFA approach.
  6. Brief the assessment owner. Whoever completes the self-assessment should read the Danzell question set and the v3.3 requirements before starting, and know which questions carry automatic failure marking.

Common Errors to Avoid

  • Assuming renewal uses last year's questions. Any assessment purchased from 27 April 2026 is marked against Danzell, and answers copied from a Willow submission may no longer pass.
  • Excluding cloud services from scope. Version 3.3 states plainly that cloud services cannot be excluded. Leaving your CRM or payroll platform out of the answers will surface at assessment and undermine your declaration.
  • Leaving MFA off accounts judged low risk. The auto-fail marking makes no distinction between a dormant standard user and a global administrator. Every eligible account needs MFA enforced.
  • Treating the 14 day patch window as flexible. Two security update questions now fail the assessment automatically, so a delayed monthly patch cycle can cost you the certificate.
  • Forgetting BYOD and home working devices. Personal devices that access organisational data or services are in scope, and a scope that omits end-user devices is not acceptable.
  • Letting documentation lag behind the controls. Assessors expect written policies that match your answers. Controls that exist in practice but not on paper are hard to evidence, especially at Cyber Essentials Plus.

How Policy Pros Can Help

Certification is easier when the paperwork already matches the standard. Our Cyber Essentials policies service produces the access control, patching, firewall and malware protection documents that sit behind your self-assessment answers, written against the current question set rather than a superseded one. If you are unsure what evidence assessors expect, start with our Cyber Essentials documents required guide.

For organisations preparing a submission, our IASME Cyber Essentials checklist walks through the assessment area by area, and our wider IT security policies service covers the documents that go beyond the scheme, from acceptable use to incident response.

The 2026 question set is also not the only change on the horizon for UK SMEs. The forthcoming Cyber Security and Resilience Bill will raise expectations for suppliers and managed service providers, and our Cyber Security and Resilience Bill SME guide explains how it fits alongside Cyber Essentials. Getting your Danzell documentation right now puts you ahead of both.

Frequently Asked Questions

What is the Willow question set?

Willow is the Cyber Essentials question set that applied to assessment accounts created between 28 April 2025 and 26 April 2026. It aligned to version 3.2 of the NCSC's Requirements for IT Infrastructure and replaced the earlier Montpellier set. It is now being phased out in favour of Danzell.

What is the Danzell question set and when did it start?

Danzell is the Cyber Essentials question set published by IASME on 13 February 2026, aligned to Requirements for IT Infrastructure v3.3. It applies to all assessment accounts created from 27 April 2026. Its headline changes are automatic failure marking for missing cloud MFA, two auto-fail security update questions, a formal cloud services definition and recognition of FIDO2 passkeys.

Can I still certify against Willow in 2026?

Only if your assessment account was created on or before 26 April 2026. Those accounts have six months from creation to complete the assessment against Willow, which means the last Willow certifications will be issued by late October 2026. Any account created from 27 April 2026 is assessed against Danzell.

Does Cyber Essentials 2026 make MFA an automatic fail?

Yes, where a cloud service supports multi-factor authentication and your organisation has not enabled it, the assessment fails automatically under the Danzell marking rules. This applies to standard user accounts as well as administrator accounts. Requirements v3.3 states that authentication to cloud services must always use MFA where available.

Do the five Cyber Essentials controls change under v3.3?

No. The five technical controls remain firewalls, secure configuration, security update management, user access control and malware protection. The 2026 update tightens marking and scope definitions around those controls rather than replacing them, so most changes affect how strictly existing requirements are assessed.

Share:
Trustpilot Reviews - 5 Stars