Cyber Essentials Danzell: what Cambridge SMEs must fix before autumn
Autumn is when a lot of Cambridgeshire firms recertify. The certificate is twelve months old, a tender pack has appeared, and someone in finance has asked whether the cyber insurance form still holds.
Cyber Essentials for small business used to feel like a tidy questionnaire. The five controls are the same. From 27 April 2026 the marking is not.
New assessment accounts now use the Danzell question set, on NCSC Requirements v3.3. Two answers fail you outright: multi-factor authentication missing on any cloud service that offers it, and high or critical patches left longer than 14 days. Windows 10 without Extended Security Updates fails as well, because the software is no longer supported.
If you bid into life sciences or a larger supply chain, that is the difference between sending the certificate and explaining why you do not have one.
What actually changed this year
Willow was last year’s question set. Danzell replaced it for accounts opened from 27 April 2026. IASME published Danzell on 13 February. The NCSC published the v3.3 requirements to go with it.
The five technical controls have not been rewritten: firewalls, secure configuration, security update management, user access control, malware protection. What changed is definition, scope, and how assessors mark the worst answers.
If you opened an assessment account before 27 April, you can still finish under Willow. IASME gives you six months from the date the account was created. For accounts opened in the last days of Willow, that window runs into late October 2026.
After that, you are on Danzell. The old question set only changes how the controls are asked.
The two hard fails
IASME has put automatic failure on two clusters of questions.
First, MFA. Authentication to cloud services must always use multi-factor authentication where the service offers it. Free, bundled, or a paid add-on: if the vendor can give you MFA, you turn it on for administrators and for every user.
Skip it because the extra licence felt steep, and the assessment fails. The rest of the questionnaire does not rescue you.
Second, the 14-day patch clock. Two Danzell questions, A6.4 and A6.5, now auto-fail. High-risk or critical updates for operating systems and router or firewall firmware must be installed within 14 days of release.
The same window applies to applications, including associated files and extensions. “Critical or high risk” means the vendor said so, or the fix has a CVSS v3 base score of 7 or above, or the vendor gave no severity information at all.
The 14-day rule is not new. Missing it now ends the assessment. A monthly “we’ll get round to it” cycle is no longer a conversation with the assessor. It is a fail.
Automatic updates, where the vendor provides them, are how most SMEs actually hit 14 days. Someone still has to own the devices that cannot patch themselves.
Cloud services are wider than Microsoft 365
Version 3.3 finally defines a cloud service: an on-demand, scalable service, hosted on shared infrastructure, accessed over the internet, via an account, that stores or processes your organisation’s data. If your data sits on it, it is in scope. You cannot exclude cloud services from Cyber Essentials.
Microsoft 365 is the obvious one. It is not the only one: Xero, Sage, QuickBooks, HubSpot, Salesforce, a lab LIMS in the cloud, Dropbox, Google Drive, Adobe, Figma, Slack, Teams, Zoom, payroll, e-signing, and the project tool the science lead bought on a card last spring.
If staff sign in with the company email and the service holds your data, treat it as in scope until you have a reason not to. User access control on those services is your job, even when the vendor patches the platform.
For SaaS that usually means MFA, joiners and leavers, and no shared logins. For infrastructure in the cloud you also own a slice of the patching.
The usual miss is not Microsoft 365. It is the fifth SaaS tool that nobody listed because it did not feel like IT.
Still on Windows 10?
Microsoft ended support for Windows 10 on 14 October 2025. After that date, machines without Extended Security Updates are not receiving vendor security fixes. Cyber Essentials requires software that is licensed and supported.
IASME’s Knowledge Hub states that from 14 October 2025, Windows 10 machines not on ESU are not compliant. Unsupported software in scope is an automatic fail. Danzell has not softened that.
ESU is a paid programme. Microsoft sells commercial cover by the year, for devices on Windows 10 version 22H2. It is a bridge while you move to Windows 11, not a long-term home. Consumer ESU is not how you should cover a company laptop.
If the hardware cannot run Windows 11, replace it or enrol it in commercial ESU and keep patching inside 14 days. A lab PC that “only runs the old instrument software” still fails if it is in scope and talking to the internet. You can sometimes isolate a defined sub-set so it cannot send or receive internet traffic. You cannot wish it out of the questionnaire.
Insurers and supply-chain questionnaires notice unsupported operating systems. You need an asset list that is true.
A practical pre-assessment checklist for Cambridgeshire SMEs
Do this before you pay IASME.
If any of those ten is a shrug, you are not ready to submit.
DIY versus getting your MSP to own it
You can do this yourself. IASME publishes the questions free. The NCSC publishes the requirements. The verified self-assessment starts from £320 plus VAT for the smallest firms.
You complete it, a director signs, an assessor marks it. If you fail, you usually get two working days to fix simple issues without paying again.
That route works when the estate is small, the SaaS list is short, and someone technical owns the 14-day clock. It fails when the finance system, the design tools and the Windows 10 laptop in the corner are treated as “not really IT”.
The other official route is a Certification Body licensed by IASME. They assess. Some also consult. CAMBITION is not a Certification Body.
We are the MSP that makes the answers true: MFA across the cloud list, patching that hits 14 days, Windows 10 gone or on ESU, leavers removed, evidence you can show an assessor.
Paying for the assessment before the controls are in place is an expensive way to discover what you already suspected.
If you also need the wider control set that sits under Cyber Essentials, see our cyber security page, or the guide to small business IT support.
How CAMBITION helps you certify and stay certified
CAMBITION has been a Cambridge MSP since 2012. We look after Microsoft 365, cyber and cloud for SMEs, including life sciences firms that have to show Cyber Essentials to buyers. We have assisted 250+ clients.
We do not issue the certificate. We put the controls in place and keep them in place so the annual renewal is a review, not a rescue.
A short Cyber Essentials readiness check is the useful first step. We will tell you what would fail today, before you pay for the assessment. That usually means the cloud list, MFA gaps, the 14-day patch picture, and any Windows 10 still hanging around.
If you want the estate run properly after that, managed IT is how the certificate lasts the year. Patching, identity, backups and the quiet SaaS subscriptions are the same jobs we already do.
Call 01223 656 156 or use the contact form. Ask for a Cyber Essentials readiness check.
Frequently asked questions
What changed in Cyber Essentials Danzell?
From 27 April 2026, new assessment accounts use the Danzell question set and NCSC Requirements v3.3. The five controls are the same. Missing MFA on a cloud service that offers it, and high/critical patches not applied within 14 days, now fail the assessment automatically.
Does Windows 10 fail Cyber Essentials?
Yes, if it is in scope and not covered by Microsoft Extended Security Updates. Microsoft ended free Windows 10 support on 14 October 2025. Cyber Essentials requires licensed, supported software. Unsupported software in scope is an automatic fail.
Do we need MFA on every cloud app, or just Microsoft 365?
On every in-scope cloud service that offers MFA, including paid add-ons. Cloud services that store or process your data cannot be excluded. That includes CRM, accounting, file share and design tools, not only Microsoft 365.
Can we still finish a Willow assessment?
If the assessment account was created before 27 April 2026, IASME lets you complete it on the previous question set. You have six months from the date the account was created, so the last of those accounts run into late October 2026. New purchases from 27 April 2026 are Danzell.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement
Cyber Essentials Danzell: what Cambridge SMEs must fix before autumn
Autumn is when a lot of Cambridgeshire firms recertify. The certificate is twelve months old, a tender pack has appeared, and someone in finance has asked whether the cyber insurance form still holds.
Cyber Essentials for small business used to feel like a tidy questionnaire. The five controls are the same. From 27 April 2026 the marking is not.
New assessment accounts now use the Danzell question set, on NCSC Requirements v3.3. Two answers fail you outright: multi-factor authentication missing on any cloud service that offers it, and high or critical patches left longer than 14 days. Windows 10 without Extended Security Updates fails as well, because the software is no longer supported.
If you bid into life sciences or a larger supply chain, that is the difference between sending the certificate and explaining why you do not have one.
What actually changed this year
Willow was last year’s question set. Danzell replaced it for accounts opened from 27 April 2026. IASME published Danzell on 13 February. The NCSC published the v3.3 requirements to go with it.
The five technical controls have not been rewritten: firewalls, secure configuration, security update management, user access control, malware protection. What changed is definition, scope, and how assessors mark the worst answers.
If you opened an assessment account before 27 April, you can still finish under Willow. IASME gives you six months from the date the account was created. For accounts opened in the last days of Willow, that window runs into late October 2026.
After that, you are on Danzell. The old question set only changes how the controls are asked.
The two hard fails
IASME has put automatic failure on two clusters of questions.
First, MFA. Authentication to cloud services must always use multi-factor authentication where the service offers it. Free, bundled, or a paid add-on: if the vendor can give you MFA, you turn it on for administrators and for every user.
Skip it because the extra licence felt steep, and the assessment fails. The rest of the questionnaire does not rescue you.
Second, the 14-day patch clock. Two Danzell questions, A6.4 and A6.5, now auto-fail. High-risk or critical updates for operating systems and router or firewall firmware must be installed within 14 days of release.
The same window applies to applications, including associated files and extensions. “Critical or high risk” means the vendor said so, or the fix has a CVSS v3 base score of 7 or above, or the vendor gave no severity information at all.
The 14-day rule is not new. Missing it now ends the assessment. A monthly “we’ll get round to it” cycle is no longer a conversation with the assessor. It is a fail.
Automatic updates, where the vendor provides them, are how most SMEs actually hit 14 days. Someone still has to own the devices that cannot patch themselves.
Cloud services are wider than Microsoft 365
Version 3.3 finally defines a cloud service: an on-demand, scalable service, hosted on shared infrastructure, accessed over the internet, via an account, that stores or processes your organisation’s data. If your data sits on it, it is in scope. You cannot exclude cloud services from Cyber Essentials.
Microsoft 365 is the obvious one. It is not the only one: Xero, Sage, QuickBooks, HubSpot, Salesforce, a lab LIMS in the cloud, Dropbox, Google Drive, Adobe, Figma, Slack, Teams, Zoom, payroll, e-signing, and the project tool the science lead bought on a card last spring.
If staff sign in with the company email and the service holds your data, treat it as in scope until you have a reason not to. User access control on those services is your job, even when the vendor patches the platform.
For SaaS that usually means MFA, joiners and leavers, and no shared logins. For infrastructure in the cloud you also own a slice of the patching.
The usual miss is not Microsoft 365. It is the fifth SaaS tool that nobody listed because it did not feel like IT.
Still on Windows 10?
Microsoft ended support for Windows 10 on 14 October 2025. After that date, machines without Extended Security Updates are not receiving vendor security fixes. Cyber Essentials requires software that is licensed and supported.
IASME’s Knowledge Hub states that from 14 October 2025, Windows 10 machines not on ESU are not compliant. Unsupported software in scope is an automatic fail. Danzell has not softened that.
ESU is a paid programme. Microsoft sells commercial cover by the year, for devices on Windows 10 version 22H2. It is a bridge while you move to Windows 11, not a long-term home. Consumer ESU is not how you should cover a company laptop.
If the hardware cannot run Windows 11, replace it or enrol it in commercial ESU and keep patching inside 14 days. A lab PC that “only runs the old instrument software” still fails if it is in scope and talking to the internet. You can sometimes isolate a defined sub-set so it cannot send or receive internet traffic. You cannot wish it out of the questionnaire.
Insurers and supply-chain questionnaires notice unsupported operating systems. You need an asset list that is true.
A practical pre-assessment checklist for Cambridgeshire SMEs
Do this before you pay IASME.
If any of those ten is a shrug, you are not ready to submit.
DIY versus getting your MSP to own it
You can do this yourself. IASME publishes the questions free. The NCSC publishes the requirements. The verified self-assessment starts from £320 plus VAT for the smallest firms.
You complete it, a director signs, an assessor marks it. If you fail, you usually get two working days to fix simple issues without paying again.
That route works when the estate is small, the SaaS list is short, and someone technical owns the 14-day clock. It fails when the finance system, the design tools and the Windows 10 laptop in the corner are treated as “not really IT”.
The other official route is a Certification Body licensed by IASME. They assess. Some also consult. CAMBITION is not a Certification Body.
We are the MSP that makes the answers true: MFA across the cloud list, patching that hits 14 days, Windows 10 gone or on ESU, leavers removed, evidence you can show an assessor.
Paying for the assessment before the controls are in place is an expensive way to discover what you already suspected.
If you also need the wider control set that sits under Cyber Essentials, see our cyber security page, or the guide to small business IT support.
How CAMBITION helps you certify and stay certified
CAMBITION has been a Cambridge MSP since 2012. We look after Microsoft 365, cyber and cloud for SMEs, including life sciences firms that have to show Cyber Essentials to buyers. We have assisted 250+ clients.
We do not issue the certificate. We put the controls in place and keep them in place so the annual renewal is a review, not a rescue.
A short Cyber Essentials readiness check is the useful first step. We will tell you what would fail today, before you pay for the assessment. That usually means the cloud list, MFA gaps, the 14-day patch picture, and any Windows 10 still hanging around.
If you want the estate run properly after that, managed IT is how the certificate lasts the year. Patching, identity, backups and the quiet SaaS subscriptions are the same jobs we already do.
Call 01223 656 156 or use the contact form. Ask for a Cyber Essentials readiness check.
Frequently asked questions
What changed in Cyber Essentials Danzell?
From 27 April 2026, new assessment accounts use the Danzell question set and NCSC Requirements v3.3. The five controls are the same. Missing MFA on a cloud service that offers it, and high/critical patches not applied within 14 days, now fail the assessment automatically.
Does Windows 10 fail Cyber Essentials?
Yes, if it is in scope and not covered by Microsoft Extended Security Updates. Microsoft ended free Windows 10 support on 14 October 2025. Cyber Essentials requires licensed, supported software. Unsupported software in scope is an automatic fail.
Do we need MFA on every cloud app, or just Microsoft 365?
On every in-scope cloud service that offers MFA, including paid add-ons. Cloud services that store or process your data cannot be excluded. That includes CRM, accounting, file share and design tools, not only Microsoft 365.
Can we still finish a Willow assessment?
If the assessment account was created before 27 April 2026, IASME lets you complete it on the previous question set. You have six months from the date the account was created, so the last of those accounts run into late October 2026. New purchases from 27 April 2026 are Danzell.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement
Autumn is when a lot of Cambridgeshire firms recertify. The certificate is twelve months old, a tender pack has appeared, and someone in finance has asked whether the cyber insurance form still holds.
Cyber Essentials for small business used to feel like a tidy questionnaire. The five controls are the same. From 27 April 2026 the marking is not.
New assessment accounts now use the Danzell question set, on NCSC Requirements v3.3. Two answers fail you outright: multi-factor authentication missing on any cloud service that offers it, and high or critical patches left longer than 14 days. Windows 10 without Extended Security Updates fails as well, because the software is no longer supported.
If you bid into life sciences or a larger supply chain, that is the difference between sending the certificate and explaining why you do not have one.
Willow was last year’s question set. Danzell replaced it for accounts opened from 27 April 2026. IASME published Danzell on 13 February. The NCSC published the v3.3 requirements to go with it.
The five technical controls have not been rewritten: firewalls, secure configuration, security update management, user access control, malware protection. What changed is definition, scope, and how assessors mark the worst answers.
If you opened an assessment account before 27 April, you can still finish under Willow. IASME gives you six months from the date the account was created. For accounts opened in the last days of Willow, that window runs into late October 2026.
After that, you are on Danzell. The old question set only changes how the controls are asked.
IASME has put automatic failure on two clusters of questions.
First, MFA. Authentication to cloud services must always use multi-factor authentication where the service offers it. Free, bundled, or a paid add-on: if the vendor can give you MFA, you turn it on for administrators and for every user.
Skip it because the extra licence felt steep, and the assessment fails. The rest of the questionnaire does not rescue you.
Second, the 14-day patch clock. Two Danzell questions, A6.4 and A6.5, now auto-fail. High-risk or critical updates for operating systems and router or firewall firmware must be installed within 14 days of release.
The same window applies to applications, including associated files and extensions. “Critical or high risk” means the vendor said so, or the fix has a CVSS v3 base score of 7 or above, or the vendor gave no severity information at all.
The 14-day rule is not new. Missing it now ends the assessment. A monthly “we’ll get round to it” cycle is no longer a conversation with the assessor. It is a fail.
Automatic updates, where the vendor provides them, are how most SMEs actually hit 14 days. Someone still has to own the devices that cannot patch themselves.
Version 3.3 finally defines a cloud service: an on-demand, scalable service, hosted on shared infrastructure, accessed over the internet, via an account, that stores or processes your organisation’s data. If your data sits on it, it is in scope. You cannot exclude cloud services from Cyber Essentials.
Microsoft 365 is the obvious one. It is not the only one: Xero, Sage, QuickBooks, HubSpot, Salesforce, a lab LIMS in the cloud, Dropbox, Google Drive, Adobe, Figma, Slack, Teams, Zoom, payroll, e-signing, and the project tool the science lead bought on a card last spring.
If staff sign in with the company email and the service holds your data, treat it as in scope until you have a reason not to. User access control on those services is your job, even when the vendor patches the platform.
For SaaS that usually means MFA, joiners and leavers, and no shared logins. For infrastructure in the cloud you also own a slice of the patching.
The usual miss is not Microsoft 365. It is the fifth SaaS tool that nobody listed because it did not feel like IT.
Microsoft ended support for Windows 10 on 14 October 2025. After that date, machines without Extended Security Updates are not receiving vendor security fixes. Cyber Essentials requires software that is licensed and supported.
IASME’s Knowledge Hub states that from 14 October 2025, Windows 10 machines not on ESU are not compliant. Unsupported software in scope is an automatic fail. Danzell has not softened that.
ESU is a paid programme. Microsoft sells commercial cover by the year, for devices on Windows 10 version 22H2. It is a bridge while you move to Windows 11, not a long-term home. Consumer ESU is not how you should cover a company laptop.
If the hardware cannot run Windows 11, replace it or enrol it in commercial ESU and keep patching inside 14 days. A lab PC that “only runs the old instrument software” still fails if it is in scope and talking to the internet. You can sometimes isolate a defined sub-set so it cannot send or receive internet traffic. You cannot wish it out of the questionnaire.
Insurers and supply-chain questionnaires notice unsupported operating systems. You need an asset list that is true.
Do this before you pay IASME.
If any of those ten is a shrug, you are not ready to submit.
You can do this yourself. IASME publishes the questions free. The NCSC publishes the requirements. The verified self-assessment starts from £320 plus VAT for the smallest firms.
You complete it, a director signs, an assessor marks it. If you fail, you usually get two working days to fix simple issues without paying again.
That route works when the estate is small, the SaaS list is short, and someone technical owns the 14-day clock. It fails when the finance system, the design tools and the Windows 10 laptop in the corner are treated as “not really IT”.
The other official route is a Certification Body licensed by IASME. They assess. Some also consult. CAMBITION is not a Certification Body.
We are the MSP that makes the answers true: MFA across the cloud list, patching that hits 14 days, Windows 10 gone or on ESU, leavers removed, evidence you can show an assessor.
Paying for the assessment before the controls are in place is an expensive way to discover what you already suspected.
If you also need the wider control set that sits under Cyber Essentials, see our cyber security page, or the guide to small business IT support.
CAMBITION has been a Cambridge MSP since 2012. We look after Microsoft 365, cyber and cloud for SMEs, including life sciences firms that have to show Cyber Essentials to buyers. We have assisted 250+ clients.
We do not issue the certificate. We put the controls in place and keep them in place so the annual renewal is a review, not a rescue.
A short Cyber Essentials readiness check is the useful first step. We will tell you what would fail today, before you pay for the assessment. That usually means the cloud list, MFA gaps, the 14-day patch picture, and any Windows 10 still hanging around.
If you want the estate run properly after that, managed IT is how the certificate lasts the year. Patching, identity, backups and the quiet SaaS subscriptions are the same jobs we already do.
Call 01223 656 156 or use the contact form. Ask for a Cyber Essentials readiness check.
From 27 April 2026, new assessment accounts use the Danzell question set and NCSC Requirements v3.3. The five controls are the same. Missing MFA on a cloud service that offers it, and high/critical patches not applied within 14 days, now fail the assessment automatically.
Yes, if it is in scope and not covered by Microsoft Extended Security Updates. Microsoft ended free Windows 10 support on 14 October 2025. Cyber Essentials requires licensed, supported software. Unsupported software in scope is an automatic fail.
On every in-scope cloud service that offers MFA, including paid add-ons. Cloud services that store or process your data cannot be excluded. That includes CRM, accounting, file share and design tools, not only Microsoft 365.
If the assessment account was created before 27 April 2026, IASME lets you complete it on the previous question set. You have six months from the date the account was created, so the last of those accounts run into late October 2026. New purchases from 27 April 2026 are Danzell.
© CAMBITION I.T. Services Ltd
Head Office
Unit 7, Church Meadows, Haslingfield Road, Barrington, Cambridgeshire, CB22 7RG
VAT# 136 186 313 · Registered in the UK # 808 4429
View Privacy / Data Protection / Cookie Statement