Two answers now fail Cyber Essentials outright

· · Security

If your business certified for Cyber Essentials last year and renewal is on the horizon, the questionnaire has changed underneath you. Two things that used to be shortcomings you would be told to fix are now automatic failures: get either wrong and the assessment fails regardless of how good the rest of your answers are.

Cyber Essentials is the UK Government-backed baseline certification, five technical controls and a verified self-assessment; we walked through what it actually involves when this site launched. This filing is about what has changed since, because the scheme moves once a year and the 2026 update, called Danzell, is the strictest step in a while.

The two automatic failures

Multi-factor authentication on every cloud service. IASME's summary of the April 2026 changes is blunt: multi-factor authentication (the second check at login, a code or prompt on your phone alongside the password) is mandatory for all cloud services where it is available, whether it is free, included, or a paid extra. Fail to switch it on somewhere it exists, and the assessment fails automatically. "We did not want to pay for that tier" is no longer an answer the scheme accepts.

High-risk updates within 14 days. The 14-day rule for applying high-risk and critical security updates has been in the scheme for years. What changed is the consequence: the two questions that cover it, one for operating systems, router, and firewall firmware, and one for applications and their extensions, are now automatic fails too. The window includes the kit people forget they own: the office router's firmware counts just as much as Windows updates.

Neither requirement is new. What is new is that the scheme stopped treating them as negotiable, which tells you exactly where UK breach investigations keep ending up: a login with no second check, and a known hole left unpatched past its fix.

What else changed for 2026

Danzell applies to assessment accounts created from 27 April 2026; accounts opened before then finish on last year's question set, with six months to complete. Beyond the auto-fails:

  • Cloud services get a formal definition and cannot be excluded from scope. If your business runs on Microsoft 365, Google Workspace, Xero, or a hosted phone system, that is in the assessment, full stop.
  • Certificates now name every legal entity in scope, with company numbers, and the definition of "point in time" is pinned to the date the certificate is issued. A certificate is becoming harder to wave vaguely at a customer, which is rather the point.
  • The board declaration now acknowledges responsibility for maintaining compliance throughout the certification period, not just on assessment day.
  • Cyber Essentials Plus got teeth. Plus is the audited version, where an assessor tests a sample of devices. If the first sample fails, the retest now covers the original sample plus a fresh random one, and a second failure revokes the underlying certificate. Answers can no longer be quietly adjusted once testing starts.

Last year's update (Willow, April 2025) reads as the warm-up: remote working was widened to cover cafés, hotels, and trains, passwordless logins such as passkeys were formally recognised, and "patches" became "vulnerability fixes" to cover every mechanism a vendor uses to close a hole.

Why stricter is good news if you hold one

A certificate that is easy to hold is not worth much to show a customer. The pressure runs the other way now: the Cyber Resilience Pledge has large firms committing to require Cyber Essentials across their supply chains, and the government's own pledge pack cites organisations seeing up to an 80% reduction in incidents where they mandated it from third parties. The stricter the scheme gets, the more that questionnaire from your biggest customer is worth answering with a current certificate.

Costs are unchanged in shape: basic certification is priced by size, from £320 plus VAT for the smallest firms to £600 for the largest, per the NCSC's overview and IASME's scheme page; Plus is quoted on your setup. Certification still includes free security insurance for UK organisations under £20 million turnover certifying their whole organisation.

What to check before renewal

  • Which question set you will face. Renewal through an account created from 27 April 2026 means Danzell; check with your certification body rather than assuming.
  • Multi-factor authentication, everywhere, now. List your cloud services, including the ones a department signed up for without telling anyone, and turn on the second login step wherever it exists. This is worth doing regardless of certification.
  • Whether 14-day patching reaches the edges. Router and firewall firmware fails assessments; whoever looks after your network should be able to say when it was last updated, in writing.
  • Your legal entities. If the business is a group, decide which entities the certificate must name before the assessment, not during it.

How Steelwise can help

Getting a business through Cyber Essentials, or working out why a renewal that passed last year would fail this year, is the kind of security advisory work we do. Get in touch and we will walk it through in plain English.

Further reading

← All filings