Back to articles

Cyber Essentials requirements v3.3: what changed in 2026

By , founder and reviewer at BrightCertPublished Reviewed

Part of our plain-English Cyber Essentials guide

Short answer

Cyber Essentials requirements v3.3 took effect on , and the Danzell question set replaced Willow. The five control areas did not change. What changed is how tightly scope is drawn around cloud services, remote workers and personally owned devices, and that multi-factor authentication must be enabled for users of a cloud service wherever that service makes it available. If your answers were written before that date, they were written against a question set that is no longer current.

Most of what is written about v3.3 describes it as a minor update. That is true of the controls and misleading about the work, because the changes land on scope, and scope is what determines how much of your organisation the other requirements apply to.

What actually changed on 27 April 2026

Two things happened on the same date. The requirements moved to v3.3, and the self-assessment moved to the Danzell question set, replacing Willow. Applications started from that date use both.

The five control areas are unchanged, which is why the update is easy to underestimate. The substance sits in three places: cloud services cannot be excluded from scope, multi-factor authentication is required for users of cloud services that offer it, and scope has to account for remote workers and personally owned devices that can reach organisational data or services.

For a business certifying for the first time, this is simply the current standard. For a business renewing, it is the more awkward case: the arrangement that passed last year may be described by answers that no longer map onto the questions being asked.

The five controls, and the evidence to collect for each

Preparation tends to fail not because a control is missing but because nobody can show it is in place. The table below maps each control area to what v3.3 asks and the evidence worth gathering before you start an application.

Cyber Essentials v3.3 control areas mapped to requirements and the evidence a UK SME should collect
Control areaWhat v3.3 asksEvidence to collect
Boundary Firewalls & Internet GatewaysEvery device that connects to the internet sits behind a correctly configured firewall, with default administrative passwords changed and each inbound rule justified.A list of internet-facing devices and cloud boundaries; who approved each open port and why; written confirmation that default administrative passwords were changed.
Secure ConfigurationDevices and software are configured before use: unused accounts and applications removed, no default credentials left in place, and screens that lock when unattended.Your build or configuration standard; the software actually installed on each device type; the auto-lock setting on laptops, desktops and mobile devices.
User Access ControlEach person has their own account, administrative rights are granted through an approval process, and multi-factor authentication is enabled on cloud services that offer it.A user list showing role and whether the account is administrative; your leaver process and a recent example of it running; MFA status for each cloud service, covering all users rather than administrators alone.
Malware ProtectionIn-scope devices are protected by anti-malware software, application allow-listing, or code sandboxing.Which of the three approaches applies to each device type; confirmation that protection is active and updating; how personally owned devices in scope are covered.
Security Update ManagementSoftware is still supported by its vendor, and critical or high-risk security updates are applied within 14 days of release.A software inventory recording vendor support status and end-of-life dates; an update policy stating the 14-day window; a sample patch record showing it was met.

Cloud services are in scope, and cannot be carved out

The most common scoping mistake is treating cloud services as somebody else’s responsibility. Cloud services used by the organisation form part of the assessment, and the provider being responsible for its own infrastructure does not remove your responsibility for how your organisation configures and grants access to the service.

In practice the work is inventory work. Most SMEs underestimate how many cloud services they use, because the list assembled by the person who manages IT and the list of services actually in use are rarely the same. Services signed up for by a single department, tools attached to a personal login, and anything inherited from a previous supplier all belong on it.

Multi-factor authentication, where the service makes it available

Under v3.3, where a cloud service makes MFA available, it must be enabled for users of that service. The obligation follows the capability of the service, so the question to answer per service is whether MFA is offered, and then whether it is actually switched on.

This is where readiness work most often finds a gap, and the gap has a predictable shape. Multi-factor authentication gets enabled for the people who set the system up, an administrator or two, and then is never completed for everyone else. “We have MFA” and “MFA is enabled for users of this service” are different statements, and only the second one answers the question.

Working through it service by service:

  1. List every cloud service the organisation actually uses.
  2. For each, establish whether the provider offers multi-factor authentication.
  3. Where it does, confirm it is enabled for all users of that service, not administrators only.
  4. Record who confirmed it and on what date, so the answer is evidenced rather than remembered.

Remote workers and personally owned devices

Scope has to account for remote workers and personally owned devices that can access organisational data or services. A personal laptop used to check work email is within scope for the controls that apply to it, which surprises businesses that think of scope as a list of assets the company bought.

Two consequences follow. Home working arrangements need to be described accurately rather than generically, and any bring-your-own-device arrangement needs an answer for malware protection, updates and access control on devices the organisation does not own. Deciding that personal devices may not access organisational data is a legitimate answer, provided it is genuinely enforced.

Supported software and the 14-day window

Software in scope must still be supported by its vendor, and critical or high-risk security updates must be applied within 14 days of release. Both halves matter, and the first is the one that fails quietly: an operating system or application past its end-of-life date cannot be patched into compliance, because the updates are no longer issued.

The useful artefact here is a software inventory that records the vendor support status and end-of-life date alongside each entry. It answers the supported-software question directly, and it gives you advance warning of the next thing due to fall out of support, rather than discovering it during an assessment.

If you are renewing rather than certifying for the first time

A Cyber Essentials certificate covers 12 months, so most organisations meet v3.3 for the first time at renewal rather than at initial certification. The failure mode is specific: last year’s saved answers are opened, dates are updated, and the submission goes in. The answers are honest. They were also written against Willow, and they describe an arrangement that predates the current scoping and MFA expectations.

Before reusing anything, three checks are worth the time:

  • Which question set the answers were written against. Anything from before 27 April 2026 was written for Willow.
  • Whether every cloud service appears in scope. Include services adopted during the year that never reached the central list.
  • What changed in the organisation. New starters, leavers, a new device type or a supplier change can all leave an old answer describing an arrangement that no longer exists.

Starting that review 30 to 60 days before the certificate date leaves room to fix what it finds. Starting it in the week of renewal generally does not.

Frequently asked questions

When did Cyber Essentials requirements v3.3 take effect?

27 April 2026. Applications started from that date use the Danzell question set and v3.3 of the requirements. Anything written against the earlier Willow question set is out of date for a new application.

Did the five Cyber Essentials controls change in v3.3?

No. The five control areas are the same: firewalls, secure configuration, user access control, malware protection and security update management. What changed is how scope is drawn around cloud services, remote workers and personally owned devices, and the treatment of multi-factor authentication.

Does v3.3 require MFA on every system?

It requires multi-factor authentication for users of a cloud service where that service makes MFA available. The obligation follows what the service offers, so the practical first step is establishing which of your cloud services support it.

Can we leave cloud services out of scope?

No. Cloud services used by the organisation form part of the assessment scope. Scope also needs to account for remote workers and personally owned devices that can access organisational data or services.

We are renewing. Can we reuse last year's answers?

Read them again before you do. A Cyber Essentials certificate covers 12 months, so a renewal completed after 27 April 2026 is answering a different question set from the one the original answers were written against. The answers may still be honest and still describe the old arrangement.

Are these the official Danzell questions?

No. This guide explains what v3.3 requires and what evidence to gather. It does not reproduce the official Danzell self-assessment question set, which is completed through an IASME-licensed Certification Body.

Work through the five control areas against v3.3 and see where your gaps are, with a prioritised list of what to fix first.

Start your assessment

BrightCert helps UK businesses prepare for Cyber Essentials by assessing readiness, identifying gaps, and producing a practical report. BrightCert does not issue the official Cyber Essentials certificate. That comes from an IASME-licensed Certification Body.

Sources: NCSC: Cyber Essentials v3.3 resources · IASME: preview the self-assessment questions