Blog Cyber Essentials

Cyber Essentials requirements in 2026: the Danzell question set explained

By Andrew Heppinstall, founder of Unavoidable Studio · 10 October 2026 · 7 min read

Cyber Essentials changed in April 2026. If you buy an assessment now, you will answer the Danzell question set and be marked against version 3.3 of the NCSC's Requirements for IT Infrastructure. The five technical controls are the same as before, but a few things that used to be marked down are now automatic fails, and cloud services can no longer be left out of scope. This guide explains what the 2026 requirements are, what changed, and what that means for a dental practice, care provider or small charity getting ready to apply.

What is the Danzell question set?

Danzell is the name of the current Cyber Essentials self-assessment question set, used for assessments bought from 27 April 2026. IASME, the Cyber Essentials partner for the NCSC, names each question set, and Danzell follows the previous set, Willow. Its questions are based on the NCSC's Requirements for IT Infrastructure version 3.3.

IASME says the changes apply to assessment accounts created after 26 April 2026, and organisations that opened an account before then have six months to certify under the previous requirements. You can preview the full Danzell questions on IASME's question set page before you start.

What are the Cyber Essentials requirements in 2026?

The requirements are still built around five technical controls that protect you against the most common internet-based attacks:

If you are new to the scheme, our plain-English guide to Cyber Essentials walks through each control in more detail.

What changed in April 2026?

The biggest changes are about multi-factor authentication, cloud services and patching. According to IASME's update of 12 February 2026:

Multi-factor authentication on every cloud service

MFA is now a mandatory requirement for all cloud services, whether they are free, included with something else or paid for. Not having it switched on for a cloud service is an automatic fail. For a small practice that means your email, practice management or care planning system, file storage, payroll and any other online accounts staff sign in to. Our guide to MFA for small teams covers how to roll it out without a fuss.

Cloud services cannot be left out

The requirements now define a cloud service and state that cloud services cannot be excluded from scope. If your staff use it to handle your organisation's data, it is in.

Critical updates within 14 days, or you fail

Two questions now carry an automatic fail: high-risk or critical security updates for operating systems, and the same for applications, must be installed within 14 days of release. Many organisations already aimed for this, but a missed update on a single laptop can now fail the whole assessment.

Clearer scope and a stronger declaration

Certificates can now carry a fuller scope description, legal entities in scope must be listed, and any network you exclude must be justified and kept separate. The signed declaration also now acknowledges your duty to keep the controls in place for the whole certification period, not just on the day you apply.

Passwordless sign-in is encouraged

The user access control guidance gives more weight to passwordless methods such as passkeys, which IASME describes as a more secure alternative to passwords.

Do the changes affect Cyber Essentials Plus?

Yes. For Cyber Essentials Plus, IASME says that if a sample of devices fails testing, you must fix the problems and be retested on the original sample plus a new random sample, and a second failure means the self-assessment certificate is revoked. The self-assessment must also be finalised and unchanged before Plus testing starts. If you are weighing up the two levels, see Cyber Essentials vs Cyber Essentials Plus.

What does this mean for dental practices, care providers and charities?

For most small health, care and charity organisations, the changes land in the same three places:

If you also complete the Data Security and Protection Toolkit, the same work counts twice. The DSPT asks about MFA, patching and access control, so getting ready for Cyber Essentials will strengthen your DSPT answers as well. Our article on Cyber Essentials for dental practices explains how the two fit together.

How should you prepare before you apply?

  1. List every cloud service you use. Include free ones and anything a single member of staff signed up to.
  2. Switch on MFA everywhere it is offered. Start with email and admin accounts, then work through the list.
  3. Check updates on every device. Turn on automatic updates where you can, and remove any device or software that is no longer supported.
  4. Tidy up accounts. Remove leavers, separate admin accounts from everyday ones and change any default passwords.
  5. Read the Danzell questions before you buy. Answer them honestly in a draft first, so there are no surprises.

Costs depend on the size of your organisation; our guide to what Cyber Essentials costs in 2026 explains the bands.

How we can help

We do not certify, and we cannot guarantee you will pass. What we offer is Cyber Essentials readiness: an independent look at your setup against the current requirements, so you know what to fix before you pay for an assessment. Certification itself is carried out by an IASME certification body. Nothing in this article is legal advice. For more guides, head back to the blog.

Ready for Cyber Essentials under Danzell?

Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix before you apply for Cyber Essentials.

Book a free audit

← Back to the blog