Cyber Essentials changed in April 2026. If you buy an assessment now, you will answer the Danzell question set and be marked against version 3.3 of the NCSC's Requirements for IT Infrastructure. The five technical controls are the same as before, but a few things that used to be marked down are now automatic fails, and cloud services can no longer be left out of scope. This guide explains what the 2026 requirements are, what changed, and what that means for a dental practice, care provider or small charity getting ready to apply.
What is the Danzell question set?
Danzell is the name of the current Cyber Essentials self-assessment question set, used for assessments bought from 27 April 2026. IASME, the Cyber Essentials partner for the NCSC, names each question set, and Danzell follows the previous set, Willow. Its questions are based on the NCSC's Requirements for IT Infrastructure version 3.3.
IASME says the changes apply to assessment accounts created after 26 April 2026, and organisations that opened an account before then have six months to certify under the previous requirements. You can preview the full Danzell questions on IASME's question set page before you start.
What are the Cyber Essentials requirements in 2026?
The requirements are still built around five technical controls that protect you against the most common internet-based attacks:
- Firewalls: every device and network connection to the internet is protected by a properly configured firewall.
- Secure configuration: default passwords changed, unused accounts and software removed, and auto-run features turned off.
- Security update management: operating systems and applications are supported, licensed and kept up to date.
- User access control: people only have the access they need, admin accounts are used only for admin work, and strong authentication is in place.
- Malware protection: anti-malware or application allow-listing stops harmful software from running.
If you are new to the scheme, our plain-English guide to Cyber Essentials walks through each control in more detail.
What changed in April 2026?
The biggest changes are about multi-factor authentication, cloud services and patching. According to IASME's update of 12 February 2026:
Multi-factor authentication on every cloud service
MFA is now a mandatory requirement for all cloud services, whether they are free, included with something else or paid for. Not having it switched on for a cloud service is an automatic fail. For a small practice that means your email, practice management or care planning system, file storage, payroll and any other online accounts staff sign in to. Our guide to MFA for small teams covers how to roll it out without a fuss.
Cloud services cannot be left out
The requirements now define a cloud service and state that cloud services cannot be excluded from scope. If your staff use it to handle your organisation's data, it is in.
Critical updates within 14 days, or you fail
Two questions now carry an automatic fail: high-risk or critical security updates for operating systems, and the same for applications, must be installed within 14 days of release. Many organisations already aimed for this, but a missed update on a single laptop can now fail the whole assessment.
Clearer scope and a stronger declaration
Certificates can now carry a fuller scope description, legal entities in scope must be listed, and any network you exclude must be justified and kept separate. The signed declaration also now acknowledges your duty to keep the controls in place for the whole certification period, not just on the day you apply.
Passwordless sign-in is encouraged
The user access control guidance gives more weight to passwordless methods such as passkeys, which IASME describes as a more secure alternative to passwords.
Do the changes affect Cyber Essentials Plus?
Yes. For Cyber Essentials Plus, IASME says that if a sample of devices fails testing, you must fix the problems and be retested on the original sample plus a new random sample, and a second failure means the self-assessment certificate is revoked. The self-assessment must also be finalised and unchanged before Plus testing starts. If you are weighing up the two levels, see Cyber Essentials vs Cyber Essentials Plus.
What does this mean for dental practices, care providers and charities?
For most small health, care and charity organisations, the changes land in the same three places:
- Email and Microsoft 365 or Google Workspace. These are cloud services, so every account needs MFA, including shared and old accounts nobody uses any more.
- Clinical and care systems. Online practice management, care planning and rota systems are cloud services too. Check that MFA is offered and turned on for every user.
- Devices that miss updates. Reception PCs, shared tablets in care settings and volunteers' laptops are often the ones that fall behind. One device more than 14 days behind on a critical update is enough to fail.
If you also complete the Data Security and Protection Toolkit, the same work counts twice. The DSPT asks about MFA, patching and access control, so getting ready for Cyber Essentials will strengthen your DSPT answers as well. Our article on Cyber Essentials for dental practices explains how the two fit together.
How should you prepare before you apply?
- List every cloud service you use. Include free ones and anything a single member of staff signed up to.
- Switch on MFA everywhere it is offered. Start with email and admin accounts, then work through the list.
- Check updates on every device. Turn on automatic updates where you can, and remove any device or software that is no longer supported.
- Tidy up accounts. Remove leavers, separate admin accounts from everyday ones and change any default passwords.
- Read the Danzell questions before you buy. Answer them honestly in a draft first, so there are no surprises.
Costs depend on the size of your organisation; our guide to what Cyber Essentials costs in 2026 explains the bands.
How we can help
We do not certify, and we cannot guarantee you will pass. What we offer is Cyber Essentials readiness: an independent look at your setup against the current requirements, so you know what to fix before you pay for an assessment. Certification itself is carried out by an IASME certification body. Nothing in this article is legal advice. For more guides, head back to the blog.
Ready for Cyber Essentials under Danzell?
Book a free external audit. We will review your controls, website and email security and tell you plainly what to fix before you apply for Cyber Essentials.
Book a free audit