CE v3.3: What Changed in April 2026 and What It Means for Your Agency
If you already hold a Cyber Essentials certificate, your existing certification is not affected. But if you are due to recertify, planning your first assessment, or have been putting this off, the version of the standard you will be assessed against changed on 27 April 2026. The update is called Danzell, and several of the changes matter a great deal for agencies that run on cloud tools.
What is v3.3, and why does it have a codename?
Each annual update to the Cyber Essentials scheme is named after a UK lighthouse. The previous version was Willow. From 27 April 2026, all new assessments use Danzell, which corresponds to version 3.3 of the NCSC Requirements for IT Infrastructure.
The five core controls remain unchanged. Danzell does not introduce new technical requirements. What it changes is how rigorously the controls are assessed, and for the first time in the scheme’s history, it introduces automatic failure conditions. Previously, gaps could result in a “needs improvement” outcome. Under Danzell, certain gaps mean an outright fail, regardless of how well everything else is done. The NCSC published the v3.3 requirements in January 2026, giving organisations a full quarter to prepare before the switchover date.
If you are preparing for a Cyber Essentials assessment now or in the coming months, you are working to the Danzell standard. Make sure any guidance or checklists you use reflect v3.3, not the previous Willow version.
MFA is now an automatic failure
This is the change that affects most agencies most directly. Under Danzell, if a cloud service you use supports multi-factor authentication and you have not enabled it for all users, you fail the assessment. No partial credit. No allowance for a rollout in progress. The rule is binary: MFA is on for every user, or it is not.
Under Willow, MFA was required for cloud services and remote access, but the marking allowed for some context. Partial deployments could, depending on circumstances, avoid an automatic failure. That flexibility is gone.
Think about the tools your agency uses daily: Microsoft 365 or Google Workspace, Slack, Adobe Creative Cloud, Xero, your project management platform. All of these support MFA. Under Danzell, all of them must have it enabled across every user account. That includes shared accounts, contractor accounts, and any access that persists from a former member of staff.
The practical implication before you start an assessment: audit every cloud service your agency uses and confirm that MFA is enabled for every account. This is not something to discover on the day of submission.
Cloud services can no longer be excluded from scope
The second significant change is to what counts as in-scope. Under v3.2, organisations had some flexibility to treat cloud services as outside the boundary of their assessment. That flexibility has been removed.
Danzell adds a formal definition: a cloud service is an on-demand, scalable service hosted on shared infrastructure and accessible via the internet. If a service fits that definition and your organisation uses it to store or process data, it is in scope. The IASME guidance makes clear that cloud services storing or processing organisational data can no longer be excluded.
For creative agencies, this is a meaningful shift. Most agencies have migrated the majority of their data and workflows to SaaS platforms over the last five years. Email lives in the cloud. Files live in the cloud. Accounts, project tracking, client communication, and often the CRM. Under Danzell, all of it needs to meet the Cyber Essentials controls: MFA enabled, user access managed to the principle of least privilege, software supported and patched.
The scope definition work that was often optional before is now required. You need to know what cloud services your agency runs, who has access to each one, and whether those access levels are appropriate.
Patching: 14 days and no exceptions
The third change strengthens the patching requirements. High and critical vulnerabilities for operating systems, router and firewall firmware, and applications must be patched within 14 days of release. Two questions in the Danzell questionnaire, A6.4 and A6.5, cover these requirements. Failure on either is now an automatic fail, regardless of how the rest of the assessment goes.
This is not a new expectation in principle, but it is now enforced with no tolerance. A single high-severity patch outstanding for more than 14 days is enough to fail the assessment. Relying on auto-updates alone may not be sufficient if those updates do not cover third-party applications, browser extensions, or firmware on your networking equipment.
For most agencies, the practical response is to make sure your IT provider has documented evidence of patching compliance, not just a best-efforts process. If you manage IT in-house, it is worth scheduling a patching review before you start your assessment.
What this means in practice for your agency
Agencies running a SaaS-heavy environment are affected more by Danzell than those running traditional on-premise IT. The MFA rule and the expanded cloud scope together mean the assessment now tests your actual working environment, not a simplified version of it.
Preparation for a Danzell assessment looks like this:
- Audit every cloud service in use, including tools accessed by freelancers or contractors who handle your data.
- Confirm MFA is enabled for every user account across every service that supports it.
- Review user access levels. Remove access for anyone who no longer needs it. Check that permission levels reflect actual roles.
- Check your patching status across devices, firmware, and applications. Make sure there is a clear process for applying critical updates within 14 days.
None of this is technically complex. For most agencies, it is a question of visibility and documentation. The agencies that will struggle are those that have not mapped their cloud environment or do not have consistent processes for access management and patching.
If your existing certificate is still current, no action is required now. But if you are planning to recertify in the second half of 2026, start the preparation against the Danzell standard rather than the previous one.
If you have not yet assessed your agency’s current position against the v3.3 requirements, the Cubit Cyber Check gives you a clear picture in 5 minutes.