We’re seeing it more and more, whether that’s in onboardings, audits, or early conversations with prospects: businesses that hold Cyber Essentials (or at least assume they’d pass it comfortably) discovering they no longer would. Often they have no idea anything has shifted.
What’s shifted is the standard itself. Version 3.3, known as Danzell, is the most material set of Cyber Essentials 2026 changes in years, and it applies to all new assessments from 27 April 2026. The five core controls haven’t changed. What’s changed is how strictly they’re now marked, which has quietly moved the bar for a lot of organisations who were certain they were covered.
Here’s what’s actually changed under v3.3: the gaps we’re seeing catch people out, and the practical way to find out exactly where you stand.
What’s Actually Changed Under v3.3
The five controls are the same. The marking is stricter, and three of the changes now carry automatic failure; get one wrong and the rest of your assessment doesn’t matter.
MFA is now an auto-fail. The Cyber Essentials MFA requirements have hardened considerably: if multi-factor authentication is available on an in-scope cloud service and it isn’t enabled for all users, the assessment fails. It makes no difference whether MFA is free, included, or a paid add-on – if it’s there and it’s off, that’s a fail.
The 14-day patching rule is now an auto-fail. High-risk and critical security updates for operating systems, router and firewall firmware, and applications must be applied within 14 days of release. These are the scheme’s two new auto-fail questions (A6.4 and A6.5), so a gap here sinks the whole assessment on its own.
Cloud services can no longer be excluded from scope. Danzell adds a formal definition of a cloud service, and the rule is simple: if it stores or processes your data, it’s in. Microsoft 365, Google Workspace, your CRM, accounting, HR – all of it. Cyber Essentials cloud services scoping is no longer something you can get away with leaving out.
Scoping has been tightened. Every legal entity in scope must now be listed by name, address, and company number, and any exclusions have to be described and justified.
CE+ has been hardened. Selective patching of only the devices being sampled no longer passes. A retest pulls a fresh random sample, and the self-assessment can’t be amended once testing begins.
The director’s declaration now covers ongoing compliance throughout the certification period, not just at the point of assessment.
Why Businesses Are Slipping Out Without Realising
The pattern is consistent, and it’s rarely a single dramatic failure.
- Partial MFA that’s switched on for admin accounts but not general users or missing on one cloud service the team had quietly written off as an edge case.
- Informal patching was good enough before, but a 14-day window with an auto-fail attached forces a documented process and the reporting to prove it.
- Cloud sprawl made scoping loose, with systems left out that should never have been.
The MFA gap alone is wider than most people assume:
The Government’s Cyber Security Breaches Survey 2025/2026 found that just 47% of UK businesses use two-factor authentication, meaning over half would fall foul of the new rule from day one.
Thankfully, most of the gaps we’re spotting are just the unsexy operational stuff that’s been overlooked for years:
- Servers patched on no documented schedule
- Critical updates left well beyond 14 days
- Remote access still resting on a username and password alone
The new standard catches all of it.
What to Do About It
Four practical steps will tell you most of what you need to know:
- Audit your MFA coverage: It should apply across every cloud service in your environment – not just the obvious ones like Microsoft 365, but also the CRM, accounting, and HR systems that hold your data too.
- Document a 14-day patching cycle: It needs to cover operating systems, firmware, and applications. Make sure you can evidence it, not just assert it.
- Map your cloud services honestly: Decide what’s genuinely in scope before an assessor does it for you.
- Get visibility on your Microsoft Secure Score: That way, the posture underneath all of this is something you can measure and improve rather than guess at.
For most organisations, that’s where good managed IT services in Devon earn their keep, keeping these things in order so certification becomes a formality rather than a scramble.
See How You’d Score Against v3.3
The standard has moved closer to operational reality. For us, much of v3.3 simply formalises what’s been our baseline since day one, having operated to public sector and defence-grade standards from the start. The real question is where your own environment sits against it now. An honest assessment is the quickest way to find out, whether you’re based in Devon, Somerset, or anywhere across the UK.
Book your free M365 assessment with us and get a free review of your Microsoft 365 environment, benchmarked against CIS and the new Cyber Essentials standard.
