DEV Community

Cover image for The April 2026 Cyber Essentials Change That Will Auto-Fail Your Audit
With Nate
With Nate

Posted on Fully Autonomous

The April 2026 Cyber Essentials Change That Will Auto-Fail Your Audit

On 27 April 2026, Cyber Essentials moved to version 3.3 of the Requirements for IT Infrastructure — question set codenamed "Danzell." If you've passed Cyber Essentials before under the old marking scheme, read this before your next renewal. The five core controls haven't changed. What changed is how strictly they're marked — and several things that used to cost you points now fail the audit outright.

Nothing new to build. Your existing setup can now auto-fail.

That's the part worth sitting with. This isn't "here are three new controls to implement." It's "the same five controls you already have are now marked with zero tolerance in specific places." If your organisation currently scrapes through on a technicality, Danzell is designed to catch exactly that.

The changes that actually bite

MFA becomes strictly mandatory, everywhere it's available. Any cloud service where multi-factor authentication exists — free, bundled, or paid tier — now requires it. Not "recommended," not "deduct points if missing." Missing MFA on any in-scope cloud service where the provider offers it is an automatic fail. If you've been treating MFA as something to roll out "eventually" on lower-priority services, this is the deadline that removes the option.

Patching gets a hard 14-day SLA. High-risk and critical updates for operating systems, firmware (routers, firewalls — not just laptops), and applications must be installed within 14 days of release. Miss that window and it's an automatic fail, not a marked-down score. If your patch cadence is "monthly Patch Tuesday plus whatever we get to," check the actual gap between release and install for your critical assets — 14 days is tighter than most SME patch cycles.

Scoping just got a lot less forgiving. The old certification let you write ambiguous exclusions — "untrusted" devices, "user-initiated" processes — and get away with vague language. That's gone. Cloud services can no longer be excluded from scope at all. Any device or network exclusion now needs formal justification plus proof of genuine segregation, not a line in the questionnaire. If your current cert relies on excluding something that isn't actually properly isolated, this is where that gets found.

Certificates require precise legal-entity detail. Full legal name, address, company number. If you operate as a corporate group, separate certificates per entity are now available (for a small fee) rather than one certificate awkwardly covering everyone.

Directors sign a personal declaration for the full 12-month period. This is the real accountability shift. It used to be about confirming controls were in place on audit day. Now a director is putting their name to maintaining compliance for the entire certification period — not a point-in-time snapshot.

Cyber Essentials Plus gets stricter too. Verified self-assessment answers can no longer be altered once the CE+ audit begins. And if patching failures turn up during testing, remediation now has to cover the whole environment, with expanded re-testing — not just fixing the one device the assessor happened to flag.

What to check before your next audit

  1. Audit every cloud service in scope for MFA availability, not just the obvious ones. If a service offers it and you haven't turned it on, that's your most likely auto-fail.
  2. Measure your actual patch-to-install gap for OS, firmware, and application updates on anything in scope. Not your policy — your real numbers.
  3. Review every exclusion in your current scope statement. If it's vague ("untrusted devices") or covers a cloud service, it needs to be rewritten or the device/service needs to come back into scope with real segregation evidence.
  4. Confirm your legal entity details are exact — name, address, company number — especially if you're part of a group structure.
  5. Make sure whoever is signing the director's declaration understands what they're actually committing to — this is no longer a box-ticking signature.

The bottom line

Cyber Essentials hasn't added new hoops to jump through. It's closed the gaps that let organisations pass while quietly not really meeting the five controls it's always asked for. If you're renewing after 27 April 2026, the honest move is to check your MFA coverage and patch timing against the new hard limits now, not the week before your assessment.

I've sourced the specifics of the April 2026 update from IASME (the scheme's own accreditation body) and cross-checked against several independent compliance publishers, but the scheme's own documentation is the definitive source — always verify against current NCSC/IASME guidance before your audit rather than relying solely on this summary.


This post was written with AI assistance. The research behind it draws on publicly available scheme documentation and third-party compliance analysis current as of August 2026.


If you found this article helpful or informative, please consider supporting us by visiting our creative sister brand, With Nate on Etsy.

Top comments (0)