Cyber Security

Cyber Essentials Support for Kent SMEs

Cyber Essentials renewal for Kent SMEs: what support actually involves, evidence you need under Danzell v3.3, and how to tell real help from a free audit.

Cyber Security

Cyber Essentials Support for Kent SMEs

Cyber Essentials renewal for Kent SMEs: what support actually involves, evidence you need under Danzell v3.3, and how to tell real help from a free audit.

Published:

If your Cyber Essentials certificate is approaching its 12-month expiry, you are probably asking whether to renew on your own or buy support from a provider. For owner-managed SMEs in Kent, that decision is harder than it used to be — the question set changed in April 2026, and last year's answers will not carry straight through.

This article explains what Cyber Essentials support actually involves at renewal, what evidence a competent provider should assemble for a Microsoft 365 estate, how the Danzell update changes the game, and how to tell real help from a "free audit" that leads to a sales call.

For context on the full scope of the scheme, see our Cyber Essentials hub page, which covers certification pathways, evidence requirements and how CE fits into a broader security operating model.

What Cyber Essentials support actually involves

Cyber Essentials is the UK Government-backed scheme managed by IASME, with technical standards set by the NCSC. Certification costs from £320 + VAT for a self-assessment, or requires a quoted technical audit if you need Cyber Essentials Plus. Certificates are valid for 12 months and must be renewed annually under whichever question set is current at the time of renewal.

Support from a provider typically covers four stages:

  1. Gap assessment — mapping your current estate against the five technical controls (firewall, secure configuration, security update management, user access control, malware protection) and identifying where you fall short of the current requirements.

  2. Remediation — fixing the gaps. This might mean enabling MFA on a cloud service, tightening admin access, updating unsupported software, or standardising device builds.

  3. Evidence assembly — preparing the screenshots, exports and policy documents you need to submit with your self-assessment, or handing them to the assessor if you are going through CE Plus.

  4. Submission and remarking — completing the questionnaire on your behalf, managing any assessor feedback, and resubmitting within the two-day remediation window if required.

For an SME running Microsoft 365, this means the support provider needs to understand your cloud service inventory, your remote-working setup, and how your identity and device management are configured — not just your office network. Our article on Microsoft 365 for Kent SMEs walks through the same estate from a backup-and-security perspective.

What the Danzell update changes for renewals

Assessment accounts created from 27 April 2026 use the Danzell question set, built on version 3.3 of the NCSC Requirements for IT Infrastructure. This is the same scheme — five technical controls, same basic structure — but several operational details have tightened.

The changes most relevant to a Kent SME renewing now:

MFA is now a hard pass-or-fail rule for cloud services. If any in-scope cloud service offers MFA — free, paid, or via a connected service — and you have not enabled it, you will fail automatically. This applies to all users on those services, not just administrators.

The 14-day patch window is enforced more strictly. High-risk or critical security updates must be applied within 14 days of release across your entire estate. Unsupported software in scope remains an automatic fail, as it always has been.

Cloud services cannot be excluded from scope. This was already the direction of the scheme, but v3.3 now states it definitively. Microsoft 365, your CRM, project management tools, shared drives — all in scope. Business-owned social media accounts (LinkedIn, Facebook, X) are now explicitly called out as cloud services in the Danzell question set.

Scoping is more granular. Danzell asks for more operational detail: how many employees, what addresses are in scope, how remote workers connect, what equipment creates any sub-sets. Partial scope still exists, but the separation must be a real firewall or VLAN boundary — not software-based methods.

Named internal ownership is non-negotiable. The responsible person for in-scope IT systems must be a member of your organisation, not employed by your outsourced IT provider. That was already true under the previous version, but it is now reinforced alongside wider scope and accountability questions.

If you certified under the previous Willow question set (before 27 April 2026), your current certificate remains valid until expiry. But when you renew, you will be assessed against Danzell and v3.3 regardless of which version you originally certified under. You cannot recycle last year's answers.

Evidence: what a competent provider assembles for your M365 estate

The evidence pack is where most SMEs struggle — not because they lack security, but because they have never had to prove it in one place. Under Danzell, the evidence expectations are more detailed than before.

A solid support provider will help you build:

  • Scope statement — a clear document listing every in-scope user, device, location and cloud service.

  • Asset inventory — a current list of all devices touching business data, including remote and BYOD devices.

  • MFA coverage evidence — screenshots or exports showing MFA enforcement across all cloud services where it is available.

  • Admin access documentation — a list of who holds admin rights on each system, with separation between day-to-day user accounts and privileged access.

  • Patch status reports — evidence that critical updates are applied within the 14-day window and that unsupported software has been removed or isolated from scope.

  • Endpoint protection coverage — proof that every in-scope device has active, centrally managed malware protection.

  • Firewall and network configuration — screenshots showing boundary controls, disabled remote management interfaces, and firmware versions.

  • Written policies — joiner/mover/leaver process, BYOD stance, password policy, and incident responsibility statements.

  • Named ownership records — documented internal owners for each control area, not the MSP.

If your provider cannot produce a structured evidence pack like this, you are paying for something less than genuine support.

Our Cyber Essentials self-assessment questionnaire guide breaks down every question in the free Danzell form so you know exactly what evidence to prepare before you start.

How long does Cyber Essentials renewal take?

From the IASME FAQ, you have six months from the date of application to complete your assessment. If you prepare your answers in advance using the free question set, the self-assessment itself may take about an hour. Once submitted, most assessors aim to return results within three days. If you fail, you get two working days to address issues and resubmit, after which the assessor has up to three days to remark.

For SMEs buying support, plan to start preparation at least 60 days before your certificate expires. This gives you time to close gaps that the new question set now treats as automatic fails — particularly MFA coverage on cloud services and patch compliance across your full estate.

How a Security Baseline Review differs from a "free audit"

You will see providers offering "free Cyber Essentials audits". It is worth understanding what that actually means.

A Security Baseline Review from Infinite Cloud IT is a paid, structured assessment mapped to CE-style controls. It produces a written evaluation of your current posture across identity, devices, patching, malware protection and backup — the five technical control themes that Cyber Essentials tests. It does not guarantee certification, and it is not a sales call in disguise.

A "free audit" offered as a lead-generation tool typically aims to surface problems that only the provider can fix. It rarely produces a written report you can keep, and it does not distinguish between what the scheme actually requires and what the provider sells.

Read our Security Baseline Review vs free audit for a side-by-side comparison of what each option actually delivers.

If you are weighing whether to renew alone or with support, a Baseline Review gives you a baseline assessment you can reference — whether you ultimately choose Infinite Cloud IT or another provider. It is not a substitute for Cyber Essentials certification, but it tells you what gaps exist before you spend money on the assessment itself.

The normal commercial sequence is a Security Triage Call first, then a paid Security Baseline Review where appropriate, followed by managed service. We do not bypass that diagnostic path.

Common renewal questions

Can we renew without changing our setup?

If your current controls already meet the Danzell v3.3 requirements, you may not need to change anything technically. However, the question set now asks for more operational detail — about scope boundaries, cloud service inventories and named ownership. Even if your controls are sound, you may need to document things more precisely than last year.

What happens if we fail the assessment?

You get two working days to address the issues flagged by the assessor and resubmit your answers at no extra cost. If you still fail after those two days, you must reapply and pay the assessment fee again. This is why preparation matters — starting 60 days before expiry gives you room to fix problems rather than rushing.

Should we do Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials (self-assessment) costs from £320 + VAT and involves answering the questionnaire with supporting evidence. Cyber Essentials Plus costs more — IASME does not publish a fixed fee, and each assessment is quoted individually by Certification Bodies based on the size and complexity of your network — but adds an independent technical audit where an assessor tests a sample of your systems.

If a customer or insurer requires the higher assurance level, or if you are bidding for government contracts that specify CE Plus, go for Plus. Otherwise, standard Cyber Essentials meets the baseline requirement recommended by the UK Government.

Do we need an accredited body conversation first?

No — you register directly through IASME. If you want support, you can hire a Certification Body to help you understand the questions and prepare your evidence. Certification Bodies are trained and licensed by IASME to assess organisations and issue certification. They also offer consultancy services.

Next steps

If your certificate is approaching expiry, the first step is understanding where you stand against the current Danzell requirements. A Security Triage Call gives you a high-level view of your security posture and whether you need a deeper Baseline Review before going to assessment.

Book a Security Triage Call

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.