Cyber Security

Cyber Essentials v3.3 (Danzell): What Changed on 27 April and Why It Matters

Cyber Essentials v3.3 (Danzell) changed on 27 April 2026. Here's what changed, who's affected and how to prepare your SME for the new assessment requirements.

Cyber Security

Cyber Essentials v3.3 (Danzell): What Changed on 27 April and Why It Matters

Cyber Essentials v3.3 (Danzell) changed on 27 April 2026. Here's what changed, who's affected and how to prepare your SME for the new assessment requirements.

Published:

Cyber Essentials v3.3 (Danzell): What Changed on 27 April and Why It Matters

On 27 April 2026, Cyber Essentials moved from its "Willow" framework to "Danzell" — a transition that changed how assessments are conducted, what evidence is required and how certificates are issued. For SMEs who certified under Willow or who are planning to certify under Danzell, understanding these changes isn't optional. It directly affects your compliance strategy and your timeline.

The UK government's terminology can be confusing, so here's a straightforward breakdown: "Willow" was the previous Cyber Essentials framework. "Danzell" is the current version (officially Cyber Essentials v3.3), and it has been the mandatory framework since 27 April 2026. If you started an assessment before that date but didn't complete it, you had a transition window. If you're starting fresh now, you're operating entirely under Danzell rules.

What Changed from Willow to Danzell

The core five controls of Cyber Essentials — firewalls, secure configuration, access control, malware protection and patch management — remain the same. What changed is how those controls are assessed and what evidence is expected:

1. Enhanced Technical Assessment

Under Willow, many certifications were issued based on a self-assessment questionnaire with optional technical validation. Danzell requires a mandatory technical assessment for all new certifications. This means an accredited certification body must perform active scanning and configuration checks, not just review your answers to a questionnaire.

2. Stricter Patch Management Expectations

Danzell places greater emphasis on documented patch management processes. While Willow accepted evidence that patches were applied, Danzell expects to see a defined cadence — evidence that you have a process for identifying, testing and deploying security updates across your estate.

3. Expanded Scope of Secure Configuration

The secure configuration control under Danzell explicitly expects evidence of baseline configurations for all device types, including mobile devices and remote access solutions. Willow was less prescriptive about this.

4. Improved Malware Protection Verification

Danzell assessments now expect evidence that endpoint protection is actively managed — not just installed. This includes confirmation that protection definitions are updated regularly and that the software is running on all eligible devices.

5. Clarified Access Control Requirements

Danzell provides more detailed guidance on access control expectations, including multi-factor authentication requirements for remote access and administrative accounts. While MFA wasn't explicitly required under Willow, it is now an expected component of a compliant access control strategy.

Who Is Affected?

SMEs Certifying Under Willow Before 27 April

If you submitted your self-assessment questionnaire before 27 April and your certification body accepted it under the Willow framework, your certificate remains valid for 12 months from the date of issue. You do not need to re-certify under Danzell until your current certificate expires.

However, if you submitted a questionnaire before 27 April but had not completed the full assessment (including any required technical validation) by the transition date, your submission may have been carried forward to Danzell automatically. Check with your certification body for confirmation.

SMEs Starting Assessment After 27 April

If you're starting a Cyber Essentials assessment now, you are operating entirely under Danzell rules. This means:

  • You will complete a self-assessment questionnaire

  • Your certification body will conduct a technical assessment

  • You must demonstrate compliance with the enhanced requirements across all five controls

SMEs with Existing Certificates Near Renewal

If your Cyber Essentials certificate expires within the next 12 months, plan your renewal under Danzell rules. The technical assessment requirement means the process will take longer and cost more than a Willow self-assessment renewal. Factor this into your budgeting and timeline.

Practical Steps for SMEs

  1. Check your current certificate status — When does it expire? Was it issued under Willow or Danzell?

  2. Review your patch management documentation — Do you have evidence of a defined patching cadence?

  3. Verify endpoint protection — Is active management documented, not just installation?

  4. Check MFA coverage — Is multi-factor authentication in place for remote access and admin accounts?

  5. Contact your certification body — Confirm whether you can still use Willow or must transition to Danzell

  6. The Cost Implication

    The shift from Willow to Danzell has increased certification costs for many SMEs. While Willow self-assessments could cost as little as £300, Danzell assessments typically range from £450–£750 depending on the size of your IT estate and the certification body you use. The technical assessment component adds both time and cost, but it also provides a more meaningful assurance of your security posture.

    Your Next Step

    If you're unsure whether your current IT setup meets Danzell requirements or need help preparing for a Cyber Essentials assessment under the new framework, a Security Triage Call covers your compliance readiness as part of our baseline review.

    Book a Security Triage Call

    *This article is part of the Infinite Cloud IT retrospective blog series, filling publication gaps identified during our 2026 content audit.*

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

More resources

Keep reading

Browse the latest practical guides across Managed IT, Cyber Security, Modern Workplace, and Backup

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.

For 10-15 seat

Owner-managed SMEs in Sussex & Kent

Who want clarity, stability, and a proper security baseline — start with the free Security Triage Call.