cyber-essentials-requirements-2026
  • Cyber Essentials
  • 22nd Jul 2026
  • 1 min read

Cyber Essentials Requirements 2026

Gabriel Few-Wiegratz
  • Written by
Gabriel Few-Wiegratz
View my profile on
In Short..
  • Scope is determined by control, not ownership. Cloud services, BYOD devices, home-working equipment, and managed systems may all fall within scope if your organisation configures or administers them.
  • Multi-factor authentication is mandatory. MFA must protect all accounts that can access internet-facing services, regardless of perceived risk.
  • Patch management requirements are strict. Critical and high-severity vulnerabilities must be remediated within 14 days across operating systems, applications, firmware, and browser extensions.
  • Unsupported software is not permitted. Any end-of-life software on an in-scope device results in an automatic certification failure.
  • The scheme has a new name for 2026. Assessments are now run against the Danzell scheme, which replaced Willow on 26 April 2026. If your last certification predates that date, your scope statement needs a fresh look, not a rollover.

Cyber Essentials and Cyber Essentials Plus assess organisations against the same five security controls. The difference is not the standard itself, but how compliance is validated: Cyber Essentials relies on self-assessment, while Cyber Essentials Plus independently verifies controls through technical testing.

 

Working towards certification? Our Cyber Essentials resource hub brings together everything in one place: the five controls, certification costs, the self-assessment questionnaire, and what Cyber Essentials Plus actually tests. Start there to plan your route to certification.  

Expert View

undefined-May-25-2026-06-11-05-9774-PM

 

Matt Davies

Chief Product Officer, SureCloud

LinkedIn



 

 

What our experts say about scope decisions that catch organisations out

 

"The scope questions that trip organisations up most often are cloud services and BYOD. The principle is simple: if you control the configuration, it's in scope. But applying that to a mixed estate of M365, SaaS tools, and personal devices requires deliberate scoping decisions, not assumptions. Get this agreed with your ASP before you open the questionnaire."

The Danzell Scheme: The Current Requirements Framework

Cyber Essentials is assessed against the Danzell scheme requirements. Danzell replaced the earlier Willow scheme on 26 April 2026 and is the version in force for every 2026 assessment submitted from that date onward. Willow ran from January 2022 to April 2026 and was the scheme that made MFA mandatory for all internet-facing accounts, tightened the patch management window, and set out how cloud services and personal devices are scoped — the requirements this article covers below.

 

Danzell carries those core requirements forward. If your organisation certified, or last reviewed its scope, under Willow, treat 2026 as a checkpoint rather than a rollover: confirm what applies now instead of assuming last year’s scope statement still holds. For the technical detail on what moved under each scheme, see our breakdowns of Cyber Essentials Plus v3.2 (Willow): What Changed and Cyber Essentials v3.3 Danzell: What Changed.

 

The IASME scoping guidance and the NCSC’s Cyber Essentials Requirements for IT Infrastructure document are the authoritative sources for both schemes. This article interprets and explains those requirements; organisations should review the current specification directly before assessment.

Defining Your Scope: What Is In and What Is Out

The scope boundary defines which systems, devices, and users the certification covers. Every device and service within that boundary must meet all five CE controls. Scope definition is where most first-time applicants run into problems, because the Montpellier scheme is explicit about cloud services and personal devices in ways the earlier scheme was not.

 

What is in scope by default

  1. All end-user devices that can access internet-facing services: laptops, desktops, tablets, and smartphones, whether organisationally owned or personally owned if used for work.
  2. All servers where the organisation manages the operating system and software configuration, including on-premises servers, cloud-hosted virtual machines, and containers.
  3. Network devices that form the boundary between the organisation's network and the internet, and those within the internal network: routers, switches, firewalls.
  4. Cloud services where the organisation controls the configuration above the infrastructure layer: Microsoft 365 tenancies, Google Workspace tenancies, and AWS or Azure instances with organisation-managed operating systems.

Cloud services: scope follows control

This is the most frequently misunderstood aspect of current CE requirements. The principle is straightforward: if your organisation configures and manages a service, it’s in scope. If a service’s infrastructure and configuration is entirely controlled by the provider, the underlying infrastructure may be out of scope.

 

But the key word is infrastructure.

  1. In scope: your Microsoft 365 tenancy, including Exchange Online, SharePoint, Teams, and the associated Azure Active Directory or Entra ID configuration. Your organisation controls account provisioning, MFA policy, conditional access, and device management settings within M365. That configuration is in scope.

  2. In scope: AWS EC2 instances where your organisation manages the operating system and installed software.

  3. Potentially out of scope: SaaS applications where the provider manages all infrastructure, OS, and patching. But your configuration of accounts, MFA enforcement, and data access controls within those platforms may still fall within CE requirements. 4. When in doubt: include the service in scope and verify controls are met. Excluding a service and later finding it should have been included creates a gap that may invalidate certification.


BYOD and home-working devices

Personally owned devices that access organisational systems may be in scope. The Danzell scheme is explicit: if a personal device directly accesses in-scope work services, and no technical control prevents that direct access, the device may fall within scope.

 

Three practical approaches exist: 

  1. First, include BYOD devices in scope and verify they meet all five controls. This requires visibility and management capability over personal devices the organisation may not have.

  2. Second, implement a technical control such as Virtual Desktop Infrastructure or a browser-based access solution that means the personal device never directly accesses in-scope systems. In that scenario, the personal device itself may be excluded.

  3. Third, prohibit BYOD access to in-scope systems entirely and enforce that prohibition technically.

Organisationally owned devices used for home working are in scope and must meet all five CE requirements, including personal firewalls.

Requirements by Control: What the Scheme Requires in 2026

Scope tells you which systems are covered. This is what each of the five controls demands of them, in brief. For the reasoning behind each requirement, worked examples, and implementation guidance, see The 5 Cyber Essentials Controls Explained — this table is a summary, not the full walkthrough of what each control actually requires.

 

Control

What’s mandatory in 2026

 

Firewalls

Boundary and device firewalls configured on every in-scope device, with no unauthenticated default rules or unnecessary open ports.

Full breakdown →

Secure configuration

Default passwords changed, unnecessary accounts and software removed, autorun and unneeded functionality disabled.

Full breakdown →

User access control (incl. MFA)

Access granted on a need-only basis; MFA mandatory on every account that can reach an internet-facing service.

Full breakdown →

Malware protection

Anti-malware active and maintained on every in-scope device, or application allowlisting used instead.

Full breakdown →

Patch management

Critical and high-severity vulnerabilities patched within 14 days; only vendor-supported software permitted.

Full breakdown →

How Requirements Differ Between CE and CE+

Standard CE and CE+ assess against the same five controls and the same technical requirements. The difference is not in what is required but in how compliance is verified.

 

Aspect

Standard CE

CE+

Requirements tested

All 5 controls

Same 5 controls, no additional requirements

Verification method

Self-assessment questionnaire reviewed by ASP

Technical verification by an approved assessor: scanning, configuration checks, device sampling

Timing constraint

None beyond annual renewal

Must complete within 3 months of standard CE certification

 

What "Supported Software" Means in Practice

Supported software is software for which the vendor is still releasing security updates. The definition is simple; the practical implications catch organisations out. 1. Windows 10 reached end of support in October 2025. Devices still running Windows 10 are already out of CE compliance. Organisations with Windows 10 in scope needed to complete migration to Windows 11 or an alternative supported OS before that date. 2. Third-party applications that have reached end-of-life fail the supported software requirement regardless of whether all other CE requirements are met. 3. The supported software check applies to firmware on network devices and servers, not only to installed software. 4. There is no grace period. The date a vendor ends support is the date from which that software is out of compliance.

Am I Ready? A Pre-Submission Self-Check

Before submitting a CE self-assessment, work through these questions. A “no” or “uncertain” answer is a remediation item, not a question to navigate carefully in the Cyber Essentials questionnaire. 1. Have all devices in scope been identified and documented, including cloud services and remote-working devices? 2. Is all software on in-scope devices currently supported by its vendor, with security updates still available? 3. Have critical and high-severity patches been applied within the last 14 days across all in-scope systems? 4. Have default credentials been changed on all network devices, hardware, and software? 5. Is MFA enforced for all accounts that can access internet-facing services, including Microsoft 365 and any cloud applications? 6. Are administrative accounts separate from standard user accounts, with no unnecessary admin accounts active? 7. Is anti-malware installed and actively maintained on all in-scope devices, or is application allowlisting in place? 8. Are personal firewalls enabled on all laptops and mobile devices used outside the office network? 9. Do you have a complete, current software inventory for all in-scope devices?

Once you’ve worked through this list, the next step is filling in the questionnaire itself. Our guide, How to Complete the Cyber Essentials Questionnaire, walks through each section and the evidence assessors expect to see.

Key Facts

  1. The Danzell scheme, in force from 26 April 2026, is the requirements framework for CE assessments from that date. Willow applied from January 2022 to April 2026.
  2. All five controls must be met across every system within scope.
  3. MFA must be enforced on all internet-facing accounts without exception.
  4. Windows 10 reached end of support in October 2025. Devices still running it are already out of CE compliance.
  5. The 14-day patch window applies to everything on in-scope devices.
  6. CE+ does not apply different requirements — same requirements, independent technical verification instead of self-assessment.

Know Your Control State Before You Submit

Gracie AI Agents with Personas and Skills map your organisation's current position against all 2026 CE requirements, surfacing gaps and organising evidence so decisions on remediation are made 40% faster. See how SureCloud Assure works.
Related articles:
  • Cyber Essentials

Cyber Essentials Cost: What UK Organisations Pay

  • Cyber Security
  • Cyber Essentials

Cyber Essentials Plus: How to Operationalise It

  • Cyber Essentials

The 5 Cyber Essentials Controls Explained

Share this article

FAQ’s

What is the Cyber Essentials Danzell scheme?

Danzell is the name of the current Cyber Essentials requirements framework, effective from 26 April 2026. It replaced the Willow scheme, which had been in force since January 2022, and is the version all 2026 assessments are measured against. 

Is Cyber Essentials certification mandatory in 2026?

 Cyber Essentials is not a legal requirement for most private-sector organisations, but it is mandatory for suppliers bidding on certain UK government contracts, and increasingly requested by commercial customers and insurers as a baseline assurance standard. 

My scope statement was approved under Willow. Do I need to redo it for Danzell?

 Not automatically, but you should review it. Danzell carries the same five controls forward, so a scope statement built correctly under Willow will usually still hold. Confirm this rather than assume it, particularly if your cloud services or device estate have changed since your last assessment. 

Do I need Cyber Essentials Plus as well as standard CE?

 Not always. Standard CE and CE+ test the same five controls; CE+ simply verifies them independently through technical testing rather than self-assessment. Whether you need CE+ typically comes down to what your customers, contracts, or insurers require. See our full comparison for the detail. 

How long does Cyber Essentials certification last?

 Certification is valid for 12 months from the date of assessment. Because the underlying scheme requirements can change between renewals, as they have with the move from Willow to Danzell, treat each renewal as an opportunity to re-check scope and controls rather than a formality.