Danzell 2026
Cyber Essentials Danzell vs Willow: Every Change Explained
Published 29 June 2026
What actually changed
- Scoping – clearer rules on what counts as a sub-set scope and how home workers are declared.
- Cloud services – sharper distinction between IaaS, PaaS and SaaS responsibility splits.
- Multi-factor authentication – stricter wording on administrative accounts and cloud admin consoles.
- Patching – the 14-day rule is unchanged, but evidence expectations are firmer.
- CE Plus methodology – revised sampling and marking framework for the assessor.
What has not changed
The five controls – firewalls, secure configuration, user access control, malware protection and security update management – are identical. The 30-day rule between CE and CE Plus is unchanged. The free £25,000 cyber insurancefor eligible UK organisations is unchanged.
Which question set applies to you
If your assessment account was created on or after 27 April 2026, you are on Danzell. Accounts created before that date can still complete under Willow within the existing 6-month submission window, then move to Danzell at renewal. See our Danzell hub for the full transition timeline.
Where firms trip up
- Assuming "no change" because the controls list looks identical.
- Re-using Willow-era screenshots that do not address the new scoping wording.
- Missing MFA on a cloud admin console that was previously borderline.
Next steps
Read our deep-dives on scoping, MFA and cloud services under Danzell, or book a Cyber Essentials assessment with our IASME-licensed assessors.
