Skip to main content
    NixInfinity-AI
    Danzell 2026

    Cyber Essentials Danzell vs Willow: Every Change Explained

    Published 29 June 2026

    What actually changed

    • Scoping – clearer rules on what counts as a sub-set scope and how home workers are declared.
    • Cloud services – sharper distinction between IaaS, PaaS and SaaS responsibility splits.
    • Multi-factor authentication – stricter wording on administrative accounts and cloud admin consoles.
    • Patching – the 14-day rule is unchanged, but evidence expectations are firmer.
    • CE Plus methodology – revised sampling and marking framework for the assessor.

    What has not changed

    The five controls – firewalls, secure configuration, user access control, malware protection and security update management – are identical. The 30-day rule between CE and CE Plus is unchanged. The free £25,000 cyber insurancefor eligible UK organisations is unchanged.

    Which question set applies to you

    If your assessment account was created on or after 27 April 2026, you are on Danzell. Accounts created before that date can still complete under Willow within the existing 6-month submission window, then move to Danzell at renewal. See our Danzell hub for the full transition timeline.

    Where firms trip up

    • Assuming "no change" because the controls list looks identical.
    • Re-using Willow-era screenshots that do not address the new scoping wording.
    • Missing MFA on a cloud admin console that was previously borderline.

    Next steps

    Read our deep-dives on scoping, MFA and cloud services under Danzell, or book a Cyber Essentials assessment with our IASME-licensed assessors.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions