Skip to main content
    NixInfinity-AI
    2026 Updates

    Cyber Essentials Danzell 2026: What Changed

    Published 30 April 2026

    The headline changes

    1. MFA on every cloud user account

    Previously MFA was firmly required on admin accounts and "where available" on user accounts. Danzell makes MFA mandatory for all cloud service user accounts in scope. See the full MFA requirements guide.

    2. Passkeys explicitly accepted

    FIDO2 passkeys (Windows Hello for Business, Apple Passkeys, hardware security keys) are now explicitly named as accepted MFA methods.

    3. Cloud service scope tightened

    The definition of an in-scope cloud service is sharper. Any IaaS / PaaS / SaaS used to store or process organisational data is in scope, and you must list them. See our cloud services guide.

    4. BYOD treatment clarified

    BYOD devices accessing in-scope cloud services bring those accounts (not the device) into scope. MFA, password policy and account hygiene still apply. See our BYOD guide.

    5. Patching language reinforced

    The 14-day rule for high/critical CVEs (CVSS v3 7.0+) is unchanged but assessors are explicitly told to require evidence, not just policy. See our 14-day patching guide.

    What you need to do for renewal

    • Re-confirm MFA is enforced on every cloud user account (not just admins)
    • Document your full list of in-scope cloud services
    • Disable any legacy authentication paths that bypass MFA
    • Have patch evidence ready (Intune, RMM, or similar report)
    • Review BYOD policy if staff use personal devices for work

    Download the official Danzell question set

    The full Excel file is available free from our Cyber Essentials hub.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions