Cyber Essentials Danzell 2026: What Changed
Published 30 April 2026
The headline changes
1. MFA on every cloud user account
Previously MFA was firmly required on admin accounts and "where available" on user accounts. Danzell makes MFA mandatory for all cloud service user accounts in scope. See the full MFA requirements guide.
2. Passkeys explicitly accepted
FIDO2 passkeys (Windows Hello for Business, Apple Passkeys, hardware security keys) are now explicitly named as accepted MFA methods.
3. Cloud service scope tightened
The definition of an in-scope cloud service is sharper. Any IaaS / PaaS / SaaS used to store or process organisational data is in scope, and you must list them. See our cloud services guide.
4. BYOD treatment clarified
BYOD devices accessing in-scope cloud services bring those accounts (not the device) into scope. MFA, password policy and account hygiene still apply. See our BYOD guide.
5. Patching language reinforced
The 14-day rule for high/critical CVEs (CVSS v3 7.0+) is unchanged but assessors are explicitly told to require evidence, not just policy. See our 14-day patching guide.
What you need to do for renewal
- Re-confirm MFA is enforced on every cloud user account (not just admins)
- Document your full list of in-scope cloud services
- Disable any legacy authentication paths that bypass MFA
- Have patch evidence ready (Intune, RMM, or similar report)
- Review BYOD policy if staff use personal devices for work
Download the official Danzell question set
The full Excel file is available free from our Cyber Essentials hub.
