Reformed IT
01158 244 824Request a callback
Compliance · 5 min read

Cyber Essentials vs Cyber Essentials Plus: what's changed and which one your business needs

Cyber Essentials changed on 27 April 2026 under a new question set called Danzell, with stricter auto-fail rules on MFA and patching. Here's what's different, and which certification level your business actually needs.

By Felicity Price · Aug 2026
Cyber Essentials vs Cyber Essentials Plus: what's changed and which one your business needs — Reformed ITReformed IT · Nottingham office

If you’re looking into Cyber Essentials for the first time, or renewing a certificate you already hold, the rules changed this year. On 27 April 2026, the scheme moved to a new question set called Danzell. If your assessment account was created on or after that date, you’re being assessed under stricter terms than before.

The headline change is around multi-factor authentication. If a cloud service you use offers MFA and you haven’t switched it on, for every user, not just admins, that’s now an automatic fail. There’s no partial credit and no assessor discretion. The same applies to critical security updates: if a high-risk fix isn’t applied within 14 days, that’s an automatic fail too. Cloud services can no longer be left out of scope, and that includes things like business LinkedIn or Facebook accounts if they’re managed with company credentials.

None of this changes what Cyber Essentials actually covers. The five controls are the same as they’ve always been. What’s changed is how much room there is for gaps. Things that used to just get flagged now fail the whole assessment outright.

So what’s the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment. You answer a set of questions about your organisation’s security controls, a qualified assessor reviews your answers, and if everything checks out, you’re certified. It’s a good baseline and it’s often enough to satisfy a client or a tender requirement asking for “Cyber Essentials.”

Cyber Essentials Plus goes further. You still complete the same self-assessment, but once your answers are verified, an assessor also runs hands-on technical tests on your systems. They check that what you said in the questionnaire actually matches what’s happening on your network and devices. It’s the difference between telling someone your systems are secure and having someone independently check.

One thing worth knowing under Danzell: once your self-assessment answers are verified and Cyber Essentials Plus testing begins, you can’t go back and change them. If there’s a gap between what you’ve declared and what the assessor finds on testing, that’s a problem you’ll be dealing with mid-assessment rather than before you start. Getting the self-assessment right the first time matters more now than it used to.

Why does the difference matter to your business?

If you’re bidding for contracts, especially with public sector clients, larger corporates, or anyone handling government data, Cyber Essentials Plus is increasingly the one being asked for by name. Some procurement processes will accept standard Cyber Essentials, but plenty won’t, particularly where the work involves sensitive data or connects into a client’s own systems.

Beyond procurement, Plus gives you something standard Cyber Essentials can’t: independent verification. If a client, insurer, or board member asks “how do you know your security controls actually work,” Plus is your answer. Standard Cyber Essentials tells people what you say you do. Plus confirms it.

What this means if you’re preparing now

Whichever level you’re going for, the practical starting point under Danzell is the same: go through every cloud service your business uses, including the ones that don’t feel like “IT systems,” like social media accounts, and confirm MFA is switched on for every user. Then check your patching process actually gets high-risk fixes applied within 14 days, and that you can evidence it.

If you’re not sure whether your current setup would pass, or you want a clearer picture of where Cyber Essentials or Cyber Essentials Plus would leave you exposed, that’s a conversation worth having before you start the assessment rather than partway through it.

Not sure where you stand?

Whether you’re aiming for Cyber Essentials or Cyber Essentials Plus, our team can walk you through what Danzell means for your setup and where the gaps might be, for free, before you commit to an assessment. Get in touch with Reformed IT to talk it through.

Felicity Price
Written by
Felicity Price
Marketing Coordinator, Reformed IT
See the team
Keep reading

Related from the team.

Related questions

Have a question this didn't answer?