Plain English Guide to the April 2026 Cyber Essentials Changes
The Danzell question set and v3.3 requirements took effect on 27 April 2026. This guide answers the exact questions IT managers and MSPs are asking about MFA auto-fails, cloud service scope, free accounts, and what assessors actually check.

Section 01
Plain English Guide to the April 2026 Cyber Essentials Changes
Cyber Essentials v3.3 took effect for assessment accounts created from 27 April 2026. It makes missing MFA on an in-scope cloud service an automatic fail, makes two critical update questions automatic fails, and adds clearer cloud-service and assessment-scope rules. Existing assessment accounts created earlier retain a six-month completion window under the previous requirements.
The NCSC updated the Cyber Essentials requirements to version 3.3 on 27 April 2026. The assessment uses the Danzell question set and introduces changes that have caused genuine confusion among IT managers, MSPs, and business owners preparing for certification.
This guide answers the specific questions people are actually asking and the issues that come up most often during Cyber Essentials preparation. It is grounded in the NCSC requirements v3.3, IASME's April 2026 update, and the current Danzell question-set preview.
Section 02
What actually changed on 27 April 2026?
Three things changed:
1. MFA marking became stricter. MFA must be used wherever it is available and cloud-service authentication must always use MFA. Failing to implement available MFA on an in-scope cloud service is now an automatic fail.
2. Critical update marking became stricter. Required vulnerability fixes must be applied within 14 days of release. Triggers include vendor high/critical ratings, CVSS v3 base score 7 or above, and absent vendor severity details. Vendor-approved fixes can include patches or prescribed configuration/workaround changes; generic business mitigation is not a waiver.
3. Scope and certificates became clearer. Applicants must describe exclusions and legal entities more precisely, while the requirements add a specific cloud-service definition and remove ambiguity from some network-scope language.
The five control categories have not changed. Firewalls, secure configuration, security update management, user access control, and malware protection still form the core of the assessment.
Section 03
Do I automatically fail if I don't have MFA on my free Mailchimp account?
This is the single most common question I get asked, and the answer requires some nuance.
If the account is used for organisational purposes and handles organisational data, it is in scope. A free Mailchimp account that sends your company newsletter contains customer email addresses. That is organisational data. The account is in scope and needs MFA.
However, the question is really about what counts as an "organisational cloud service" under the new definitions. The test is straightforward: does the service store, process, or provide access to any data belonging to your organisation or your customers? If yes, it is in scope regardless of whether the service is free or paid.
Practical examples:
Mailchimp (free tier) for company newsletters
In scope. Contains customer email addresses - that is organisational data. Needs MFA.
Canva (free) for marketing materials
In scope if you store company assets there. Needs MFA.
Personal Gmail with forwarded work email
If it is used to store or process organisational email, assess the actual business use: a personal label or absence of a policy directing forwarding does not automatically exclude it. Stop unauthorised forwarding and remove organisational data, or apply the relevant cloud-service controls.
Trello (free) for team projects
In scope. Contains organisational project data. Needs MFA.
The auto-fail: If an in-scope cloud service does not have MFA enabled on all user accounts, the submission will fail. There is no partial credit. The assessor cannot exercise discretion on this point - it is a binary pass/fail control under v3.3.
What to do: Audit every cloud service your organisation uses. If it holds any organisational data, enable MFA. If the service does not support MFA at all, you need to either find an alternative that does, or demonstrate that the service genuinely holds no organisational data and is therefore out of scope.
Section 04
What is the new definition of "cloud services" in the Danzell question set?
The previous question set was ambiguous about what qualified as a cloud service. The Danzell set is more explicit.
Under v3.3, a cloud service is an on-demand, scalable service hosted on shared infrastructure, accessed via the internet through an account, and used to store or process organisational data. This includes:
- SaaS platforms: Microsoft 365, Google Workspace, Salesforce, HubSpot, Xero, QuickBooks Online, Slack, Teams, Zoom
- Cloud storage: OneDrive, Google Drive, Dropbox, SharePoint Online, iCloud (if used for work)
- Web-based email: Outlook.com, Gmail (organisational), any webmail
- Line-of-business applications hosted externally: CRM systems, project management tools, HR platforms, accounting software
- Infrastructure services: AWS, Azure, and Google Cloud Platform, including the administrative accounts and the customer-managed components that fall inside your assessment scope
What is NOT a cloud service under this definition:
- Websites you visit but do not log into
- Services where you have no account and store no data
- Consumer services used purely personally with no organisational data (your personal Netflix account)
The key test remains: does your organisation store or access its own data through this service? If yes, it is a cloud service in scope for Cyber Essentials, and all user accounts need MFA.
Section 05
Does the MFA auto-fail apply to admin accounts only?
No. For an in-scope cloud service, the MFA requirement applies to the accounts authenticating to that service, not only its administrators. The wider requirements also say to implement MFA wherever it is available.
In practice:
- Every Microsoft 365 user needs MFA, not just Global Admins
- Every Google Workspace user needs MFA, not just Super Admins
- Every user of your CRM, project management tool, or cloud accounting software needs MFA
The auto-fail specifically: if an in-scope cloud service makes MFA available but the organisation has not implemented it, the assessment fails. Avoid extending that statement into an invented blanket rule for accounts or systems that are not cloud services; assess those against the exact v3.3 wording.
For organisations with Conditional Access policies (Azure AD / Entra ID), see the next section.
Section 06
Is Conditional Access enough for Cyber Essentials MFA?
Yes, if it is configured correctly. This is one of the most misunderstood areas.
Conditional Access in Microsoft Entra ID can satisfy the Cyber Essentials MFA requirement, but only if the resulting control actually meets the requirement for the in-scope cloud services. Common mistakes include untested exclusions or policies that are merely available rather than enforced.
A straightforward policy:
- "Require MFA for all users and all in-scope cloud apps" provides a clear baseline, subject to correctly controlled and documented technical accounts.
Policies that need careful review:
- MFA only for administrators leaves ordinary users of the cloud service uncovered.
- Location or device exclusions can create a route that does not use MFA.
- Risk-based policies may allow some authentication without MFA.
What to prepare: describe the policy, identify exclusions, and test representative sign-ins. Your certification body decides whether the actual implementation meets the scheme requirements; a policy name by itself is not evidence.
Practical recommendation: keep the policy as broad and simple as the environment permits, and discuss unavoidable technical exceptions with the certification body before submission.
Section 07
Can I put a legacy server on a separate VLAN to exclude it from scope?
A well-defined and separately managed subset can be segregated by a firewall or VLAN, with scope agreed before assessment. IASME's subset guidance permits controlled communication across an ordinary boundary; it does not universally demand zero cross-network traffic or separate identities and locks.
Unsupported software is different. The NCSC update requirements, page 17, require its removal from devices or exclusion through a defined subset preventing all traffic to or from the internet. A different subnet, a jump host or generic risk acceptance is not proof that this stricter condition is met.
Describe and verify the actual boundary and discuss it with your certification body.
Section 08
How do I define scope for 100% remote workers with no office firewall?
This is increasingly common and the v3.3 requirements handle it clearly.
If your organisation has no physical office and all employees work remotely, the scope is:
- Every device used to access organisational data (laptops, phones, tablets)
- All cloud services used by the organisation (M365, Google Workspace, business SaaS, IaaS, PaaS)
- All user accounts
The home router question: Under v3.3 (Danzell A2.5), normal home routers used by remote workers are explicitly out of scope. The relevant Danzell wording is: "Details of routers and firewalls in the home environment must not be included." The boundary instead follows the device that touches organisational data, and the device's software firewall handles enforcement against the home network.
What this means in practice:
1. The work laptop's software firewall (Windows Firewall, macOS firewall, or Linux iptables/nftables) must be enabled, default-deny on inbound, and configured so a standard user cannot disable it.
2. Reliance on the software firewall must be noted in the A2.5 network-equipment field of the questionnaire. The wording does not need to be elaborate; "Home and remote workers rely on the device's software firewall as the boundary; no home routers in scope" is enough.
3. Where the organisation supplies and manages a router for a home worker (i.e., issues the router as corporate kit rather than relying on the worker's own home router), that router IS corporate equipment and is in scope.
What you do NOT need:
- You do not need to audit employees' home routers
- You do not need to mandate anything about their home ISP or router
- You do not need to enrol home routers in any inventory or management system
Section 09
Do BYOD phones count if they only check email via Outlook Web Access?
Yes. Access to organisational data or services matters, even through a browser with no local storage. A personal phone using Outlook Web Access is an end-user device in scope, as is a phone syncing work email through an app.
The NCSC excludes mobile/remote devices used only for native voice, native text or MFA apps. That exemption does not extend to browser-only email or virtual-desktop access.
Apply and evidence the relevant device controls. MDM can help, but is not compulsory; enrolment itself is not the definition of scope. If you restrict work to corporate devices, verify that actual use matches the restriction.
Section 10
What are the most common Cyber Essentials v3.3 failures?
Across Cyber Essentials assessments, these are the issues that commonly cause failures under v3.3:
MFA not on all cloud accounts
Usually it is enabled for administrators but not standard users of the same cloud service. Under v3.3, leaving available MFA unimplemented on an in-scope cloud service is an automatic fail.
Unsupported operating systems
Windows 10 reaches end of support in October 2025. Organisations still running Windows 10 in April 2026 without Extended Security Updates (ESU) should expect this to fail. Out-of-support OS is a categorical fail under v3.3.
Patches not applied within 14 days
The 14-day clock starts from the date the vendor publishes the patch, not when your scanner finds it. Many organisations are patching monthly - that's outside the v3.3 window.
Default admin passwords on network devices
An in-scope office or organisation-supplied router still using factory credentials is a configuration gap. Ordinary privately owned home routers are excluded; apply the relevant controls to in-scope switches, access points and managed network devices.
No documented scope
The Danzell question set asks you to define and document your scope. "Everything" is not an acceptable answer. You need to list your in-scope devices, users, and network boundaries.
Section 11
How Fig Group can help
Fig Group is an IASME-licensed Cyber Essentials certification body. The service is built around the v3.3 requirements and the Danzell question set, with structured feedback when a submission needs correction.
If you are unsure whether your organisation is ready for certification under the new requirements, use our free readiness checker to assess your position across all five controls before purchasing your certification.
Cyber Essentials certification from £299.99 + VAT. Guaranteed within 6 working hours for complete compliant submissions received before midday on a UK business day. Three free rounds of assessment feedback are included if your submission needs corrections.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials Firewall Requirements: What Assessors Actually Check
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, what v3.3 (Danzell) actually says about home routers for remote workers, default credentials, and the cloud firewall configuration assessors expect in 2026.
Read articleTechnical Guides
Secure Configuration for Cyber Essentials: The Controls Assessors Expect to See
Secure configuration is the control area with the broadest scope and the most room for getting details wrong. This guide covers default passwords, auto-run, unnecessary software, cloud service configuration, and the specific settings assessors check against v3.3 (effective 27 April 2026).
Read articleTechnical Guides
Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.
Read article

