Danzell assessments are marked against v3.3 with less discretion than earlier years. Two conditions fail a submission outright regardless of everything else: multi-factor authentication missing on any in-scope cloud service where the service supports it, and security update management outside the rules, unsupported software in scope, or high/critical updates unapplied beyond 14 days. Clear those two first; nothing else matters until they're clean.
Beyond the auto-fails, assessors mark for accuracy and internal consistency. An asset list of 12 laptops alongside an answer describing 30 users invites questions; “we plan to enable” anything is a fail for that control, the scheme assesses the present tense. Write every answer as a description of today, verified by someone who can see the admin consoles, not as an aspiration.
None of this evidence is submitted with the basic assessment, but gathering it forces the honesty the marking rewards, and it becomes your CE+ pack, insurance evidence and next year’s renewal baseline for free.
Failed first attempts cluster around the same patterns: scope drawn optimistically (the director's home laptop “doesn't really count”), cloud service lists built from memory instead of billing records and SSO logs, answers written by someone who can't see the actual configurations, and the declaration signer discovering their responsibilities the morning of submission.
The fix is sequencing. Scope before inventory, inventory before remediation, remediation before answers, review before submission. Teams that jump straight to the questionnaire, the natural instinct, end up rewriting it twice as the real scope emerges underneath them.
Preparation done in the right order is boring, and boring is exactly what you want an assessment to be.
Work top to bottom. Each step produces the input the next one needs.
Register your interest and we’ll review your readiness against every auto-fail condition, and contact you the day our certification service launches.