Tick each item as you confirm it. Your progress bar updates as you go. Nothing is saved or sent, this is a working tool for you, not a form.
Every device that connects to the internet must sit behind a correctly configured firewall or equivalent.
Devices and software must be configured to reduce the attack surface, no defaults left in place.
Accounts must be controlled, least-privilege, and protected with MFA where available.
At least one malware defence must be active on in-scope devices.
Supported software only, patched fast, this is where most 2026 failures happen.
Since the Danzell question set went live on 27 April 2026, three requirements became automatic failures rather than observations. Multi-factor authentication must be on for every cloud service that offers it. Critical and high-risk patches must be applied within 14 days. And unsupported software anywhere in scope fails the assessment outright. Most organisations that fail do so on one of these three, not on anything exotic.
The checklist above is the working version of the official questions. For the full wording, download the Danzell question set. When you want a second pair of eyes before submitting, that is exactly what our readiness review does.