Cyber Essentials is a verified self-assessment: your organisation answers the Danzell question set covering the five technical controls, a board member or equivalent signs the declaration, and a licensed assessor reviews and verifies the responses. It is deliberately scoped at the fundamentals, the controls that stop the commodity attacks responsible for the majority of breaches affecting UK SMEs.
The 2026 update raised the bar considerably. Multi-factor authentication is now mandatory on all cloud services where it is available, and failing to apply high or critical security updates within 14 days is now an automatic failure rather than a discretionary mark-down. Scope definitions were also tightened, so remote workers, BYOD devices used for work data, and cloud services can no longer be quietly excluded.
For most UK SMEs, Cyber Essentials is the fastest and cheapest way to turn good security hygiene into a credential that procurement teams and insurers actually recognise.
Pass rates have tightened since the Danzell question set introduced automatic failure conditions. Most failures are avoidable, they come from misunderstanding scope or answering aspirationally rather than accurately. An assessor cannot pass an answer that describes what you intend to do; only what is true on the day you submit.
Because our team audits infrastructure for a living, we review your draft answers the way an assessor will read them, and tell you exactly what to fix before you submit, not after a failed attempt.
Every failed submission costs time, and under the 2026 marking rules, some gaps mean an outright fail rather than a chance to clarify. Preparation is where certification is won.
Every Cyber Essentials requirement hangs off these five technical controls. They are unchanged in the 2026 update, what changed is how strictly two of them are marked.
Register your interest today. We’ll review your readiness against the Danzell (v3.3) requirements and contact you the day our certification service goes live.