Two things move every year: the scheme and your organisation. On the scheme side, the April 2026 update was the most consequential in years, MFA on every cloud service where available became an automatic failure, security update timescales gained auto-fail enforcement, cloud service definitions widened, and scoping language around remote workers and BYOD tightened. Answers copied from last year's spreadsheet may now describe a failing configuration.
On your side, twelve months of business change accumulates: new SaaS subscriptions nobody added to the asset list, staff turnover leaving stale accounts, devices bought outside procurement, an office move or acquisition. Renewal is the annual moment those drifts get caught, which is precisely why buyers value a current certificate over an old one.
Treat renewal as a health check with a certificate attached, the organisations that do find it cheaper and faster every year, because drift never accumulates.
Because certification is annual, a lapse is visible: your organisation disappears from the NCSC's certified-organisations register, and any contract clause requiring you to “maintain” Cyber Essentials is technically in breach from expiry day. Re-certifying after a lapse is a full assessment either way, so delaying saves nothing and risks plenty.
The pattern we see repeatedly: certification was one person's project, that person left, the reminder email went to a dead mailbox, and the first anyone hears of it is a procurement portal rejecting a bid. A renewal process, not a calendar entry, is the fix.
Every one of these is preventable with a 90-day runway and a current-rules review. That is exactly the service we’re building.
If your current certificate was assessed under Willow (v3.2), these are the differences your renewal will be marked against.
| Area | Under Willow (your last pass) | Under Danzell v3.3 (your renewal) |
|---|---|---|
| MFA on cloud services | Required, with assessor discretion on gaps | Automatic failure if MFA is not enabled on any in-scope cloud service where available |
| Security updates | 14-day expectation, marked with discretion | Automatic failure for unsupported software in scope or high/critical updates older than 14 days |
| Cloud service definition | Narrower; ‘peripheral’ services often excluded | Formal, broad definition, includes the full SaaS toolchain and business social media accounts |
| Shared logins | Discouraged | Individual accounts expected wherever the service supports them, including social platforms |
| Remote workers & BYOD | In scope, with looser wording | Tightened scoping language; personal devices touching work data are unambiguously in |
| CE Plus sampling | Standard sampling | Revised sampling approach designed to catch selective, assessment-week-only patching |
Summary based on the published v3.3 requirements and IASME guidance as of July 2026. Legacy Willow assessment accounts must be finalised by late October 2026, check the exact deadline shown in your assessment account.
Register your interest and tell us your current certificate’s expiry date. We’ll build your renewal runway against the 2026 rules and contact you when our service launches.