Cyber Essentials Updates Explained: What Was the Standard Before (Willow) vs. What Is the Standard Now (Danzell)?

If your organisation is preparing for Cyber Essentials or Cyber Essentials Plus certification, the compliance baseline has evolved. On 27 April 2026, the National Cyber Security Centre (NCSC) and IASME officially retired the previous ‘Willow’ standards and launched Version 3.3, known as the ‘Danzell’ question set.
While the fundamental five technical controls remain the same, Danzell introduces hard ‘auto-fail’ conditions that catch businesses unprepared.
Here is a side-by-side breakdown of what the Cyber Essentials standard was before (Willow) versus what the standard is now (Danzell).
What Was the Standard Before? (Version 3.2 – ‘Willow’)
The Willow question set (v3.2) governed Cyber Essentials prior to this update. It focused on establishing clear rules for hybrid working, defining passwordless login mechanisms, and broadening the scope of cloud services.
Key Characteristics of Version 3.2 (Willow):
- Cloud & MFA Focus: Strong encouragement and requirements for MFA on cloud services, with some allowance for assessor discretion during edge-case reviews.
- Remote Working Parameters: Explicit definitions protecting fixed home offices as well as hybrid worker endpoints.
- 14-Day Vulnerability Fixes: Required High and Critical vulnerabilities (CVSS 7.0+) across OS and desktop applications to be patched within 14 days.
- Passwordless Authentication: Formally permitted biometrics, passkeys, and FIDO2 security tokens as valid substitutes for traditional password combinations.
What Is the Standard Now? (Version 3.3 – ‘Danzell’)
Version 3.3 (‘Danzell’) is the active assessment standard for all new certification accounts. Danzell eliminates gray areas by establishing strict, binary pass/fail questions.

Key Changes Introduced in Danzell (v3.3):
1. Mandatory MFA Across ALL Cloud Services (Hard Auto-Fail)
• Before (Willow): MFA was expected, but minor gaps or unenforced cloud apps could sometimes be justified or remediated under advisory conditions.
• Now (Danzell): MFA is mandatory for all user accounts accessing cloud services, SaaS platforms, and company data. If a cloud tool supports MFA and it is not enforced across 100% of users, your assessment automatically fails.
2. Strict 14-Day Patching Questions (Hard Auto-Fail)
• Before (Willow): Patch management was reviewed holistically as part of general software update policies.
• Now (Danzell): Danzell introduces dedicated, binary auto-fail questions regarding updates. If any high-risk or critical security updates for operating systems, application extensions, or firewall/router firmware exceed 14 days, it triggers an automatic failure.
3. Network Infrastructure & Firmware Brought into Equal Scope
• Before (Willow): Firewalls and routers were assessed primarily through configuration rules.
• Now (Danzell): Router and firewall operating systems and firmware updates are explicitly held to the exact same strict 14-day patching rule as desktop OS and server software.
4. Expanded Cloud & Social Media Boundaries
• Before (Willow): Cloud service scoping occasionally left room to exclude secondary third-party web apps.
• Now (Danzell): Any SaaS platform holding organizational data—including company-owned social media accounts and third-party web tools—is explicitly locked into scope and cannot be excluded.

Summary Comparison: Willow vs. Danzell
| Requirement Area | Old Standard (v3.2 – Willow) | Current Standard (v3.3 – Danzell) |
|---|---|---|
| Active Question Set | Willow | Danzell (v3.3) |
| MFA Enforcement | Required for cloud/admin logins; reviewed with assessor context | Mandatory on ALL cloud logins. Missing MFA = Instant Auto-Fail |
| Patch Management | 14-day window reviewed holistically | Dedicated Auto-Fail questions for OS, apps, extensions & firmware > 14 days |
| Network Infrastructure | Router & firewall boundaries | Firmware patches for firewalls/routers explicitly bound to 14-day rule |
How NetManageIT Helps You Pass Danzell First Time
Because Danzell introduces hard automatic fail conditions, attempting a self-assessment without pre-auditing your cloud estate or patching logs can lead to wasted certification fees.
At NetManageIT, we protect your business from Danzell auto-fails by:
- Auditing MFA Policy Enforcement: Verifying that Conditional Access rules in Microsoft 365 / Google Workspace actually enforce MFA rather than leaving it optional.
- Running Pre-Assessment Scans: Uncovering missing 14-day patches, registry workarounds, or firmware updates before your official SAQ submission.
- Boundary Scoping: Mapping out all remote devices, SaaS apps, and endpoints so your submission passes without friction.
Preparing for certification or renewal under Danzell?
Get in touch with NetManageIT today to speak with a Cyber Essentials consultant.