March 25, 2026

Cyber Essentials

Cyber Essentials renewal 2026: what changes under v3.3. Should you renew early?

Cyber Essentials renewal 2026: what changes under v3.3 and whether to certify before the April deadline

Cyber Essentials v3.3 comes into force on 27 April 2026, bringing the most significant technical changes in several years and introducing a new auto-fail rule for Multi-Factor Authentication that will catch organisations by surprise if they are not prepared.

This article explains what changes at renewal under v3.3, who is affected and when, and whether renewing before the 27 April deadline makes sense for your organisation.

What happens to my Cyber Essentials certificate at renewal?

Your Cyber Essentials certificate is valid for 12 months from the date it was issued. At renewal, you go through the assessment process again: either the self-assessment questionnaire for Basic, and/or the full technical audit for Plus.

What changes in 2026 is which version of the requirements your renewal is assessed against. That depends entirely on one date: 27 April 2026.

  • If your assessment account is created before 27 April, your renewal will be assessed against the current v3.2 Willow (v3.2) requirements, regardless of when you finish the assessment.
  • If your assessment account is created on or after 27 April, your renewal will be assessed against the new v3.3 Danzell (v3.3) requirements.

The date your account is created is the determining factor, not the date you submit or receive your certificate.

What actually changes under v3.3 at renewal?

If your renewal falls under v3.3, three changes are most likely to affect you.

1) Multi-Factor Authentication is now an automatic fail

Under v3.3, if any cloud service in scope offers Multi-Factor Authentication (MFA) and you have not enabled it for all users, your assessment fails immediately. There is no opportunity to remediate within the assessment cycle.

2) Cloud services can no longer be excluded from scope

V3.3 formally defines cloud services and makes clear that any cloud tool used to store or process business data is in scope for your assessment. If your organisation has historically excluded cloud tools from its certification scope, that approach is no longer valid at renewal.

3) The question set is different

V3.3 introduces a new self-assessment questionnaire called Danzell (v3.3), replacing the current Willow (v3.2) set. Expect more granular questions around your cloud service inventory, MFA implementation and patching evidence.

“The gap we’re finding most often isn’t that organisations don’t have Multi-Factor Authentication. The issue is that organisations have enabled it for standard accounts but missed service accounts, shared mailboxes, or legacy integrations. Under v3.3, any of those would be an automatic fail.”

Jonathan Krause, Founder and Head Assessor, Forensic Control

For a full breakdown of every v3.3 change, see our Cyber Essentials v3.3 April 2026 update

Should I renew before 27 April?

For some organisations, renewing before the deadline is the right call. For others, it makes no practical difference. The decision comes down to one question: are you currently MFA-compliant across all cloud services?

Renew before 27 April if:

  • You have cloud services where MFA is available but not yet fully enforced across all users
  • You know your IT setup needs work before it would pass the new scoping or patching requirements
  • You want 12 months to implement the v3.3 changes properly rather than under assessment pressure

Your renewal timing makes no practical difference if:

  • MFA is already fully enforced across every cloud service in scope
  • Your cloud services are already properly mapped and documented
  • You have a documented, auditable patching process in place

Contact us today to start your renewal before 27 April

Does the renewal cost change under v3.3?

No. Forensic Control’s Cyber Essentials renewal pricing is unchanged:

Cyber Essentials BasicFrom £450 per year
Cyber Essentials PlusFrom £1,350 per year, includes 12 months vulnerability scanning at no extra cost
Cyber Essentials DuoFrom £1,800 per year (Basic + Plus bundle)

V3.3 does not affect certification fees.

What do I need to do before my renewal under v3.3?

In addition to your standard preparation for certification (ensuring all applications and operating systems are running latest updates, checking that your answers from last year are still applicable, etc.) there are some additional areas you need to review. If your renewal falls after 27 April, the following preparation can make the difference between a smooth renewal and a failed assessment.

Audit your cloud services

Map every cloud tool your team accesses with business credentials. For each one, confirm whether MFA is available and whether it is enabled for every user without exception. This is the single most important preparation step.

Check your patching process

V3.3 broadens what counts as a vulnerability fix. Registry edits, configuration changes and scripts now count alongside software patches. If your patching process is informal or undocumented, you will need an auditable record before your Plus assessment.

Review your scope

If your previous certification excluded any cloud services, review that decision. Under v3.3, exclusions require documented justification and technical segregation evidence.

Check your administrator accounts

Beyond MFA, administrator accounts are among the most common areas of non-compliance we see at assessment. The question is not just whether you have them, but how they are allocated and how they are actually used day to day.

“Beyond MFA, the most consistent area of non-compliance we see at assessment is around administrator accounts: specifically how they’re allocated and how they’re actually used day to day. We’re surprised how many applicants tell us they don’t have any administrator accounts because these are handled by their IT supplier. Every administrator account, whether used by internal staff or external suppliers, needs to be addressed by the administrator questions at A7.x in Cyber Essentials.”

Jonathan Krause, Founder and Head Assessor, Forensic Control

‘For Cyber Essentials Plus & Duo clients: Forensic Control’s included vulnerability scanning service provides continuous monitoring and a documented fix timeline. That is exactly the evidence trail v3.3 assessors will look for. Most CE Plus providers charge separately for this, or do not offer it at all.’

Passwordless authentication: what’s coming next

V3.3 signals a clear direction toward passwordless authentication. Passkeys and FIDO2 hardware keys are now explicitly encouraged within the scheme, though not yet required.

If you are making authentication infrastructure decisions now, it is worth building toward FIDO2-compatible systems rather than older MFA methods such as SMS codes, which may face tighter scrutiny in future updates.

Contact us today to start your renewal before 27 April

Frequently asked questions about Cyber Essentials renewal


Will I fail my CE renewal if I don’t have MFA enabled?

Yes, if your renewal falls under v3.3. If a cloud service offers MFA and you have not enabled it for all users, your assessment fails automatically with no opportunity to remediate within that cycle. This applies to every cloud service in scope, including Microsoft 365, Google Workspace, Salesforce and similar tools.

When does my Cyber Essentials renewal change under v3.3?

Your renewal changes if your assessment account is created on or after 27 April 2026. Accounts created before that date are assessed under v3.2 Willow requirements, even if the assessment is completed after the deadline. The creation date of your account determines which version applies.

How much does Cyber Essentials renewal cost in 2026?

Renewal pricing is unchanged under v3.3. Cyber Essentials Basic renews from £450 per year, Cyber Essentials Plus from £1,350 per year including 12 months of vulnerability scanning, and Cyber Essentials Duo from £1,800 per year. Forensic Control does not charge for resubmissions.

What is the Danzell questionnaire?

Danzell is the new self-assessment questionnaire that replaces the Willow set from 27 April 2026. It reflects the v3.3 requirement changes, with more detailed questions around cloud services, MFA and patching evidence. If you have completed Willow previously, expect Danzell to be more granular in these areas.

Can I still renew Cyber Essentials if I fail the v3.3 assessment?

Yes. If your assessment fails under v3.3, you address the non-conformities and resubmit. Forensic Control does not charge for resubmissions and our assessors will guide you through any gaps at no additional cost. MFA failures are typically straightforward to resolve once the affected services are identified.

How do I know if my organisation is ready for renewal under v3.3?

The clearest indicator is whether MFA is fully enforced across every cloud service in scope. Use our free Cyber Essentials Quick Check Tool to identify gaps before your renewal assessment, or contact our team for a pre-renewal conversation.

Ready to take control of your cyber security?

Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.