Published on 26 August 2026
If your Northamptonshire business holds Cyber Essentials, plans to certify this year, or relies on the badge to win contracts, the 2026 update matters more than any annual refresh in recent memory.
From 27 April 2026, every new Cyber Essentials assessment in the UK will be marked against the updated v3.3 Requirements for IT Infrastructure and a new question set called Danzell. For the first time, the scheme contains automatic-fail questions, where a single weak control can end the assessment on its own.
Cloud services can no longer be quietly excluded from scope. Critical patches must be installed within 14 days. And a board-level declaration commits your business to maintaining controls for the full 12 months, not just on the day you certify.
Cyber Essentials is a UK government-backed certification scheme designed by the National Cyber Security Centre (NCSC) and delivered by IASME. It is built around five technical controls that, together, block the majority of common cyber attacks faced by UK SMEs.
The five controls remain the same in v3.3:
What has changed is how strictly those controls are assessed. The Requirements for IT Infrastructure v3.3 document and the Danzell question set replace the previous v3.2 and Willow versions, and they apply to any assessment account created on or after 27 April 2026.
If you are renewing or certifying for the first time in Northamptonshire this year, you will be assessed against v3.3.
The official guidance from IASME and the NCSC describes the v3.3 updates as a clarification exercise rather than a rewrite. In practice, four changes will have the biggest impact on local businesses.
Multi-factor authentication (MFA) is now mandatory for every cloud service your business uses, wherever MFA is technically available. That includes Microsoft 365, your accounting platform, your CRM, your HR system, file storage, and any other SaaS tool that holds company data.
IASME has confirmed that failing to apply MFA where it is available is now an automatic-fail condition. “Available” includes free, included, and paid-for MFA options. You cannot avoid the requirement by claiming MFA is only on a higher-tier plan.
Two new auto-fail questions, A6.4 and A6.5, require that all high-risk or critical security updates be installed within 14 days of release. This applies to operating systems, router and firewall firmware, applications, browsers, extensions, and the configuration changes vendors release alongside patches.
A “high-risk or critical” update is any patch the vendor labels critical or high risk, or one with a CVSS v3 score of 7.0 or above. If a single in-scope device misses the 14-day window, the entire assessment fails.
For Cyber Essentials Plus, the audit process has been tightened with two-stage device sampling, specifically designed to catch the pattern of patching only the devices that an assessor is about to test.
Cloud scoping is no longer optional. The v3.3 requirements make it explicit: if your organisational data is processed or stored on a cloud service, that service must be in scope of the assessment. Cloud services cannot be excluded.
The NCSC has also tightened its definition of a cloud service. It now covers any on-demand, scalable platform hosted on shared infrastructure, accessed via an organisational account, and used to store or process business data. For most Northamptonshire SMEs, that means every SaaS tool is in daily use.
The default scope for Cyber Essentials v3.3 is now the whole organisation. Any exclusions, such as a separate trading entity or a development environment, must be justified and evidenced rather than waved through.
Alongside this, the signed declaration has been updated. A board member or director must now acknowledge responsibility for maintaining the controls throughout the 12-month certification period, not just on the day the certificate is issued.
For local SMEs working with the public sector, the MOD supply chain, healthcare partners, or legal clients, Cyber Essentials is increasingly a tender prerequisite. Losing the badge during a renewal cycle can quietly close doors that are difficult to reopen, and the cost of failing an assessment is rarely just the resubmission fee.
It is the lost time, the contract review delays, and the conversations with clients about why your certification has lapsed.
The v3.3 changes do not introduce new technical concepts. They remove the wriggle room that some businesses had relied on. If your patching process is informal, if MFA is missing on one cloud platform, or if you are unsure which services hold your data, those gaps will now cause a failure rather than a follow-up question.
The businesses that pass v3.3 first time will be the ones with a clear cloud inventory, a documented patching process, MFA enforced everywhere available, and an honest, organisation-wide scope.
A few practical steps will put your business in a strong position before your next assessment.
We work with businesses across Northampton, Milton Keynes, Bedfordshire, Buckinghamshire, and the wider Northamptonshire region, helping them prepare for and pass Cyber Essentials and Cyber Essentials Plus.
Our Cyber Essentials service includes:
If you also rely on us for managed IT services, cloud services, or IT consultancy, your Cyber Essentials readiness is maintained continuously rather than rebuilt every renewal.
Get Certified with Bluebell IT Solutions
Cyber Essentials v3.3 applies to all assessment accounts created on or after 27 April 2026. Active assessments started before that date continue under v3.2 and the Willow question set, with up to six months to complete.
Yes. Under v3.3, MFA must be enabled on every cloud service where it is available, including services where MFA is only offered as a paid option. Missing MFA on any in-scope cloud service is an automatic fail.
Any update the vendor describes as critical or high risk, or one with a CVSS v3 base score of 7.0 or above. If severity is not disclosed, treat the update as high risk and apply within 14 days.
Certification fees are set by IASME and are based on organisation size, not the requirements version. Internal costs may rise if you need to invest in MFA rollouts, patch management tools, or upgrades from end-of-life software.
If your renewal is approaching, or you are certifying for the first time, the right preparation now will save weeks of work later. Speak to our team about a v3.3 readiness review tailored to your business.
Call us today on 01908 044202 or fill in our enquiry form to find out how Bluebell can help your Northamptonshire business pass Cyber Essentials v3.3 first time.
© 2026 Bluebell IT Solutions - All rights reserved
SEO and Website Design by Loop Digital