Cyber Essentials v3.3 Explained for Northamptonshire Businesses

Cyber Essentials v3.3 Explained: What Northamptonshire Businesses Need to Do in 2026

Published on 26 August 2026

If your Northamptonshire business holds Cyber Essentials, plans to certify this year, or relies on the badge to win contracts, the 2026 update matters more than any annual refresh in recent memory.

From 27 April 2026, every new Cyber Essentials assessment in the UK will be marked against the updated v3.3 Requirements for IT Infrastructure and a new question set called Danzell. For the first time, the scheme contains automatic-fail questions, where a single weak control can end the assessment on its own. 

Cloud services can no longer be quietly excluded from scope. Critical patches must be installed within 14 days. And a board-level declaration commits your business to maintaining controls for the full 12 months, not just on the day you certify.

What is Cyber Essentials v3.3?

Cyber Essentials is a UK government-backed certification scheme designed by the National Cyber Security Centre (NCSC) and delivered by IASME. It is built around five technical controls that, together, block the majority of common cyber attacks faced by UK SMEs.

The five controls remain the same in v3.3:

  • Firewalls
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

What has changed is how strictly those controls are assessed. The Requirements for IT Infrastructure v3.3 document and the Danzell question set replace the previous v3.2 and Willow versions, and they apply to any assessment account created on or after 27 April 2026.

If you are renewing or certifying for the first time in Northamptonshire this year, you will be assessed against v3.3.

The Key Cyber Essentials Changes in 2026

The official guidance from IASME and the NCSC describes the v3.3 updates as a clarification exercise rather than a rewrite. In practice, four changes will have the biggest impact on local businesses.

1. Mandatory MFA Across All Cloud Services

Multi-factor authentication (MFA) is now mandatory for every cloud service your business uses, wherever MFA is technically available. That includes Microsoft 365, your accounting platform, your CRM, your HR system, file storage, and any other SaaS tool that holds company data.

IASME has confirmed that failing to apply MFA where it is available is now an automatic-fail condition. “Available” includes free, included, and paid-for MFA options. You cannot avoid the requirement by claiming MFA is only on a higher-tier plan.

2. The 14-Day Critical Patching Rule Is Now Auto-Fail

Two new auto-fail questions, A6.4 and A6.5, require that all high-risk or critical security updates be installed within 14 days of release. This applies to operating systems, router and firewall firmware, applications, browsers, extensions, and the configuration changes vendors release alongside patches.

A “high-risk or critical” update is any patch the vendor labels critical or high risk, or one with a CVSS v3 score of 7.0 or above. If a single in-scope device misses the 14-day window, the entire assessment fails.

For Cyber Essentials Plus, the audit process has been tightened with two-stage device sampling, specifically designed to catch the pattern of patching only the devices that an assessor is about to test.

3. Cloud Services Are Fully in Scope

Cloud scoping is no longer optional. The v3.3 requirements make it explicit: if your organisational data is processed or stored on a cloud service, that service must be in scope of the assessment. Cloud services cannot be excluded.

The NCSC has also tightened its definition of a cloud service. It now covers any on-demand, scalable platform hosted on shared infrastructure, accessed via an organisational account, and used to store or process business data. For most Northamptonshire SMEs, that means every SaaS tool is in daily use.

4. Stricter Scoping and a Director-Level Declaration

The default scope for Cyber Essentials v3.3 is now the whole organisation. Any exclusions, such as a separate trading entity or a development environment, must be justified and evidenced rather than waved through.

Alongside this, the signed declaration has been updated. A board member or director must now acknowledge responsibility for maintaining the controls throughout the 12-month certification period, not just on the day the certificate is issued.

What This Means for Northamptonshire Businesses

For local SMEs working with the public sector, the MOD supply chain, healthcare partners, or legal clients, Cyber Essentials is increasingly a tender prerequisite. Losing the badge during a renewal cycle can quietly close doors that are difficult to reopen, and the cost of failing an assessment is rarely just the resubmission fee.

It is the lost time, the contract review delays, and the conversations with clients about why your certification has lapsed.

The v3.3 changes do not introduce new technical concepts. They remove the wriggle room that some businesses had relied on. If your patching process is informal, if MFA is missing on one cloud platform, or if you are unsure which services hold your data, those gaps will now cause a failure rather than a follow-up question.

The businesses that pass v3.3 first time will be the ones with a clear cloud inventory, a documented patching process, MFA enforced everywhere available, and an honest, organisation-wide scope.

How to Prepare for Cyber Essentials v3.3

A few practical steps will put your business in a strong position before your next assessment.

  • Build a cloud service inventory: List every cloud platform that holds or processes company data. Confirm MFA is enabled for every user account on every service.
  • Audit your patching: Check that you can evidence high-risk and critical patches being applied within 14 days across operating systems, firmware, and applications. If updates rely on individual users clicking “install later,” that process will not survive a v3.3 assessment.
  • Confirm supported software: Anything past the end of life, including Windows 10 without Extended Security Updates, will fail at A6.3. Replace or upgrade unsupported systems before you start the assessment.
  • Review your scope: Document every in-scope device, including home worker laptops, BYOD endpoints, and remote machines. Whole-organisation scope is the default.
  • Get director-level sign-off: Make sure the person signing the declaration understands the 12-month commitment to maintain controls.

How Bluebell IT Solutions Helps Local Businesses Get Certified

We work with businesses across Northampton, Milton Keynes, Bedfordshire, Buckinghamshire, and the wider Northamptonshire region, helping them prepare for and pass Cyber Essentials and Cyber Essentials Plus.

Our Cyber Essentials service includes:

  • Gap analysis against the v3.3 Danzell question set
  • Centralised patch management aligned with the 14-day rule
  • MFA rollout across Microsoft 365, Azure, and your wider SaaS estate
  • Scope documentation and evidence gathering
  • Support through the assessment portal and assessor questions

If you also rely on us for managed IT services, cloud services, or IT consultancy, your Cyber Essentials readiness is maintained continuously rather than rebuilt every renewal.

Get Certified with Bluebell IT Solutions

Frequently Asked Questions on Cyber Essentials v3.3

When does Cyber Essentials v3.3 take effect?

Cyber Essentials v3.3 applies to all assessment accounts created on or after 27 April 2026. Active assessments started before that date continue under v3.2 and the Willow question set, with up to six months to complete.

Is MFA really mandatory for every cloud service?

Yes. Under v3.3, MFA must be enabled on every cloud service where it is available, including services where MFA is only offered as a paid option. Missing MFA on any in-scope cloud service is an automatic fail.

What counts as a critical security update for the 14-day rule?

Any update the vendor describes as critical or high risk, or one with a CVSS v3 base score of 7.0 or above. If severity is not disclosed, treat the update as high risk and apply within 14 days.

Does Cyber Essentials v3.3 cost more than v3.2?

Certification fees are set by IASME and are based on organisation size, not the requirements version. Internal costs may rise if you need to invest in MFA rollouts, patch management tools, or upgrades from end-of-life software.

Talk to Bluebell IT Solutions About Cyber Essentials

If your renewal is approaching, or you are certifying for the first time, the right preparation now will save weeks of work later. Speak to our team about a v3.3 readiness review tailored to your business.

Call us today on 01908 044202 or fill in our enquiry form to find out how Bluebell can help your Northamptonshire business pass Cyber Essentials v3.3 first time.

Cyber Security shield

Contact us!


Recent Posts

Our Resources

Our Accreditations