Cyber Essentials vs Cyber Essentials Plus in 2026 and What the New Changes Mean for UK Businesses

by | Sep 10, 2026

Cyber Essentials has long been the UK’s baseline cyber‑security standard – a practical, government‑backed way for organisations to demonstrate they have essential protections in place. But in April 2026, the scheme underwent one of its most significant updates since launch. The introduction of the Danzell question set has tightened requirements, removed assessor discretion, and made accuracy in your Cyber Essentials (CE) answers more important than ever.

For many organisations, this has raised a new question: is Cyber Essentials still enough, or is Cyber Essentials Plus (CE+) now the safer, more reliable option? And more importantly – what happens if you make mistakes under the new rules?

This blog breaks down the differences between CE and CE+, what the Danzell changes mean in practice, how long certification takes, and why working with the right people matters more now than at any point since the scheme launched.

1. Cyber Essentials vs Cyber Essentials Plus: The Core Difference

The simplest way to understand the difference is this:

Cyber Essentials (CE) is what you say you do. Cyber Essentials Plus (CE+) is what you prove you do.

Both certifications are built on the same five technical controls:

  • Firewalls and secure configuration
  • User access control
  • Malware protection
  • Patch management
  • Secure network configuration

These controls haven’t changed under Danzell, but the way they’re assessed has.

Cyber Essentials (CE): Verified Self‑Assessment

Cyber Essentials is a self‑assessment. You complete a detailed questionnaire, a licensed Certification Body reviews your answers, and if everything checks out, you’re certified. It’s a strong baseline and often enough for smaller tenders or supply‑chain requirements.

Cyber Essentials Plus (CE+): Independent Technical Testing

Cyber Essentials Plus includes the same questionnaire, but adds hands‑on technical testing. An assessor checks your devices, scans your network, validates patching, and confirms your controls actually work. It’s independent verification – the difference between claiming your systems are secure and proving it.

CE+ is increasingly required for higher‑assurance contracts, NHS suppliers, and larger enterprise tenders.

2. What Changed in 2026: The Danzell Question Set

On 27 April 2026, Cyber Essentials moved to a new question set called Danzell. If your assessment account was created on or after that date, you’re being assessed under stricter rules.

The headline changes are significant:

Mandatory MFA for All Users – Not Just Admins

If a cloud service offers MFA and you haven’t enabled it for every user, it’s now an automatic fail. No partial credit. No assessor discretion.

Critical Patches Must Be Applied Within 14 Days

If a high‑risk security update isn’t applied within 14 days, that’s also an automatic fail. Previously, this might have been flagged as a risk – now it fails the entire assessment.

Cloud Services Can No Longer Be Excluded

Under Danzell, cloud services are always in scope. That includes business social media accounts if they’re accessed using company credentials.

No More “Fix It Later” During CE+

Once your CE answers are verified and CE+ testing begins, you cannot change your answers. If the assessor finds something that contradicts your questionnaire, you’re dealing with that problem mid‑assessment, not before.

This is one of the biggest practical changes. It means:

Getting the CE answers right the first time matters more now than ever.

3. Why Accuracy Matters: The Risks of Mistakes Under Danzell

Before Danzell, assessors had some discretion. If you misunderstood a question or missed a detail, they could often guide you. That’s gone.

Automatic Fails Are Now Common

The new rules introduce strict auto‑fail conditions. Even a single missed MFA setting or a single unpatched critical vulnerability can fail the entire assessment.

Misunderstanding Scope Can Sink Your Assessment

Cloud services are now always in scope. If you incorrectly exclude a system — even something as simple as a shared business social media account — your answers may be considered inaccurate.

CE+ Testing Will Expose Any Gaps

If your CE answers don’t match what the assessor finds during CE+ testing, you cannot revise them. This can lead to:

  • Delays
  • Additional remediation work
  • Re‑testing fees
  • Potential failure

This is why organisations are increasingly turning to experienced partners to help them prepare.

4. How Long Cyber Essentials and CE+ Take in 2026

The time required depends on your readiness, but the typical timelines are:

Cyber Essentials (CE)

Most organisations complete the CE questionnaire within a few hours to a few days, depending on how well‑documented their controls are. The certification body’s verification usually takes 1–3 working days.

Cyber Essentials Plus (CE+)

Once your Cyber Essentials Verified Self‑Assessment (CE) is complete, Cyber Essentials Plus must normally be completed within 90 days.

The technical testing itself typically takes:

  • Half a day for small organisations
  • One full day for medium organisations
  • Multiple days for complex environments

Preparation time varies widely. Organisations with strong patching, MFA, and device management can move quickly. Those with gaps may need days or weeks to remediate.

5. Why CE+ Is Becoming the Expected Standard

CE remains valuable – it’s still the UK’s baseline cyber standard. But CE+ is increasingly the certification organisations ask for when they need assurance that controls actually work.

CE+ is now commonly required for:

  • NHS suppliers
  • Larger enterprise supply chains
  • Public‑sector contracts
  • Organisations handling sensitive data
  • Higher‑assurance frameworks and tenders

The Danzell changes amplify this trend. With stricter rules and less room for error, CE+ provides confidence that your systems genuinely meet the standard – not just on paper.

6. Why You Need the Right People Helping You

Under Danzell, the CE questionnaire is no longer a simple tick‑box exercise. It requires:

  • Accurate scoping
  • Correct interpretation of technical controls
  • Evidence‑based answers
  • Understanding of MFA, patching, and cloud requirements
  • Awareness of auto‑fail conditions
  • Alignment between declared controls and real‑world configurations

Mistakes can now fail your assessment outright – and CE+ will expose any inaccuracies.

This is why organisations increasingly rely on experienced partners to:

  • Review their environment
  • Validate their answers
  • Identify gaps before submission
  • Prepare for CE+ testing
  • Ensure controls are implemented correctly
  • Avoid costly re‑tests or failures

The right partner doesn’t just help you pass – they help you build a stronger, more resilient security posture.

7. What Happens If You Make Mistakes

The consequences of errors under Danzell are more severe than before:

You Can Fail the Entire Assessment

Even a single missed MFA setting or unpatched critical vulnerability can cause an automatic fail.

You May Need to Pay for Re‑Testing

If CE+ testing reveals gaps, you may need remediation and re‑testing – both of which cost time and money.

You Could Lose Tender Eligibility

Many contracts require CE or CE+. A failed assessment can delay or block your ability to bid.

Your Cyber Insurance Could Be Affected

Cyber Essentials certification unlocks free cyber liability insurance for eligible organisations. A failed assessment may impact eligibility.

You Risk Reputational Damage

Clients increasingly expect suppliers to demonstrate strong cyber hygiene. Failing CE or CE+ can raise questions about your security maturity.

8. How to Prepare Properly: A Practical, No‑Nonsense Approach

To succeed under Danzell, organisations should focus on three areas:

1. Get MFA Right Everywhere

Check every cloud service. Ensure MFA is enforced for all users – not just admins.

2. Tighten Patch Management

Critical patches must be applied within 14 days. No exceptions.

3. Validate Your Answers Before Submission

Your CE answers must be:

  • Accurate
  • Evidence‑based
  • Consistent with your real environment
  • Fully aligned with CE+ testing expectations

This is where experienced support makes the biggest difference.

9. Use Our Cyber Essentials Checklist

To help organisations prepare, we’ve created a clear, practical Cyber Essentials checklist – updated for the Danzell changes.

It covers:

  • Scoping
  • MFA
  • Patch management
  • Device controls
  • Cloud services
  • Documentation
  • Evidence requirements
  • CE+ preparation steps

You can find it here: https://ergos.uk/blog/cyber-essentials-checklist-a-practical-guide-for-uk-businesses/

10. Cyber Essentials & CE+ FAQ (Updated for Danzell)

Do I need CE before I can get CE+?

Yes. CE+ cannot be completed unless you have a valid CE certificate.

How long is CE valid for?

Both CE and CE+ are valid for 12 months

Can I change my CE answers during CE+ testing?

No. Under Danzell, once CE is verified, your answers are locked. Any contradictions found during CE+ may lead to failure.

Is MFA now mandatory for all users?

Yes – if the cloud service supports MFA. Not enabling MFA for all users is now an automatic fail.

Can I exclude cloud services from scope?

No. Cloud services are always in scope under Danzell.

What happens if I fail CE or CE+?

You may need remediation and re‑testing. This can delay tender eligibility and increase costs.

Is CE+ worth it?

For organisations handling sensitive data, working with public‑sector clients, or operating in higher‑assurance supply chains, CE+ is increasingly expected.

Can mistakes in CE cause CE+ to fail?

Yes. CE+ testing validates your CE answers. Any mismatch can lead to failure.

How long does CE+ testing take?

Typically half a day to a full day, depending on organisation size.

Do I need external support?

You don’t have to – but under Danzell, most organisations benefit from expert guidance to avoid auto‑fail conditions and ensure CE+ readiness.

Final Thoughts

Cyber Essentials has always been a strong baseline. But the Danzell changes mean the scheme is now stricter, clearer, and less forgiving. That’s a good thing – it raises the bar for UK cyber resilience.

But it also means:

  • You must answer the CE questionnaire accurately.
  • You must implement MFA and patching correctly.
  • You must scope cloud services properly.
  • You must prepare for CE+ testing thoroughly.
  • You must avoid mistakes that now lead to automatic fails.

And above all:

You need the right people helping you – people who understand the scheme, the controls, the testing, and the new Danzell rules.

With the right support, CE and CE+ become straightforward, predictable, and valuable. Without it, the risk of failure is higher than ever.

Contact us at Ergos to help you with any further questions you may have about your Cyber Essential or Cyber Essentials+ certifications: Contact – ERGOS Technology Partners

Let ERGOS take the stress out of IT for you

Contact us now to get six months of IT Support for free