โ† Seb's Workshop Danzell v3.3 ยท April 2026
Cyber Essentials

CE Readiness Check

Gap analysis against the Danzell question set (Requirements for IT Infrastructure v3.3)

๐Ÿ”ด New auto-fail rules ยท April 2026 ๐Ÿ’พ Auto-saves progress
๐Ÿ”ด New Auto-Fail
MFA on cloud services โ€” if MFA is available on any cloud platform and you haven't enabled it, assessment fails immediately. Cost is not an excuse.
๐Ÿ”ด New Auto-Fail
14-day patching (A6.4 & A6.5) โ€” missing the window for OS/firmware or application fixes is now immediate failure. Previous tolerance removed.
โš ๏ธ Changed
Password minimum โ†’ 12 characters (up from 8). MFA or passwordless authentication satisfies this independently.
โš ๏ธ Changed
Point-in-time = certificate issue date โ€” your systems must be compliant on the day the certificate is issued, not submission day.
โœฆ Clarified
Passkeys are now the NCSC's preferred auth method. FIDO2, biometrics, OTPs, security keys and push notifications all formally accepted.
โœฆ Clarified
Cloud services formally defined for the first time โ€” they cannot be excluded from scope. Scope descriptions are now unlimited in length on certificates.
โœฆ Clarified
Director declaration updated โ€” now includes explicit acknowledgement of responsibility for maintaining CE compliance throughout the full certification period.
โš ๏ธ CE+ Only
Self-assessment locked before CE+ audit โ€” VSA responses cannot be amended after testing begins. "Selective patching" workaround closed.