Blog › Article
What the Danzell question set changed, operationally
MFA and patching, which used to be findings, are now automatic failures. Most MSP patching processes were built for the old rules, and the transition period that let older assessments finish under those rules ends in October.
What changed
Cyber Essentials assessments started under the Danzell question set on 27 April 2026. It has four automatic-fail questions, in two groups. A "no" to any of them fails an assessment on its own, whatever the rest of the questionnaire says:
- Multi-factor authentication on cloud services that offer it — one question for administrator accounts, one for users.
- High-risk or critical updates applied within fourteen days of release — one question for operating systems, routers and firewalls, one for applications.
Neither requirement is new. Both were in the scheme before. What changed is that an assessor no longer weighs them against everything else: a single honest "no" is a fail.
The deadline that matters. Assessment accounts opened before 27 April 2026 could be completed under the previous question set within six months. That window closes at the end of October. From November, every client of yours going through Cyber Essentials does so under Danzell.
Why "fourteen days" is harder than it sounds
Most estates are patched. The problem is that the rule is about every in-scope machine and every high-risk or critical update, measured from the day the vendor released it — not from the day your RMM approved it. The gaps are rarely a policy anyone chose. They are the machines and settings nobody was looking at.
Deferral rings that add up past the limit
A seven-day deferral, then an approval step that runs weekly, then a maintenance window at the weekend: each is sensible, and together they can carry a critical update past day fourteen on a machine that did everything it was told.
Paused updates nobody unpaused
A user pauses Windows Update before a presentation, or a technician pauses it while fixing something else. The pause outlives the reason, and the machine quietly falls behind with nothing reporting it as a fault.
Laptops that are simply not there
A machine that is off, travelling or sitting in a drawer misses the window without any update having failed. It only shows up when someone asks when it last installed something.
Failed installs that look like success
An update that downloads, fails to install and retries the next night can sit in that loop for weeks. The RMM shows it as approved. The machine is still exposed.
Software that isn't Windows
The fourteen days apply to applications too: browsers, PDF readers, remote-access tools, anything in scope. An estate can be perfect on Windows and fail on a browser nobody manages centrally.
Operating systems past end of support
An unsupported operating system cannot receive the updates, so it cannot meet the rule. Windows 10 reached end of support in October 2025; any Windows 10 machine in scope needs replacing, upgrading or removing before assessment, or moving into a separate subset with no internet access at all.
What an assessor is really asking
The question is whether updates were applied within fourteen days, not whether they are applied now. A machine that was thirty days behind for most of the year and caught up the week before the assessment gives a different honest answer from one that never slipped. A screenshot of a green dashboard on assessment day shows the second thing. Only a dated record shows the first.
A checklist before your next assessment
- Agree the scope for each client, including home workers, servers and the machines nobody mentioned. You cannot patch what isn't on the list.
- Add up your deferrals. From release to installed, across every ring and window, the worst case must land inside fourteen days.
- Find paused and failing machines and fix the cause, not just the instance.
- List every unsupported operating system in scope and decide, per machine, whether it is replaced, upgraded, removed, or moved into a separate subset with no internet access at all.
- Cover applications, not just Windows: browsers and common tools first.
- Check MFA on every cloud service, for administrators and users. This is outside anything an endpoint can report, so it needs its own check.
- Start keeping dated records now. The best time to have a year of evidence is a year before the assessment; the second best is today.
The short version
Danzell didn't add work so much as remove the room to explain it away. The MSPs who find this easy will be the ones who can show, for any day in the year, how far behind each machine was. Everyone else will be reconstructing it from memory the week before the assessor asks.