Quick answer: Cyber Essentials changed in April 2026. A new question set called Danzell replaced the old Willow set, the Requirements moved to version 3.3, and Cyber Essentials Plus audits became stricter. For Aberdeen businesses, the bigger shift is commercial: more tenders, contracts and supply chain checks now ask for the certificate before they will work with you.
Backed by the National Cyber Security Centre (NCSC) and run by IASME, Cyber Essentials has been the UK’s baseline security certification since 2014. For most small and medium businesses it is the first formal step in proving they take security seriously.
In 2026 the scheme had its most significant update in years. If your certificate is coming up for renewal, or a client has started asking whether you hold one, it is worth understanding what actually changed and what it means for you locally.
The certification checks five basic technical controls that stop the most common attacks. These are firewalls, secure configuration, user access control, malware protection, and security update management (keeping software patched).
There are two levels. Standard Cyber Essentials is a verified self-assessment. You answer a questionnaire, and a certification body reviews your answers. Cyber Essentials Plus (CE Plus) adds a hands-on technical audit, where an assessor tests a sample of your devices to confirm the controls are actually working.
The five controls sound simple. In practice, most businesses that fail do so on patching or on user access, not on anything exotic. The value of the certificate is that it forces you to check.
The headline update is a new question set. Since 27 April 2026, every new Cyber Essentials assessment has used a set named Danzell, which replaced the previous set called Willow.
The names cause confusion, so it is worth being clear. Willow was the outgoing set, in use since April 2025. Danzell is the current one, published by IASME in February 2026 and live for all new assessment accounts created on or after 27 April 2026. Alongside it, the NCSC Requirements for IT Infrastructure moved to version 3.3.
Businesses that certified before that date were assessed against Willow. Your next renewal will use Danzell, so the questions will look different from last year.
The five controls have not changed in principle. What changed is how much evidence you need to show and how little room there is to fudge it.
The update sharpens expectations around several everyday areas. Multi-factor authentication (MFA) is treated more firmly, patching windows are tighter, and there is more focus on how you evidence secure configuration across the devices in scope. None of this is new security thinking. It is the scheme catching up with how businesses actually work now, including cloud services and remote staff.
For most well-run businesses, the practical effect is more preparation. You cannot answer from memory. You need records that show MFA is switched on, that updates are applied within the required window, and that old accounts are removed when people leave. That last point is why a clear secure leaver process matters more than people expect at assessment time.

If you hold or want CE Plus, the 2026 changes are more noticeable. The audit is stricter and harder to game.
The most important change is that the verified self-assessment is now locked once CE Plus testing begins. Under the old rules, businesses could quietly adjust their answers after testing revealed a problem. Under version 3.3, your self-assessment responses are fixed from the moment the audit starts and cannot be changed to reflect fixes made afterwards.
The retest process also changed. When a device fails and you fix it, the reassessment no longer looks only at that device. It now covers the original sample plus a new random sample of different devices from the same scope. The pool widens rather than narrows, so a single fix no longer clears the whole audit if the same weakness exists elsewhere.
The message is consistent. The scheme wants proof that a control works across your estate, not just on the day, not just on one laptop.
The assessment fee is set by IASME and is the same through every certification body. It is tiered by organisation size. These are the 2026 fees for standard Cyber Essentials:
| Organisation size | Employees | Assessment fee |
|---|---|---|
| Micro | 0 to 9 | £320 + VAT |
| Small | 10 to 49 | £440 + VAT |
| Medium | 50 to 249 | £500 + VAT |
| Large | 250+ | £600 + VAT |
Cyber Essentials Plus is priced separately, because it involves a hands-on audit, and the cost depends on the size and complexity of your setup. Standard certification also includes cyber liability insurance for eligible UK organisations under a set turnover, which is worth checking against any policy you already hold.
The certificate fee is rarely the real cost. The real work is the preparation: fixing gaps, tidying up access, and getting your evidence in order before you submit. That is where most of the effort, and most of the value, sits.
For years, Cyber Essentials was a nice-to-have for most local firms. In 2026 it is becoming a condition of doing business, and Aberdeen’s economy makes that pressure sharper than most.
The Cyber Security and Resilience Bill, introduced to Parliament in late 2025, tightens obligations on operators of essential services, critical infrastructure, and managed service providers. Aberdeen sits in the middle of energy supply chains, and large regulated organisations do not absorb new security duties alone. They pass them down. The likely effect is that aligned demands appear in contracts, tenders and supplier audits well beyond the companies directly named in the law.
Suppliers to an energy major, a public sector body, or a large prime contractor will feel this through their paperwork before they feel it anywhere else. Cyber Essentials is often the flow-down requirement. On many government contracts it is mandatory, and primes routinely require subcontractors to hold it as a condition of the work.
So the practical picture for an Aberdeen SME is this. A certificate that once helped you stand out now helps you stay in the running. Losing a tender because you cannot produce one is a far more expensive outcome than the £320 to £600 fee. It is also worth remembering that the certificate is a floor, not a ceiling. It reduces exposure to common attacks but does not replace a plan for what to do after a cyber attack.

Before you spend anything, it helps to know roughly where you stand. Use a simple traffic light view across the five controls.
Green means the control is in place and you can prove it. MFA is enforced on email and key systems, updates apply automatically within a few days, and leavers lose access quickly.
Amber means the control mostly works but the evidence is patchy. You think MFA is on everywhere, but nobody has checked. Patching happens, but not on a schedule you could show an assessor.
Red means the control is missing or inconsistent. Shared logins, unsupported software still in use, or no clear record of who has access to what.
Work the reds first, tidy the ambers, then submit. Going into an assessment with unresolved reds wastes the fee and your time. For a working IT setup, a lot of this overlaps with everyday good practice, including how you use tools like Microsoft 365 and Copilot safely.
Most businesses do not fail Cyber Essentials because their security is poor. They stall because the preparation is fiddly and the 2026 rules leave less room for guesswork. Knowing which controls apply to your cloud services, which devices are in scope, and what evidence an assessor will accept is where a managed provider earns its place.
At Alto we help Aberdeen businesses prepare for and achieve Cyber Essentials and CE Plus, from the first readiness check through to submission. We map your current setup against the Danzell requirements, fix the gaps, and get your evidence in order so the assessment is a formality rather than a gamble.
Standard Cyber Essentials is a verified self-assessment reviewed by a certification body. Cyber Essentials Plus adds a hands-on technical audit, where an assessor tests a sample of your devices to confirm the controls work. CE Plus gives buyers stronger assurance and is often required for higher-value or public sector contracts.
The assessment fee is set by IASME and is the same everywhere. It ranges from £320 + VAT for micro organisations up to £600 + VAT for large ones, based on employee numbers. Cyber Essentials Plus is quoted separately because it involves an audit, and preparation work is usually the larger cost either way.
A new question set named Danzell replaced Willow from 27 April 2026, and the NCSC Requirements moved to version 3.3. Expectations around MFA, patching and evidence tightened, and CE Plus audits became stricter, including a locked self-assessment and a wider device sample on retest.
For a well-prepared business, standard Cyber Essentials can be completed in a few days once your controls and evidence are ready. The variable is preparation. If you have gaps in patching, access control or MFA, fixing them first is what takes the time.
If you supply the public sector, energy firms, or large prime contractors, increasingly yes. Cyber Essentials is a common flow-down requirement in tenders and supplier audits, and that trend is growing as new UK cyber regulation pushes obligations down the supply chain.
If Cyber Essentials is coming up on a tender, a renewal, or a client request, we can tell you exactly where you stand before you commit. Book a Cyber Essentials readiness assessment with Alto and we will map your setup against the 2026 requirements, flag the gaps, and give you a clear path to the certificate. Visit our cyber security page or get in touch to book a consultation.
