Cyber Essentials has changed. Here’s what the April 2026 Danzell update means for your Mac fleet.

Cyber Essentials logo centred, surrounded by five blue security themed icons on a dark background—perfect for showcasing compliance with the April 2026 Danzell Update across your Mac fleet.

From 27 April 2026, Cyber Essentials assessments run against a tighter standard. The five controls have not changed. The way they are enforced has. For Mac-first businesses, the patching auto-fail, expanded cloud scope, and MFA requirements all have specific implications. This article covers what is different, what it means for a managed Mac fleet, and what to prepare before your next renewal.

If you renewed Cyber Essentials before April 2026, your answers passed under the Willow question set. Danzell, the v3.3 update that came into force on 27 April, applies to all assessments created from that date. Your previous experience is no longer a reliable guide to your next one. Organisations that held certification comfortably under Willow are discovering gaps under Danzell’s tighter enforcement. The businesses most likely to be caught out are those that assume continuity.

Some businesses will already have renewed successfully under Danzell by the time this article is published. For them, the value is knowing what to maintain. For everyone else, the preparation starts now.

What the Danzell update is and what it replaces

The Willow question set and why it was updated

Willow (v3.2) came into force in April 2025. Danzell (v3.3) replaced it from 27 April 2026. IASME, which administers Cyber Essentials on behalf of the NCSC, publishes an annual review; this year’s update reflects findings from breach investigations and assessor feedback.

What changed on 27 April 2026

The five core Cyber Essentials controls remain unchanged: firewalls, secure configuration, user access control, security update management, and malware protection. What changed is the marking. Danzell introduces automatic failure for specific control failures that previously counted as major non-compliances. Under Willow, organisations could receive up to two major non-compliances and still pass. That safety margin has been removed for the most critical requirements. The key auto-fail triggers are: missing MFA on any cloud service where it is available, and failure to apply high and critical patches within 14 days. A single missed patch or a single cloud service without MFA now fails the entire assessment.

The 14-day patching auto-fail and what it means for a Mac fleet

Which vulnerabilities trigger the 14-day requirement

All high-severity and critical-severity vulnerabilities must be patched within 14 days of release. This applies to operating systems, third-party applications, and firmware on network devices including routers and firewalls. Under Willow, failing this requirement was a major non-compliance that did not automatically end the assessment. Under Danzell, it does. Questions A6.4 and A6.5 in the new question set cover this, and both are now auto-fail.

How macOS update delivery interacts with the requirement

macOS delivers security updates reliably, but delivery and deployment are two different things. Apple releasing an update does not mean devices in your fleet have received it. On an unmanaged fleet, individual users control whether and when they install updates. One device that has not updated, sampled during a Cyber Essentials Plus audit, can fail the entire assessment. The 14-day window is achievable on a well-managed fleet. It is not achievable without a Device Management Service (formerly Mobile Device Management).

What your DMS needs to be configured to evidence

This is where many Mac-first businesses are caught out. Having a DMS in place is not enough. Assessors need evidence that patch policies are actively enforced and that compliance is logged at a point in time. Jamf and Addigy can produce device-level patch compliance reports showing update status for every enrolled Mac. These reports are the evidence format assessors expect. Apple Business’s basic DMS capability does not produce this level of audit evidence without additional configuration. Our recommendation for any business approaching renewal is to run a patch compliance report before opening the Danzell questionnaire, not after.

AI tools are now in scope and most businesses are not ready

Which AI services count as cloud services under Danzell

Danzell formally defines cloud services for the first time within Cyber Essentials and makes clear that any service storing or processing organisational data is in scope. That definition covers AI tools. ChatGPT Enterprise, Microsoft 365 Copilot, Google Gemini for Workspace, Claude for Work, and any other AI service your team uses to draft, summarise, or process business content is now a scoped cloud service. If MFA is available on it and you have not enabled it, the assessment fails.

What you need to be able to demonstrate about AI tools in your environment

The question assessors are now asking is not just whether MFA is enabled. It is whether you know which AI tools are in use at all. Shadow AI, tools employees are using without IT approval, creates automatic scope exposure under Danzell. If your team is using AI tools and you cannot list them, evidence their data handling configuration, and confirm MFA is active on every account, you have a Danzell compliance gap. In our experience, most businesses do not have a complete picture of which AI tools their team is using until they look properly.

How this connects to your AI acceptable use policy

An AI acceptable use policy and Cyber Essentials compliance are now the same conversation. The foundation is the same: know what tools are in use, bring them into scope, and ensure MFA is active across all of them.

The MFA auto-fail and what it means for Apple ID and Managed Apple Accounts

Which account types trigger the auto-fail if MFA is not enabled

Under Danzell, MFA is required on every cloud service where it is available, with no exceptions. If a service offers MFA as a paid add-on and you have not paid for it, the assessment still fails. This applies to email platforms, productivity tools, cloud administration portals, and any SaaS service your business uses. For Mac-first businesses using Apple’s ecosystem, this brings Apple accounts directly into scope.

How Managed Apple Accounts satisfy the requirement

Managed Apple Accounts, created and administered through Apple Business, are controlled by your organisation rather than individual employees. MFA requirements for Managed Apple Accounts are configurable via DMS policy. Apple Business administrators can enforce MFA settings across all managed accounts, and the configuration produces the kind of documented, auditable control that Danzell assessors are looking for.

Personal Apple IDs used for business purposes are a different matter entirely. They are outside IT control. You cannot enforce MFA policy on a personal Apple ID, you cannot audit its configuration, and you cannot produce evidence that it meets the Cyber Essentials standard. Under Danzell, any business-critical service accessed via a personal Apple ID without verified MFA is a compliance risk.

What to check before your renewal

Before you open the Danzell questionnaire, work through this list:

  • Confirm that all staff using Apple Business have Managed Apple Accounts, not personal Apple IDs, for business functions
  • Verify that MFA is enforced on all Managed Apple Accounts via DMS policy
  • Audit every cloud service in use, including AI tools, and confirm MFA is active on each one
  • Check that no business-critical accounts rely on a personal Apple ID that IT cannot manage or evidence

How to prepare for your next renewal under Danzell

The practical steps before you open the questionnaire

Danzell rewards preparation and punishes last-minute gap discovery. The businesses that pass cleanly are the ones that treat pre-assessment as a standing process, not a pre-deadline scramble. The steps below apply regardless of when your renewal falls.

  1. Audit all cloud services in use, including AI tools, CRMs, project management platforms, HR systems, and accounting software. If business data touches it, it is in scope.
  2. Verify DMS patch policies are enforced and logging compliance data. Run a patch status report for every enrolled device before assessment. Remediate any devices not current before the 14-day window is triggered.
  3. Confirm MFA is enabled on all in-scope services. Pay particular attention to services where MFA is available as a paid add-on and may not have been activated.
  4. Check that Managed Apple Accounts are in use for all business functions, and that personal Apple IDs are not being used to access business systems.
  5. Disable or remove accounts for leavers. Access control under Danzell includes timely account removal. This maps directly to the offboarding process and is one of the most commonly missed steps at assessment.

What documentation to have ready

Assessors under Danzell expect more than answers; they expect evidence. Have ready: DMS patch compliance reports with timestamps, screenshots of MFA configuration on key platforms, your cloud service inventory, and your Managed Apple Account configuration. The more of this documentation you can produce before the questionnaire, the smoother the assessment.

Where an Apple technical partner helps

Most Cyber Essentials consultants work from a Windows-centric background. For a Mac fleet, the specific evidence formats, DMS configuration requirements, and Apple Business administration requirements are different. We hold both Cyber Essentials and Cyber Essentials Plus certification and provide pre-assessment gap analysis for Mac-first businesses.

If your Cyber Essentials renewal is approaching and you are not sure whether your Mac fleet meets the Danzell requirements, we can run a pre-assessment review and close the gaps before you submit.

Related articles

FAQs

What is the Danzell update to Cyber Essentials?

Danzell is the name of the updated Cyber Essentials question set (v3.3) that came into force on 27 April 2026. It replaces the previous Willow question set. The five core controls are unchanged, but Danzell introduces automatic failure for specific gaps, including missing MFA on any cloud service where it is available and failure to apply high and critical patches within 14 days of release.

Does the 14-day patching requirement affect Mac fleets differently?

The requirement itself is the same across all platforms. The difference for Mac fleets is evidence. Assessors need documented proof that patches were applied within 14 days, which requires a Device Management Service (DMS) configured to produce device-level compliance reports. Jamf and Addigy both produce the required evidence format. A Mac fleet relying on user-initiated updates cannot evidence this to the standard Danzell requires.

Are AI tools now in scope for Cyber Essentials?

Yes. Under Danzell, any cloud service that stores or processes organisational data is in scope. That definition covers AI tools including Microsoft Copilot, Google Gemini, and ChatGPT Enterprise. If MFA is available on an AI tool your team uses and it is not enabled, the assessment fails automatically. Shadow AI tools, those in use without IT approval, create scope exposure even if IT is unaware of them.

Bearded man in a gray vest and blue patterned tie smiling, looking to the side.
Colin

Managing Director

Colin has spent his career building the kind of IT relationships that make people glad they picked up the phone. As Managing Director at Dr Logic, he thinks a lot about what good service actually looks like at scale — and how technology, including AI, should serve people rather than complicate their working lives.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.