Security & Compliance

Pass Danzell first time.
Or find out why now.

The April 2026 question set added auto-fail conditions the old one did not have, and brought AI and LLM tools into scope as cloud services. We get your estate to a state that passes, then hand you to a licensed certification body — we are not one, and cannot certify you.

5 controls
Five themes, and any one can fail you
14 days
New patch window for critical and high
12 months
Your director now commits to maintaining it
Trusted by 32+ teams shipping remote engineering, today
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Razorpay
Naamly
Tekdoors
SimAgro
Enzen Technologies
Greenlink Health
R360
SharafDG
Concourse Solutions
YOptima
ReMarketplace
Desisiv
Dealflow
LIAISON
Stealth Connect
Car Concierge Pro
Dinner Daddy
Heal Me Fit
Heather Hakes
Kegelbell
Laina
MogiFit
Visag
YouthRenewal
OC Weight Loss
USPTO Lawmatics
Delegata
AZCap
Mindbase
WeBuyUglyBuildings
One Collab Space
Epifinder
Why it matters

Cyber Essentials used to be a form-filling exercise. The Danzell question set, mandatory for accounts created from 26 April 2026, turned missing MFA on any cloud service into an automatic fail, added two new auto-fail patching questions, and pulled every AI and LLM tool into scope as a cloud service. If you deployed an agent since your last renewal, you have a certification problem you did not have last year.

Benefits

Why teams choose us.

Assessed Against Danzell

Not the Willow set, not a generic checklist. The current question set, with the auto-fail conditions called out first because they are the ones that sink applications.

AI Tools Inventoried

Every LLM tool, agent and AI service your teams use, mapped as an in-scope cloud service with an owner and an access position. Most organisations have no such list.

Whole-Organisation Scope

Danzell pushes harder for whole-organisation scope. We identify what a narrow scope would exclude and what that costs you commercially before you commit to it.

We Are Not The Assessor

Certificates come only from an IASME-licensed certification body. We prepare you, then introduce you to one — and take no fee from them.

What we offer

The full menu.

The Five Control Themes

  • Firewalls and internet gateways
  • Secure configuration
  • Security update management
  • User access control
  • Malware protection

The Auto-Fail Sweep

  • MFA on every cloud service, without exception
  • Critical and high patches inside 14 days
  • Unsupported software identified and removed from scope
  • Default credentials and unnecessary accounts closed

AI & Cloud Inventory

  • LLM and agent tools as in-scope cloud services
  • Shadow AI discovery across teams
  • Access model and MFA position per tool
  • Sanctioned-tool policy your director can sign against

Device & Endpoint Baseline

  • MDM enrolment across the scoped estate
  • BYOD position and enforcement
  • Disk encryption and screen-lock policy
  • Malware protection coverage evidence

Certification Handover

  • Introduction to an IASME-licensed certification body
  • Scope statement drafted for the assessor
  • Evidence pack in the format they ask for
  • Support during the assessment questions
How it works

Our process.

01

Scope & Inventory

Agree the organisational boundary, then inventory devices, cloud services and — critically — every AI tool in use. The inventory is usually where the surprises are.

02

Auto-Fail Sweep

We check the conditions that fail an application outright before anything else, so you learn the bad news in week one rather than at assessment.

03

Remediate

MFA rollout, patch pipeline, MDM enrolment, configuration hardening. Delivered as engineering work, with your approver merging every change.

04

Hand Over

Evidence pack, scope statement, and an introduction to a licensed certification body. They assess; we support you through their questions.

Tech stack

What we build with.

Scheme
Cyber Essentials v3.3 (Danzell)IASMECyber Essentials Plus
Identity & Device
Entra IDOktaIntuneJamfGoogle Workspace
Patch & Protect
Microsoft DefenderAutomated patch pipelinesDependency policy
Week 1
Scope, inventory, auto-fail sweep
Week 2–4
Remediation
Week 5
Evidence pack and scope statement
Week 6
Certification body engaged
Right fit?

Choose this if...

You hold a public-sector or enterprise contract that requires Cyber Essentials
Your renewal falls after April 2026 and you have not re-read the question set
Your teams have adopted AI tools since your last certification
You want to know what fails before you pay an assessor to tell you
Right fit?

Honest about who this is for.

Pick us if

This will be a fit.

  • You are a UK private-sector organisation with a real certification deadline
  • You would rather find the auto-fails in week one than at assessment
  • You want the remediation done, not just a gap list
  • You accept that the certificate comes from a licensed body, not from us
Skip us if

Honestly — not our zone.

  • You want us to issue the certificate — we are not an IASME-licensed certification body and cannot
  • You need Cyber Essentials Plus hands-on device testing in the UK. That is an on-site assessment by a licensed body; we prepare you for it and refer it
  • You are a UK public-sector body. G-Cloud 15 requires CE Plus of cloud suppliers and public work requires UK data residency and cleared staff — we decline it
  • You want the narrowest possible scope to pass. Danzell pushes toward whole-organisation scope and we will tell you what a narrow scope costs you
FAQ

Common questions, straight answers.

Can you certify us?

No. Cyber Essentials certificates are issued only by IASME-licensed certification bodies, and we are not one — you can check the public directory. We prepare you and introduce you to a licensed body, and we take no fee, commission or rebate from them.

What changed in April 2026?

The Danzell question set replaced Willow for all assessment accounts created from 26 April 2026, with six months for pre-existing accounts. Missing MFA on any cloud service is now an automatic fail, two new auto-fail questions require critical and high patches inside 14 days, passwordless authentication is accepted alongside MFA, and AI and LLM tools are formally in scope as cloud services.

Why does AI being in scope matter so much?

Because almost nobody has an inventory. If your teams adopted an LLM tool, an agent, or an AI coding assistant since your last renewal, each is now an in-scope cloud service needing an owner, an access model and MFA. Shadow AI is the single most common reason a renewal that should have been routine now fails.

How much does the certificate itself cost?

The IASME assessment fee is banded by organisation size and is set by IASME, not negotiable, and paid to the certification body rather than to us. Cyber Essentials Plus is a separate and larger fee set by the certification body, in addition to the base assessment. We will tell you the current bands before you engage us.

Is this the same as ISO 27001?

No, and it is much smaller. Cyber Essentials is five technical control themes; ISO 27001 is a full management system with 93 controls, an internal audit requirement and a three-year certification cycle. If ISO 27001 is your actual target, start with a Compliance Readiness Assessment instead.

Can you do this for a UK council?

No. UK public-sector work requires contractual UK data residency covering support escalation, and often security-cleared staff — our delivery is from Mumbai and our engineers cannot obtain SC clearance, which needs roughly five years of UK residency. We say so rather than bid and hope.

From £7,500· Pass Danzell first time, or find out why now

Ready to start?

Book a free 30-minute call. We'll scope the work, share examples, and send a plan within a week.

Related

More from this category

Compliance Readiness Assessment
The honest gap list, costed in engineer-days
Compliance Remediation Pod
Keep your Vanta. Keep your auditor. We ship the fixes.
Agent Security & AI Governance Review
Answer the AI questionnaire, fix what it exposes