Cyber Essentials Plus Has Changed: Why Out-of-Date Software Can Now Cost You Both Certifications

If you’ve held Cyber Essentials or Cyber Essentials Plus for a few years, it’s easy to assume the renewal process works the same way it always has: fill in the self-assessment, book the technical audit, fix anything minor, get your certificate. From 27 April 2026, that assumption gets a lot riskier, particularly if your estate has any software running past its supported life.

The scheme has moved to a new question set, known as “Danzell”, replacing the previous “Willow” set. It’s the biggest change to Cyber Essentials in three years, and one of its central themes is unsupported and end-of-life software. Get caught out here, and for the first time, a Cyber Essentials Plus failure can put your underlying Cyber Essentials certificate at risk too, not just the Plus badge.

Why out-of-date software is suddenly under the spotlight

Cyber Essentials has always required that software in scope is licensed and supported by its vendor. What’s changed is how unforgiving the scheme now is about it.

Danzell introduces several explicit automatic-fail questions into the assessment process, significantly increasing the consequences of non-compliance in key areas such as patch management and MFA. Two of the biggest relate directly to patching: critical and high-risk security updates for operating systems, and router and firewall firmware, must now be installed within 14 days of release (question A6.4), and the same 14-day rule now applies to applications too (A6.5). Miss either, and it’s an automatic fail, no averaging out against a strong score elsewhere.

That’s exactly where end-of-life software becomes a problem. A vendor can’t issue a 14-day security patch for software it no longer supports, because there isn’t one coming. Windows 10 reached end of support on 14 October 2025. Devices running Windows 10 without a valid Extended Security Updates (ESU) entitlement should be treated as unsupported for Cyber Essentials purposes because they can no longer receive the security updates required by the scheme. The same challenge extends beyond end-user devices. SQL Server 2016 reached end of support on 14 July 2026, meaning organisations still running production databases on that platform need either an upgrade strategy or appropriate Extended Security Updates coverage. The rule that matters is simple: your systems must be supported on the date your certificate is issued, not merely when they were last reviewed.

For many organisations, unsupported software remains hidden in legacy systems, forgotten servers and unmanaged devices until certification activities bring it to light. It’s rarely a deliberate risk; it’s a visibility gap.

What actually happens when you fail

It’s worth being precise here, because the basic Cyber Essentials self-assessment and the audited Cyber Essentials Plus test now behave quite differently when something goes wrong.

If you fail the Cyber Essentials self-assessment, your certification body gives you feedback on what’s non-compliant and you typically have around two working days to correct simple issues and resubmit at no extra cost. Beyond that, you’re looking at a full reapplication at full cost, and if the whole process drags past roughly a month from the original fail, IASME can revoke the certification outright and you start again from scratch.

If you fail the Cyber Essentials Plus technical audit, you generally have a window of up to 30 days from the date of the audit or 90 days from your Cyber Essentials certification date, whichever comes first, to fix the issue and provide evidence back to your assessor for re-verification. Some evidence (firewall rules, account lists, configuration exports) can carry over between attempts, but anything that captures a point-in-time state, like a vulnerability scan, has to be re-run.

Here’s the part that’s new under Danzell, and the part that should genuinely change how you think about patching and end-of-life software: when an assessor’s sample of devices fails the update-management test, the retest no longer just re-checks those same machines. It also pulls a new, separate random sample from across your estate. You have to be clean on both. Where the second random sample demonstrates that the same update-management issues remain present elsewhere in the environment, the organisation can fail Cyber Essentials Plus and have its Cyber Essentials certification revoked. This is one of the most significant changes introduced with Danzell because Cyber Essentials Plus findings can now directly lead to revocation of the underlying Cyber Essentials certification in certain circumstances.

In practical terms: fixing the two laptops the auditor happened to test isn’t enough anymore. If out-of-date software exists anywhere in scope, it needs to be found and dealt with estate-wide, inside a 30-day clock, or you risk losing both certifications and starting the entire certification process again, along with the associated costs.

The challenge is that Cyber Essentials does not assess whether you have a patching policy; it assesses whether the devices selected during the assessment comply in practice. That distinction matters. An organisation can have documented processes, automated update tools and regular IT governance reviews, yet still fail because a small number of unmanaged, forgotten or end-of-life assets sit outside normal operational controls.

Where this becomes a visibility problem, not a willingness problem

Nobody fails Cyber Essentials Plus because they don’t care about patching. They fail because nobody had a reliable, real-time answer to “what software, and which version, is actually running across our estate right now, and is any of it end-of-life?” Spreadsheets and best-guess asset registers get out of date within weeks. Auto-patching handles a lot, but relying on it alone does not guarantee full coverage, and it does nothing for software that’s already past the point where patches exist at all.

This is precisely the gap that a proper software asset management tool closes. Licenseware provides visibility into what’s deployed across your environment, down to the specific edition and version, and flags what’s out of support or approaching end-of-life, before an assessor’s sample ever finds it for you. Instead of discovering a forgotten legacy application during a 30-day remediation clock, you know about it months in advance, with time to patch, upgrade, or formally remove it from scope.

If you’re already using an inventory or asset management tool of your own and it’s telling you what’s deployed, its edition, and whether it’s out of date or end-of-life, that data has real value beyond IT hygiene, it can become the evidence base for your Cyber Essentials Plus assessment. If you’d like help turning what you already have into audit-ready reporting or want to see what Licenseware surfaces across your own estate, get in touch with The SAM Club. We work with both scenarios every day, and either way, the goal is the same: know what’s out there before your assessor does.

Privacy Preference Center

Secured By miniOrange