You’re probably already aware that Cyber Essentials has a new set of questions, and it seems like every tech blog has published its own version of “What is Danzell?”. That’s why we’re not going to.
Understanding the changes is important, but the more useful question is: “What does Danzell mean for my business?”. Because Danzell is more than just an administrative change. It asks organisations to think more carefully about how their people, devices, systems and networks operate day to day.
This makes Cyber Essentials feel less like a form to fill in, and more like a review of how the business is set up. It turns cybersecurity from a box-ticking exercise to a continuous operational requirement.
Let’s look at the two major ways businesses will be affected by Danzell.
1. A need to consider the ‘how’
Danzell asks for a clearer picture of how your business works. Organisations need a firmer understanding of what’s happening across their environment, not just of the environment itself.
Think about how a new contractor may need access to a shared system, or how someone starts working remotely more often. These things are common, and you know they’re happening, but Cyber Essentials doesn’t want to know the ‘what’; it expects businesses to explain the ‘how’.
Danzell asks more direct questions about how users connect to systems and data, so it’s no longer enough to know who’s accessing what. You’ll need to know how they’re doing it. Are staff using company devices, personal devices, VPNs, cloud logins, remote desktop tools, or a mix of these?
2. A need to understand scope
Another important shift is the way scope is treated. Previously, businesses were asked to state which networks and systems were included in the assessment. Danzell now asks whether any networks or systems have been explicitly excluded. It’s a small change, but it makes a massive difference.
Partial scope assessments now need more thought. You can’t leave out parts of your environment without reason. If something is being excluded, there needs to be a clear understanding of why.
This is likely to affect growing businesses, multi-site organisations, those with old legacy systems, and companies with a messy mix of cloud tools, local servers and remote access. The assessment may expose gaps sitting in the background for years, but this isn’t necessarily a bad thing. It’s a chance to tidy up ownership, assign responsibilities, and manage security controls before gaps become big issues.
Preparation matters
The main takeaway is that businesses need to prepare before they apply. A rushed assessment is more likely to uncover missing information, unclear scope, weak remote working controls, unsupported systems, or cloud services that have never been properly reviewed.
At PSTG, we don’t want that to happen. Our Cyber Essentials readiness assessment gives you a clearer starting point. It helps identify what’s in scope, how access is managed, where controls need tightening, and what needs fixing before certification begins.
For businesses that want the process to run smoothly, preparation matters. Danzell asks businesses to better understand their own setup – and that’s much easier to do before the assessment is underway.