The Danzell Problem Nobody in the Supply Chain Has Fixed Yet


In July, I was running an assurance review with a defence supplier just as their annual SAQ renewal came up. Everything on their end was spotless. Cyber Essentials reissued under the new Danzell requirements? Done in June. Cloud-wide MFA, tighter patch windows, and social media brought into scope? All checked off. It was a textbook example of strong governance—someone on their team had been meticulously prepping for these changes since April. 

Talk turned to one of their Tier 2 suppliers, a small engineering firm sitting deep in the build of record on a live contract. Their CE certificate, issued in February 2026 under the outgoing Willow set, was comfortably inside its validity window, not due for renewal until February 2027. Nobody there had heard of Danzell.

The baseline had already moved. MFA, patch windows, social media scope, all tightened in April. But nothing had told that Tier 2 supplier it had moved. Their certificate was still on the wall, still valid, still true to the standard it was issued against. Just not the standard that now applied.

Twelve months sounds like plenty of runway. It isn’t, if the ground shifts under you and nobody tells you it happened.


What Danzell moved

The Cyber Essentials question set moved from Willow to Danzell on 27 April 2026, via NCSC and IASME. A certificate issued under Willow stays valid until it expires. Nobody gets failed retroactively. But the moment that certificate comes up for renewal, the assessment runs against Danzell, and there’s no grace period for saying you didn’t know.

Three changes matter more than the rest, because for the first time in the scheme’s history, getting them wrong doesn’t cost you marks. It fails the whole assessment outright.

MFA is now mandatory across every cloud service the business runs on, not only email or the identity provider: storage, CRM, project tools, file-sharing, any SaaS in regular use. Companies switched MFA on for Microsoft 365 or Google Workspace two years ago and stopped there. The tools they’ve added since have crept in without the same discipline, and under Danzell that’s no longer a deduction. It’s a fail.

High-risk and critical patches have needed applying within 14 days since before Danzell. That part hasn’t moved. What’s changed is what happens if you miss it. Under Willow, a missed patch was a major non-compliance, and you were allowed up to two of those and still pass. Under Danzell, it’s an automatic fail. No second non-compliance to absorb it. No partial credit. One missed high-risk patch outside the window, on any in-scope asset, and the whole assessment fails. For a mid-market supplier without a mature patch management process, this is the change most likely to catch them out, not because the deadline got shorter, but because the safety net that used to cover the odd miss is gone.

Business-used social media accounts are explicitly in scope for the first time. If your company runs LinkedIn, X, Instagram, YouTube, or anything else on behalf of the business, those accounts sit inside CE scope now. MFA on the login, controlled access, a documented list of who has admin rights. If a marketing intern set up a Buffer login in 2024 with a shared password, that’s a finding today.

There’s more in the question set. But those three are the ones that catch suppliers who assumed a renewal would be a formality, because for most of them, it always has been, right up until it wasn’t.


The baseline moves. Nobody sends a memo.

Cyber Essentials has moved twice in the last two years alone. Montpellier to Willow in April 2025. Willow to Danzell in April 2026. DEFSTAN 05-138 moved from Issue 3 to Issue 4 in November 2025, clarified further by ISN 2026/01 on Cyber Security Model scope. CSMv4 replaced CSMv3 that December, formalised by ISN 2025/07, which came into effect at 00:01 on 3 December 2025 and revoked every interim arrangement that came before it. Each of those tightened requirements. None of them are exceptions. This is roughly what a defence supplier should expect every twelve to eighteen months, indefinitely.

None of it comes with a notification that reaches three tiers down a supply chain. IASME publishes the new question set. NCSC and MOD publish the standard and the ISN. Primes are expected to track it, because their own contract depends on it. Tier 1 suppliers mostly do, because primes chase them. By the time you’re at Tier 2 or Tier 3, several steps removed from anyone actually reading DSIT and IASME bulletins, the update either reaches you through a diligent prime, or it doesn’t reach you until your own renewal forces the question.

That’s not a compliance failure. It’s a structural gap in how the baseline moves. The standard ratchets upward on a predictable cycle, formalised in documents most Tier 2 and Tier 3 suppliers have never opened. Awareness of that movement doesn’t travel on the same cycle. It travels on whoever happens to ask.


Flow-down is where this gets commercial

DEFCON 658 carries flow-down. If you’re the prime, you’re responsible for the assurance of your sub-contractors. Tier 2, Tier 3, all the way down the build of record for anything that touches MOD identifiable information. ISN 2026/02 sets DCC as the recognised route to evidence that assurance under DEFCON 658, but most suppliers below the DCC threshold are still proving it through CE plus SAQ, which puts them back on the awareness problem above.

Awareness doesn’t travel down that chain on its own. Contractual accountability does. That mismatch is what turns a Tier 3 supplier’s blind spot into your problem. Their contract is with you, not the MOD. When their renewal finally forces the question and they’re not ready, it’s your SAQ that’s short an answer. Your contract that gets flagged.

In practice, I see three ownership gaps that let this happen.

The first is that supplier assurance sits with procurement, and procurement treats CE as a tick-box. Certificate on file, valid dates, done. Nobody in procurement is reading which question set the certificate was issued against, or asking whether that supplier has a plan for what comes at their next renewal.

The second is that the Flow Down Risk Assessment inside SCPS isn’t being completed at the tier where the actual risk lives. Primes run the RA on their direct suppliers and stop there. The sub-contractors below that layer aren’t visible in the assurance picture at all.

The third is that Cyber Improvement Plans can be a way of putting things into the long grass. A CIP needs a remediation date, but nobody’s checking that date against the contract end date. I’ve seen plans written with a timeline that runs past when the contract itself expires. Technically compliant. A documented plan, a date on the form. Functionally, a way of making a gap disappear from this year’s SAQ without ever closing it.


Field guide: what to look for

Red flags in your supply chain right now:

  • Any CE certificate issued before 27 April 2026 with no renewal date scheduled and no plan for Danzell ahead of it
  • MFA applied only to email and identity, not to cloud storage, CRM, or project tools
  • Social media accounts running under shared logins or without MFA
  • Patch cycles tracked over 14 days for high-risk vulnerabilities
  • Sub-suppliers without a completed Flow Down RA on SCPS
  • No Cyber Improvement Plan on file for any sub-supplier known to be behind, or a CIP whose remediation date runs past the contract’s own end date

What good evidence looks like:

  • Sub-suppliers’ CE renewal dates known and tracked, with Danzell prep scheduled ahead of each one
  • MFA documented across every SaaS platform the business uses, not just email and identity
  • Sub-contractor Flow Down RA completed and submitted via SCPS
  • CIP in place with a documented remediation timeline that closes before the contract ends
  • Patch management evidence showing 14 day windows are being met for high-risk items

Self-assessment checklist

Work through this. Yes or no on each.

Our own CE status:

  1. Do we know our CE certificate’s renewal date, and have we started preparing for Danzell ahead of it?
  2. Is MFA switched on across every cloud service the business uses, not only email?
  3. Are we tracking high-risk patches to a 14 day window with evidence?
  4. Are our business social media accounts inside CE scope with documented access controls?

Sub-supplier visibility:

  1. Do we have a live list of every sub-supplier below Tier 1 that touches MOD identifiable information on our contracts?
  2. Do we know the CE certificate issue date and renewal date for each of them?
  3. Have we told them Danzell exists, and asked what their plan is?

Flow-down documentation:

  1. Has a Flow Down Risk Assessment been completed on SCPS for each sub-supplier inside scope?
  2. Where a sub-supplier is behind on Danzell, is there a Cyber Improvement Plan on file with a documented timeline that finishes before the contract does?
  3. Do we have a named owner inside our business for supplier cyber assurance, not procurement, not IT, one accountable person?

If you’re answering no to more than two of these, the gap is already there. You just don’t know where yet.


What the next 90 days require

I’m not going to frame this as a compliance list. The compliance list is the checklist above and it’s doing its job.

The decision sitting on the CEO’s or COO’s desk is whether the supply chain assurance picture they’d put in front of a customer during a bid, or an auditor during a contract review, would actually hold up, not just look defensible on paper.

Because the risk here isn’t a fine or a finding. It’s a bid that gets marked down because your assurance evidence doesn’t match the current bar. It’s a Tier 2 supplier discovering at their own renewal, with no runway left, that the standard moved eighteen months ago and nobody told them. It’s a customer relationship that gets uncomfortable because they asked a straightforward question and the answer was, we didn’t know that had changed.

The baseline will move again. Probably within the next twelve to eighteen months, on roughly the same cycle it always has. The suppliers who get caught out next time won’t be the ones who ignored the standard. They’ll be the ones nobody told.

The work is knowing every CE renewal date in your supply chain, not just your own. Getting the Flow Down RAs completed at the tier where the risk actually lives, not just the tier that’s easy to see. Putting CIPs in place before a renewal forces the conversation, not after, with a remediation date that actually closes before the contract does. And making one person accountable for that picture, rather than three functions each holding a piece of it and assuming someone else is watching the calendar.


Reference List

  • ISN 2026/01 – Update to DEFSTAN 05-138 (Issue 4) covering narrative: Clarification to Cyber Security Model scope (number confirmed via title match on gov.uk index; exact numbering to be cross-checked against the ISN register before publication)
  • ISN 2025/07 – Implementation of CSM (v4) and revocation of interim measures in support of DEFCON 658; dated 26 November 2025, effective 00:01 GMT 3 December 2025
  • ISN 2026/02 – Use of Defence Cyber Certification (DCC) as assurance of control requirements under DEFCON 658
  • DEFSTAN 05-138 Issue 4 – in force 3 November 2025, replacing Issue 3
  • DEFCON 658 – Cyber Flow Down contractual condition
  • Cyber Security Model v4 (CSMv4) – mandatory from 3 December 2025
  • Cyber Essentials Danzell question set (v3.3) – effective 27 April 2026, replacing Willow (v3.2, effective 28 April 2025), which replaced Montpellier
  • Supplier Cyber Protection Service (SCPS) – hosts SAQ and Flow Down Risk Assessment tooling

Discover more from Acceptable Risk (Documented)

Subscribe now to keep reading and get access to the full archive.

Continue reading