Skip to main content

Cyber Essentials Willow vs Danzell: what changed in the CE+ remediation process?

Cyber Essentials Willow vs Danzell: what changed in the CE+ remediation process?


​

Cyber Essentials Willow vs Danzell: what changed in the CE+ remediation process?

Danzell is the new Cyber Essentials question set replacing Willow as part of the April 2026 update. The five technical controls stay the same, but the Cyber Essentials Plus (CE+) remediation process has changed. This guide explains what the new double sampling process is and how it works.

The main change is the introduction of a formal second sample where missing updates are found during testing. This is what many people refer to as “double sampling”. In simple terms, the assessor can now use one sample to identify the issue and, if required, a second sample to check that the remediation has been applied across the wider scope of the assessment.

The purpose of this process is to confirm that remediation has been applied consistently across the certified scope - not just to the originally tested devices.

Why was this introduced?

IASME introduced this change after identifying cases where organisations were applying updates only to the devices in the original sample, rather than fixing the issue across the full certified scope. The second sample is designed to confirm that remediation has been carried out across the whole environment and that high and critical updates are being applied within the required 14-day window.

How does the double sampling process work?

1. Sample 1 is tested

The assessor tests a random sample of in-scope devices, known as Sample 1. If all devices in Sample 1 are compliant, CE+ can be awarded. If any devices are missing required updates, CE+ cannot be awarded at that stage.

2. Remediation must be completed across the full scope

If issues are found in Sample 1, you have 30 days from the date of the audit to complete remediation (as long as you are still within 3 months of your CE issue date). Once remediation is complete, the Assessor will test Sample 1 again. If relevant updates are still missing after the 30 day remediation window, you will fail the CE+ assessment, and the CE certificate will also be revoked.

3. Sample 2 is then selected and tested

Where vulnerabilities have been found in Sample 1, the assessor will select a second random sample, known as Sample 2. The timing of the second sample will be agreed between you and the auditor, and will normally be after your auditor has confirmed that the issues found in Sample 1 have been resolved.

This second sample must use the same sample-size calculation as Sample 1 and can be shared with you no more than three working days before testing.

4. The result of Sample 2 determines the outcome.

If all the high and critical vulnerabilities older than 14 days initially identified on Sample 1 are remediated on Sample 2, this section of the assessment can be passed.

If Sample 2 contains the same vulnerabilities that were identified in Sample 1, and are not patched within 3 days of sharing the Sample 2 devices, a Sample 2 vulnerability scan will be performed on day 3 to confirm patches have been applied across the estate.

If you can not prove that patching has been applied across the full scope of the assessment, you may fail CE+ and the CE Verified Self-Assessment certificate will be revoked.

If Sample 2 contains different vulnerabilities that were not identified in Sample 1, you can still pass CE+ but will receive an advisory to address those issues. If you refuse to agree to Sample 2 being tested, the Cyber Essentials VSA will remain in place,but CE+ certification can not be awarded.

What if I only have a limited device count?

If your total number of devices is small, the second sample should be made up of any remaining devices that were not part of the first test. If all devices were already included in the initial sample, the assessor will re-scan the full sample set to confirm that the missing updates have been applied and that no new vulnerabilities have been introduced.

If you need further support in understanding this requirement, please reach out to support@cybersmart.co.uk and we will be glad to assist you.

Did this answer your question?