The annual screenshot problem
October is Cyber Security Awareness Month, and for many IT teams it is also the month someone asks: "When is our Cyber Essentials renewal due?"
What follows is familiar. A spreadsheet of devices that may or may not be complete. Screenshots of firewall settings and antivirus dashboards. A scramble to confirm every laptop is patched. A questionnaire answered from memory and good intentions.
The certificate arrives. Then, for the next eleven months, nobody looks at any of it again — until the auditor, the insurer or the customer asks, or until an incident shows that the controls had quietly drifted.
The problem is not the standard. Cyber Essentials is deliberately simple. The problem is treating a set of continuous controls as an annual event.
What changed with Cyber Essentials v3.3
Since 27 April 2026, new assessments use version 3.3 of the requirements and the Danzell question set, which replaced Willow. The changes are small on paper and significant in practice:
- MFA on cloud services is now an automatic fail if missing. Where a cloud service offers multi-factor authentication — free, bundled or paid — it must be enabled for every user and administrator. It is no longer something you can fix during the assessment.
- Cloud services are formally defined and cannot be excluded from scope. Email, finance systems, CRM, HR platforms and business social media accounts all count.
- More detailed questions about your cloud service inventory, MFA implementation and patching evidence.
Put simply, Danzell asks you to know exactly what you use and to show that the controls are actually in place. That is an inventory and evidence problem as much as a security one.
The five controls, and where continuous evidence comes from
Cyber Essentials covers five technical control areas. Here is how the Echo-9 stack — Wazuh for security monitoring, GLPI for assets and service management — turns each from a yearly check into something you can evidence any day of the year.
1. Firewalls
The requirement: boundary firewalls and host firewalls protect every in-scope device, with default passwords changed and unnecessary services blocked.
Continuous evidence: Wazuh's configuration assessment checks that host firewalls are enabled on endpoints and alerts when they are switched off. Firewall and router logs can be collected and analysed centrally. GLPI network discovery keeps an inventory of boundary devices — the routers, firewalls and gateways the NCSC's recent advisory highlighted as a growing target.
2. Secure configuration
The requirement: remove unnecessary software and accounts, change default credentials, and disable auto-run.
Continuous evidence: Wazuh Security Configuration Assessment audits systems against CIS benchmarks and reports each failed check against each device. GLPI's software inventory shows what is installed across the estate, so unapproved or unnecessary software is visible rather than assumed.
3. Security update management
The requirement: software must be licensed and supported, and high-risk or critical updates applied within 14 days of release.
Continuous evidence: Wazuh vulnerability detection scans installed software for missing patches and known CVEs. When those findings create GLPI tickets, the 14-day window becomes an SLA you can measure and report on — not a hope. GLPI's inventory also shows unsupported operating systems and software nearing end of life before they become a failed question.
4. User access control
The requirement: accounts are managed, administrator privileges are restricted, and — under Danzell — MFA is enabled on every cloud service that offers it.
Continuous evidence: Wazuh analyses authentication logs, flags use of administrator accounts and alerts on new account creation. GLPI can hold your register of cloud services, owners and MFA status, which is exactly the inventory the Danzell questions probe. Our Pwned plugin adds breach monitoring, so you know when a user's credentials have appeared in a third-party breach.
Wazuh cannot switch MFA on for you. What the stack gives you is a maintained list of every cloud service in scope, who owns it, and whether MFA is enforced — so the automatic fail never comes as a surprise.
5. Malware protection
The requirement: anti-malware is active and up to date, or applications are restricted to an approved list.
Continuous evidence: Wazuh detects malware, rootkits and suspicious behaviour, monitors changes to critical files, and can collect alerts from existing endpoint protection such as Microsoft Defender. When a device stops reporting, that becomes a ticket rather than a gap nobody notices.
Closing the loop: findings become work
Detection only matters if something happens next. In the Echo-9 stack, Wazuh findings create GLPI tickets automatically, linked to the device record and its owner. A failed configuration check becomes a task. A critical vulnerability becomes an incident with a 14-day target. A disabled firewall becomes a change to investigate.
That creates something annual screenshots never can: an audit trail showing that issues were detected, assigned and resolved, with timestamps.
Scope: knowing what is in the assessment
Every Cyber Essentials assessment starts with scope — which devices, users, networks and cloud services are covered. It is also where most organisations are least confident.
GLPI's inventory answers that question from live data. Wazuh agents sync with GLPI device records, the GLPI Agent inventories endpoints and network devices, and cloud services can be recorded with owners and contracts. When the questionnaire asks how many laptops, servers and cloud services are in scope, you run a report instead of starting a spreadsheet.
What this looks like in practice
One of our customers, a national health charity with 50 staff and no dedicated IT team, needed Cyber Essentials to keep its government grants. Before Echo-9, IT ran on spreadsheets and a neglected free-tier monitoring tool.
With a managed GLPI, Zabbix and Wazuh stack generating compliance evidence as part of normal operations, their Cyber Essentials audit preparation fell from more than two weeks to two hours.
Beyond Cyber Essentials
Cyber Essentials is a foundation, not a ceiling. The same evidence — asset inventory, configuration assessment, vulnerability management, access monitoring and incident records — supports Cyber Essentials Plus, ISO 27001, NIST and GDPR accountability. Build the evidence once, and reuse it for every framework that asks the same underlying questions.
The bottom line
Compliance you prove once a year is compliance you hope you still have.
Danzell raised the bar on knowing what you use and proving that controls are in place. Wazuh and GLPI turn Cyber Essentials from an annual evidence hunt into a daily view of your security posture — with every gap becoming tracked work, not a surprise at renewal.
Talk to us about Cyber Essentials readiness
Echo-9 offers Wazuh subscriptions from Standard (deployment, agent configuration and compliance monitoring) through Advanced (full SIEM and XDR) to Enterprise (the full integrated stack with GLPI and Zabbix).