Fix it now
The scheme names capabilities rather than products, and Microsoft Defender Antivirus satisfies the malware control at no extra cost. What reliably costs money is the requirement that everything in scope is licensed and supported, plus a way to apply and evidence a configuration baseline on every device rather than device by device.
- Turn on Microsoft Entra security defaults before buying anything. MFA on cloud services is mandatory under the current question set and an auto-fail if missing.
- Price replacement or Extended Security Updates for anything past end of support first. Windows 10 Home and Pro ended on 14 October 2025, and unsupported software must be removed or isolated.
- Skip consumer ESU for company machines: Microsoft states it cannot be used in commercial scenarios and is not offered for domain-joined or MDM-enrolled devices.
- Buy device management rather than another security product when the gap is evidence. Meeting a control and proving it on every machine are different problems, and the second is what costs money.
- Skip the identity upgrade until you need rules rather than a switch. Conditional access needs Microsoft Entra ID P1, which Microsoft 365 Business Premium includes.
- Check the 14-day patching window is achievable before booking the assessment. Critical and high-risk fixes – CVSS v3 of 7 or above – are due within 14 days of release, and are auto-fail.
If everything is supported and security defaults are on, you may already be close. Below is each control translated into a buying decision, what the support requirement really costs, and where the free route genuinely suffices.
Why it happens
The scheme has five technical controls – firewalls, secure configuration, security update management, user access control and malware protection – and the current wording matters, because it changed recently. The question set in force is Danzell, published on 13 February 2026 and live from 26 April 2026, alongside version 3.3 of the Requirements for IT Infrastructure. Confirm you are working against that edition rather than an older summary, because two things became auto-fail criteria in it.
The first is identity. The requirement is that multi-factor authentication is implemented where available and that authentication to cloud services must always use MFA. That is not an aspiration in the current wording, and Microsoft Entra security defaults will satisfy it at no licence cost: they require every user to register for MFA, require it of administrators, block legacy authentication and block device code flow, on the base identity tier. If nobody in your organisation has ever been prompted for a second factor, closing that gap is a configuration exercise rather than a purchase.
The second is patching speed. Updates for vulnerabilities rated critical or high risk – a CVSS v3 score of 7 or above – must be applied within 14 days of release, and the two new security update questions are auto-fail. That is a process requirement rather than a licensing one, but it interacts with licensing at the point where a product no longer receives fixes at all.
Which is where the money goes. The requirements state that all software in scope must be licensed and supported, and that unsupported software must be removed from scope or isolated from internet access. That turns a compliance question into a purchasing one faster than anything else on the list. Windows 10 Home and Pro reached end of support on 14 October 2025 – not the end of a mainstream phase with an extended one behind it, but the end of support – so any machine still running it needs upgrading, replacing, enrolling in Extended Security Updates, or genuinely removing from scope. Isolation is harder than it sounds and assessors examine the claim closely.
Malware protection is the control that most often gets over-bought. The requirement can be met either with anti-malware software configured to prevent malware running and to block malicious websites, or with application allow-listing that restricts execution to approved, code-signed applications. No product is mandated, and Microsoft Defender Antivirus meets the description at no extra cost. What a paid product adds is central management and evidence – which matters far more for the audited tier and for insurer questionnaires than for the control itself.
That distinction, between satisfying a control and evidencing it, is where budgets actually go. A small estate can meet every control with built-in tools and manual checks. What it usually cannot do is show an assessor, at short notice, that the settings are applied consistently on every device. That is what management tooling buys, and it is why organisations pursuing certification tend to move up a plan tier rather than buy a security add-on.
Full reference
Five controls, translated into a buying decision
| Control | What it asks for | Satisfied at no extra cost by | What you may need to buy |
|---|---|---|---|
| Firewalls | A configured firewall at the boundary and on each device | Windows Defender Firewall and your router or gateway | Central enforcement and evidence of the policy |
| Secure configuration | Default accounts and unnecessary services removed, devices hardened | Manual configuration on a small estate | Device management to apply and prove a baseline |
| Security update management | All software licensed and supported; critical and high-risk fixes inside 14 days | Windows Update and Microsoft 365 update channels | Replacement licences or ESU for anything out of support |
| User access control | Separate administrator accounts, least privilege, MFA always on cloud services | Microsoft Entra security defaults, base identity tier | Microsoft Entra ID P1 where risk or device-based rules are needed |
| Malware protection | Anti-malware software, or application allow-listing | Microsoft Defender Antivirus, included with Windows | A managed console where you must evidence coverage |
| Asset and scope definition | Knowing which devices and accounts are in scope | Your own inventory | Nothing, but the inventory must exist and out-of-scope areas must be documented |
| Home and personal devices | In scope where they access organisational data | Policy and app-level controls | Company hardware, or cloud desktops, where policy is not enough |
Scope: which devices you are actually paying to fix
Scope decides the size of the bill, and the current requirements are more specific than the usual summary. User-owned devices that access organisational data or services are in scope. Devices used only for native voice and text applications, or only to receive a multi-factor authentication code, are excluded – which is a genuinely useful exemption for phones that never touch mail. For home workers, a router the organisation provided is in scope; a personal router is not, but the device’s own firewall controls then have to carry the requirement instead. Read those exclusions before pricing hardware, because they can remove a whole category of device from the exercise.
Support status is a licensing problem wearing a compliance hat
There are three honest responses to an unsupported system: upgrade it, buy extended security updates where the vendor offers them, or segregate it so completely that it is genuinely out of scope. For Windows 10 the routes are published and they are not interchangeable.
| Route | Who it is for | How long it lasts | The catch |
|---|---|---|---|
| Upgrade to Windows 11 | Any device that meets the requirements | The Windows 11 lifecycle | Hardware that does not qualify has to be replaced |
| Commercial Extended Security Updates | Commercial and educational organisations, through volume licensing | A maximum of three years after end of support, with Year One starting November 2025 | Priced per device and per year; it buys time, not a solution |
| Consumer Extended Security Updates | Individuals only | Until 12 October 2027 | Microsoft states it cannot be used in commercial scenarios, is not offered for domain-joined or MDM-enrolled devices, and is suspended if a device later joins a domain or an MDM |
| Move the desktop to the cloud | Machines that cannot be upgraded but whose workload can move | While the cloud desktop is licensed | ESU is included at no extra cost for Windows 10 VMs in Windows 365 and Azure Virtual Desktop |
| Isolate it | A machine that genuinely needs no network path | As long as the isolation holds | Assessors test the claim; segregation is harder than it looks |
The same logic applies to everything else with a published end date. Office LTSC 2024 is supported to 10 October 2029. Windows Server 2025 reaches end of extended support on 15 November 2034. Put those dates in the same sheet as your renewal dates, because the update control does not care why something is out of support.
Identity: what is free and what is not
Security defaults are the free route and they are enough for the control as written. What they cannot do is vary the requirement: they are a switch, applied to everybody, with no exceptions and no tuning. Conditional access – blocking sign-in from unmanaged devices, requiring a compliant device for particular data, or excluding legacy authentication selectively – needs Microsoft Entra ID P1, and Microsoft documents that Business Premium customers can use it. Risk-based policies that react to a suspicious sign-in need Entra ID P2, which neither tier includes.
One thing has already been decided for you. Microsoft now requires multi-factor authentication for sign-in to the Azure portal, the Microsoft Entra admin center, the Intune admin center and the Microsoft 365 admin center, and since 1 October 2025 for Azure CLI, Azure PowerShell, the Azure mobile app and infrastructure-as-code tooling. If your administrators are not yet using MFA, that is not a certification question any more.
Your buying list, by starting point
- Everything already supported and on a Microsoft 365 plan with the applications you need: switch on security defaults, document your configuration, and you may need to buy nothing at all.
- Machines past end of support: this is the first and largest line. Cost the upgrade or replacement before pricing anything else, and treat commercial ESU as bought time rather than a fix.
- Someone has suggested consumer ESU for the office: it is not available for that. Microsoft states it cannot be used in commercial scenarios and is not offered for domain-joined or MDM-enrolled devices.
- No central way to prove device configuration: device management is the purchase, not another security product.
- Personal devices in scope: check the exclusions first, then either bring the remaining devices into management or move the data onto company hardware or cloud desktops.
- Insurer asking about round-the-clock monitoring: that is a managed service, bought separately from any licence tier.
- Going for the audited tier: expect hands-on technical testing on a sample of devices, so fix the estate before booking it.
When a licence is the actual fix
For most small and medium organisations the licence that closes the certification gap is Microsoft 365 Business Premium, because the controls hardest to evidence are the ones it adds: Intune to apply and prove a configuration baseline, Microsoft Entra ID P1 for conditional access rather than passwords alone, and Defender for Business as a centrally managed endpoint layer with reporting behind it. Arco can map your current plan against the control list, say which items you already satisfy, and quote the upgrade for the users in scope rather than the whole tenant. Two things come first and cost nothing: turn on Microsoft Entra security defaults, which satisfies the MFA requirement outright, and confirm Microsoft Defender Antivirus is active and updating everywhere, which satisfies the malware control. The line that will cost real money is anything past end of support, so count those machines before you look at plans.
Questions people ask about this
Do we have to buy a third-party antivirus to certify?
No. The malware protection control can be met either with anti-malware software configured to prevent malware running and block malicious websites, or with application allow-listing, and no specific product is mandated. Microsoft Defender Antivirus meets that description at no extra cost. What a paid product adds is central management and evidence, which matters more for the audited tier and for insurer questionnaires than for the control itself.
Is multi-factor authentication optional if it is inconvenient?
Not under the current question set. The requirement is that MFA is implemented where available and that authentication to cloud services must always use MFA, and it is an auto-fail criterion. Microsoft Entra security defaults satisfy it at no licence cost. Separately, Microsoft now enforces MFA for administrator sign-in to the Azure and Microsoft 365 admin portals regardless of what you certify against.
Are personal laptops in scope?
Generally yes, where they access organisational data or services, and they must meet the same controls as company devices. There are exclusions worth reading: a device used only for native voice and text applications, or only to receive an MFA code, is out of scope, and a personal home router is out of scope provided the device’s own firewall controls carry the requirement. For the rest, the practical answers are company hardware, a cloud desktop, or restricting what personal devices can reach.
Can we use the consumer Windows 10 ESU programme for office machines?
No. Microsoft states plainly that the consumer ESU programme cannot be used in commercial scenarios, and enrolment is not offered for domain-joined or MDM-enrolled devices – a device that later joins a domain or an MDM has its consumer enrolment suspended. The commercial route is Extended Security Updates through volume licensing, available for a maximum of three years after end of support with Year One starting in November 2025. ESU is included at no extra cost for Windows 10 virtual machines in Windows 365 and Azure Virtual Desktop.
Will certification reduce our insurance premium?
Insurers treat it as evidence rather than as a discount, and each weighs it differently, so no supplier can promise a reduction. What is published is that UK organisations with turnover under 20 million pounds that certify the whole organisation are included in cyber liability insurance arranged by the scheme’s delivery partner, with incident response support. The consistent risk is the other way: answering a questionnaire inaccurately causes problems at claim time. Treat the controls as the point and the certificate as the record.
