Access Control and Cyber Essentials UK: A Complete Guide for 2026

17 August 2026

Learn how access control aligns with Cyber Essentials UK requirements. Practical steps for businesses to secure accounts, devices, and data in 2026.

What Does Cyber Essentials Require for Access Control?

Cyber Essentials, the UK government-backed certification, focuses on five core technical controls. Access control features heavily, specifically through the management of user accounts and administrative privileges. The scheme requires that you uniquely identify each user, remove default or guest accounts, and ensure accounts are only granted the permissions needed for their role. For Cyber Essentials, you must also disable or delete accounts when staff leave. This means having a clear user access policy that aligns with the principle of least privilege. In 2026, the standard remains the baseline for many UK public sector contracts, so getting access control right is not just good cybersecurity—it's a business requirement.

Setting Up Standard User Accounts for Compliance

A key step for Cyber Essentials is separating standard user accounts from privileged accounts. Every staff member should log in with a standard account for everyday tasks like email and web browsing. Standard accounts should not have local admin rights on their own machines. This prevents malware from spreading with elevated privileges. In practice, you should create a separate account with administrative rights only for IT tasks, and even then, only when needed. For UK SMEs, this often means configuring Windows or macOS devices so that the daily user account is a standard user. Cyber Essentials examiners will look for evidence that admin accounts are not used for routine work.

Managing Admin Rights and Privileged Accounts

Under Cyber Essentials, control of administrative accounts is a critical audit point. You need to identify all accounts with admin rights, both local and network-level, and justify each one. For example, only IT staff who install software or change settings should have admin accounts. These accounts must have stronger passwords and be separate from standard user accounts. In 2026, consider using a dedicated browser for admin tasks to reduce risk. Also, ensure that remote access to admin accounts uses multi-factor authentication (MFA), even though MFA itself is not yet a mandatory Cyber Essentials control. Regular audits of these privileged accounts are essential to maintain compliance.

Implementing Password and MFA Best Practices

While Cyber Essentials currently requires strong password policies rather than mandatory MFA, combining both is highly recommended. For access control, create unique passwords for each account, avoid predictable patterns, and enable MFA wherever possible—especially for cloud services and email. UK businesses are increasingly using passkeys and authenticator apps as part of their access strategy. For Cyber Essentials certification, your password policy must meet specific criteria, such as minimum length and complexity. However, the standard now suggests that MFA is a key compensating control. If you're a UK business aiming for Cyber Essentials Plus, incorporating MFA early can ease the audit process.

Reviewing Access Rights and Removing Leaver Accounts

Access control is an ongoing process. Cyber Essentials requires you to review user accounts regularly—usually at least quarterly. This includes checking that active employees have the correct permissions and that no dormant accounts remain. When someone leaves, you must revoke access immediately. In the UK, this often happens too late, increasing the risk of data breaches. Set a clear leaver process: disable the account on the day of departure, retrieve equipment, and reset credentials shared by the team. Document these reviews and keep audit trails. If you're using software like Microsoft 365 or Google Workspace, generate access reports and store them as evidence for your Cyber Essentials assessment.

FAQ

Yes, access control is a core part of Cyber Essentials. The scheme requires you to manage user accounts securely, remove unnecessary accounts, and ensure users have appropriate permissions. This includes controlling administrative rights. The exact controls are outlined in the Cyber Essentials Requirements and are essential for certification.

Latest guides