Cyber Essentials Access Control: UK Guide for 2026
17 August 2026
Learn how to meet Cyber Essentials access control requirements. A practical UK guide to user accounts, permissions, and MFA for 2026.
What is Access Control in Cyber Essentials?
Access control is one of the five core technical controls in the UK Cyber Essentials scheme. It ensures that only authorised people can access your systems and data. This means managing user accounts, setting appropriate permissions, and limiting administrative rights. The goal is to reduce the risk of unauthorised access, whether from outside attackers or internal mistakes. For UK businesses seeking Cyber Essentials certification, access control is essential to proving that your organisation takes data protection seriously. It also aligns with the NCSC's guidance and GDPR expectations, making it a foundational step for robust cyber hygiene.
Key Requirements for User Accounts and Permissions
Under Cyber Essentials, every user must have a unique account. This ensures that actions can be traced back to an individual. Shared or generic accounts are not permitted for core services. Permissions should be granted on a least-privilege basis: users only get access to the data and systems they need for their role. Accounts for former employees or contractors must be disabled immediately. You should also review user access regularly, especially when roles change. The IASME, which manages Cyber Essentials, expects you to document these processes. Implementing a formal user access review every 30 to 90 days is a practical way to stay compliant.
Managing Administrator Accounts Effectively
Administrator accounts have elevated privileges, so they are a prime target for cyber criminals. Cyber Essentials requires you to limit the number of administrative accounts to only those who genuinely need them. These accounts should be separate from standard day-to-day user accounts. For example, staff should log in with a standard user account for email and browsing, and only use an admin account when performing tasks like installing software or changing system settings. This separation reduces the impact of a compromised normal account. Additionally, you should disable the built-in 'Administrator' or 'root' account in favour of named admin accounts, and enforce strong, unique passwords with multi-factor authentication.
Implementing Multi-Factor Authentication (MFA)
Cyber Essentials now requires multi-factor authentication (MFA) for all accounts that support it, especially for cloud services, remote access, and administrative accounts. MFA adds a second layer of verification, such as a one-time code from an authenticator app or a hardware token, making it much harder for attackers to break in. In the UK, many businesses use platforms like Microsoft 365 or Google Workspace, which offer MFA natively. Ensure that MFA is enabled for all external-facing services and for any privileged access. If a system does not support MFA, you may need to apply compensating controls or document why it is not feasible. Regular testing of your MFA setup is also recommended.
Common Pitfalls and How to Avoid Them
A common pitfall is providing users with more access than they need, which expands your attack surface. Another is forgetting to revoke access when employees leave—this is a frequent issue found during Cyber Essentials audits. Also, many businesses overlook the use of default passwords on routers, printers, and other devices. To avoid these issues, create an asset inventory and map user access to it. Use a password manager to generate and store unique passwords. Implement a formal offboarding process that includes immediate account removal. Additionally, consider using a privileged access management solution. Regular internal audits and staff training can help reinforce good access control habits across your organisation.
FAQ
Yes, as of January 2024, Cyber Essentials requires multi-factor authentication (MFA) for all cloud accounts, remote access solutions, and admin accounts that support it. If MFA is not available, you must document compensating controls. For UK businesses, enabling MFA on services like Microsoft 365 is straightforward and significantly improves your security posture.