Cyber Essentials Access Control Checklist: UK Guide for 2026
17 August 2026
A practical UK-focused checklist to meet Cyber Essentials access control requirements. Manage user accounts, admin rights, MFA, password policies, and more in 2026.
Understand the Cyber Essentials Access Control Requirements
Before diving into the checklist, it's essential to know what Cyber Essentials expects from your business around access control. The scheme aligns with UK NCSC guidance, focusing on preventing unauthorised access to your systems and data. Key areas include user account management, administrative privileges, multi-factor authentication (MFA), and password security. For certification, you must show that only the right people have the right access at the right time. This means having a clear policy, documented processes, and technical controls in place. In 2026, the requirements also reflect the increased use of cloud services, making it critical to apply these controls across all your environments, not just on-premises.
User Account Management: Create, Review, and Remove
Start by creating a complete inventory of every user account on your network, including personal devices that connect to your systems. Each user should have a unique account – shared accounts are not allowed under Cyber Essentials. For each account, document the owner, purpose, and level of access. Set up a regular review process (at least quarterly) to check that access rights still match job roles. Remove accounts immediately for any user who has left the business. For temporary staff or contractors, set explicit start and end dates so accounts expire automatically. Don't forget to disable dormant accounts – these are a common entry point for attackers. Regularly refreshing your user list reduces the risk of privilege creep.
Admin Privileges: Limit and Protect
Administrative accounts are the keys to your kingdom, so you must restrict them aggressively. The principle of least privilege is central to Cyber Essentials: users should only have the admin rights they need to perform their specific job. Use separate admin accounts to reduce the likelihood of a user inadvertedly running with elevated privileges. Those admin accounts should have strong, unique passwords and should only be used for administrative tasks, not for daily checking of email or browsing the web. Implement a clear approval process for granting admin access, and conduct periodic audits to confirm who has these rights. In 2026, consider using Privileged Access Management (PAM) tools if your budget allows, but even a simple spreadsheet-based review process can meet the standard if followed diligently.
Multi-Factor Authentication and Password Policies
Multi-factor authentication (MFA) is mandatory for Cyber Essentials in 2026 for all user accounts that access cloud services, including email, file storage, and any remote access. Even if you're a small business, enabling MFA on Office 365 or Google Workspace is a straightforward step. For password policies, ensure you enforce a minimum length of 12 characters and avoid common or predictable passwords. The NCSC now advises against mandatory periodic changes unless there's a suspicion of compromise, so focus on encouraging strong passphrases and using a password manager to store them securely. Where MFA is not possible (e.g., on some legacy systems), compensate with additional controls, such as IP allow-listing or restrictive firewall rules. Document your policy and train staff to recognise phishing attempts.
Leavers, Contractors, and Third-Party Access
One of the most common gaps in access control is failing to remove access for departing employees. As part of your offboarding checklist, immediately revoke all accounts, tokens, and remote access credentials. If you use a HR system or IT ticketing tool, automate the offboarding workflow to trigger these revocations automatically. For contractors and third-party suppliers, define a clear access matrix in your contracts, and carry out due diligence on their security practices. Review third-party access at least every six months, and close any standing accounts that are no longer needed. Also, consider any devices that contractors might connect to your network – they should be treated as untrusted until verified. These steps protect your business from insider threats and reduce your Cyber Essentials audit risk.
FAQ
Access control in Cyber Essentials means managing who can access your systems and data. It covers user accounts, admin privileges, password policies, and multi-factor authentication. The goal is to prevent unauthorised access, both from external attackers and internal users with unnecessary rights. You need to document your approach and show that access is limited to those who genuinely need it for their role.