Cyber Essentials Login Security: A Practical UK Guide for 2026

17 August 2026

Learn how to secure logins for Cyber Essentials compliance in the UK. Passwords, MFA, access control, and practical tips for certification.

What Cyber Essentials Says About Login Security

Cyber Essentials, the UK government-backed scheme managed by IASME and the NCSC, sets clear requirements for how your organisation controls access to systems and data. The core principle is that only authorised users should be able to reach your devices, software, and online accounts. In practice, this means implementing strong authentication methods, managing user accounts properly, and ensuring that any default or weak credentials are replaced. For many UK small businesses, login security is the biggest hurdle to achieving certification, but it's also the most valuable aspect. Getting it right protects your business from common attacks like password spraying and credential stuffing, which the NCSC consistently highlights as major threats to British firms.

Password Policies That Meet the Standard

Cyber Essentials does not prescribe a rigid password standard, but it requires you to have a policy that prevents easily guessable passwords. The NCSC advises using three random words to create a strong passphrase, which is both memorable and secure. Avoid using password complexity rules that force frequent changes, as this often leads to weaker habits. Instead, focus on banning common passwords, blocking breached passwords, and ensuring that no default passwords remain. For UK businesses, the easiest way to satisfy the scheme is to adopt a password manager, generate unique random passwords for each account, and enable a lockout policy after repeated failed attempts. These steps align with the Cyber Essentials control 5.1 and demonstrate good practice to an assessor.

Multi-Factor Authentication (MFA) Requirements

Since 2022, Cyber Essentials has required multi-factor authentication (MFA) for all internet-facing accounts that support it, particularly for cloud email and remote access. This is a significant shift from earlier versions. If your online services offer MFA, you must enable it for all users, including third-party contractors. In the UK, that means activating MFA on Microsoft 365, Google Workspace, and any VPN or remote desktop solutions. SMS-based verification is often allowed, but the NCSC recommends using app-based authenticators or physical keys like YubiKey for stronger protection. If a service does not support MFA, you must document a compensating control. Ensure your MFA setup covers admin accounts and break-glass accounts, and test that backup codes work before you need them.

Managing User Access and Admin Accounts

A common failing in UK businesses is leaving administrator privileges on standard user accounts. Cyber Essentials requires that each user has the minimum access needed to do their job. This means creating separate admin accounts for tasks like installing software or changing security settings, and using standard accounts for everyday activities. Regularly review user lists and remove accounts for leavers or contractors. For Windows devices, ensure that local admin passwords are unique per machine and stored securely. For cloud platforms, use role-based access control and limit who can access sensitive data. Keeping an up-to-date user access audit trail is essential for demonstrating compliance during a Cyber Essentials assessment or assessment for Cyber Essentials Plus.

Common Pitfalls and How to Avoid Them

Many UK businesses fail Cyber Essentials simply because they overlook login security details. One common pitfall is forgetting that routers and other network devices also have default login credentials. Change these immediately. Another is using shared accounts for multiple staff members; Cyber Essentials expects each person to have a unique login so that activity can be traced. Be careful with password expiry policies – the NCSC now says forced expiry is counterproductive, so focus on breach monitoring instead. Also, if you use legacy software that doesn't support MFA, don't just ignore it; either upgrade or apply strict compensating controls. Finally, ensure that staff are trained on phishing because attackers will target login pages to steal MFA codes. Regular testing and a clear security culture will keep you compliant.

FAQ

Yes. Since January 2022, Cyber Essentials requires MFA for all internet-facing services that support it, particularly cloud email and remote access. If a service lacks MFA, you must document compensating security measures. For most UK businesses, this means enabling MFA on Microsoft 365, Google Workspace, and VPNs using app-based authenticators or hardware keys.

Latest guides