Cyber Essentials Password Policy: UK Requirements & Best Practices (2026)
17 August 2026
Learn the exact password requirements for Cyber Essentials certification in the UK. Get practical tips on MFA, password managers and policy templates.
What Is the Cyber Essentials Password Policy?
Cyber Essentials is a UK Government-backed scheme that sets baseline security controls to protect organisations against common cyber threats. The password policy part of the framework focuses on how you authenticate users and manage credentials. Official guidance requires the use of strong passwords, PINs or passphrases for all accounts, and enforcement of account lockout or rate limiting to prevent brute-force attacks. It also mandates the use of Multi-Factor Authentication (MFA) for cloud services and user accounts that require administrative privileges. Unlike some standards, Cyber Essentials does not insist on periodic password rotation, but it does expect you to have a clear written policy and to educate staff on good password practices.
Key Requirements for Passwords and MFA
For Cyber Essentials certification, you must implement technical controls that prevent unauthorised access. This means setting a minimum password length of at least 8 characters, but the National Cyber Security Centre (NCSC) in the UK recommends using longer passphrases, such as three random words, which are easier to remember and harder to crack. Additionally, you need to enable Multi-Factor Authentication (MFA) for any cloud-based accounts and for all administrative or privileged user accounts. You must also configure account lockout after five failed attempts, or an equivalent anti-bruteforce mechanism, such as rate limiting or password throttling. These requirements apply to all staff, contractors, and third-party users with access to your systems.
How to Implement a Password Policy Using a Password Manager
The most effective way to comply with Cyber Essentials is to adopt a password manager. A password manager generates strong, random passwords for every account and stores them securely, so staff only need to remember one master password. When implementing a password manager, choose one that supports MFA for the master account and allows centralised administration. You should create a company policy that mandates the use of the password manager for all work-related accounts. Provide training to help staff understand how to use it and why reusing passwords is risky. Also, ensure that any legacy accounts or local administrator passwords are updated and stored in the manager. This approach satisfies Cyber Essentials' requirement for strong passwords and reduces the risk of credential theft.
Common Mistakes to Avoid in Your Password Policy
Many UK businesses fall short on Cyber Essentials by making simple mistakes. One common issue is allowing password expiry every 30–90 days. NCSC guidance and Cyber Essentials do not require forced rotation, and frequent changes often lead to weaker passwords or sticky notes on monitors. Another mistake is failing to enforce MFA for all users, not just administrators. Also, many organisations use blacklists of common passwords, but Cyber Essentials expects more – you should prevent users from selecting passwords that appear in known breach lists. Additionally, some policies allow password sharing for shared mailboxes or service accounts; instead, use individual accounts and delegate access. Finally, neglecting to document your password policy in writing is a common audit failure.
Next Steps: Build Your Policy and Get Certified
To get Cyber Essentials certified, you need to turn these requirements into a formal policy and prove its implementation. Start by downloading the official Cyber Essentials readiness toolkit from the NCSC or an accredited certification body. Write a simple password policy that covers password length, complexity, MFA, account lockout, and the use of password managers. Then, audit your current systems to ensure all accounts, especially admin accounts, meet the criteria. Fix any gaps before your assessment, and train your staff on the new policy. Finally, book your assessment with an accredited provider. Once certified, you can display the badge, win government contracts, and reduce your cyber risk significantly. Remember to review your policy annually and after any major IT changes.
FAQ
There is no fixed number set by the scheme, but the official guidance says you must implement a password policy that requires at least 8 characters. The UK's NCSC recommends using longer passphrases, for example three random words, which are stronger and more user-friendly. Your policy should be documented and enforced technically.