Cyber Essentials User Access Control Requirements (2026 UK Guide)

17 August 2026

Understand the 2026 Cyber Essentials user access control requirements for UK businesses. Learn key rules, best practices, and compliance tips.

What Is User Access Control in Cyber Essentials?

User access control is a core component of the Cyber Essentials and Cyber Essentials Plus schemes, managed in the UK by IASME and backed by the National Cyber Security Centre (NCSC). It ensures that only authorised individuals can access your systems, data, and networks. For 2026, the requirements focus on managing user accounts, assigning appropriate permissions, and removing or disabling accounts when they are no longer needed. In practice, this means you must have a clear process for creating, reviewing, and deleting user accounts. The goal is to reduce the risk of insider misuse, credential theft, and lateral movement by attackers. Whether you have five employees or five hundred, access control must be consistently applied across all devices, cloud services, and on-premises systems.

Key Requirements for Standard User Accounts and Passwords

For standard user accounts, Cyber Essentials requires that you enforce a robust password policy. This means passwords should be unique to each account and system, with no shared or group accounts for critical services. Passwords must be stored securely, using salted hashes rather than plain text. UK businesses should adopt the NCSC's password guidance, which recommends using three random words and avoiding predictable combinations. You must also have a process for users to change passwords promptly if they suspect compromise. In 2026, the standard still expects you to disable accounts after a defined period of inactivity and to remove leavers' access within a reasonable timeframe, ideally within 24 hours of their departure.

Managing Privileged Access (Administrator Accounts) in 2026

Privileged access accounts are the highest risk, as they allow users to install software, change security settings, and access sensitive data. Cyber Essentials requirements for 2026 are explicit: administrators must have separate, named accounts for their admin role, distinct from their everyday user account. The use of generic admin accounts like 'admin' or 'root' is not permitted. Additionally, you must limit the number of privileged accounts to only those who genuinely need them, and review these accounts on a regular basis. Two-factor authentication (2FA) is mandatory for all administrative accounts, and in Cyber Essentials Plus, this is rigorously tested. Ensure that admin passwords are long and unique, and consider using a password manager with a secure vault.

Multi-Factor Authentication (MFA) and Modern Access Controls

Since 2022, Multi-Factor Authentication (MFA) has been a requirement for Cyber Essentials, and in 2026 it remains central to user access control. This applies to user accounts accessing cloud services or external-facing services, particularly those with access to sensitive personal data. MFA must use at least two different factors, such as a password and a one-time code from an authenticator app, or a hardware token. You should avoid SMS where possible, as it is less secure. For internal systems, MFA may be required for any remote access or for admin accounts. Businesses not yet using MFA should implement it immediately, as it blocks around 99.9% of modern automated attacks. Remember to also secure the recovery process for MFA to prevent bypass.

How to Demonstrate Compliance for Certification in 2026

To achieve Cyber Essentials certification, you must complete a self-assessment questionnaire that asks specific questions about user access control. For Cyber Essentials Plus, the technical controls are independently verified by an assessor. Be prepared to provide evidence of your account review processes, password policies, MFA usage, and leaver procedures. In 2026, the questionnaire may require you to confirm that you disable accounts for contractors after a project ends and that you restrict access to data based on job role. Keep logs of account reviews and ensure that your access control policies are documented and shared with your team. Many UK businesses use access management platforms to automate these controls, which makes evidence collection significantly easier come audit time.

FAQ

Cyber Essentials requires you to manage user accounts securely: use unique passwords for each user, enforce a strong password policy, disable accounts when someone leaves, and review accounts regularly. Administrative accounts must be separate, named, and use multi-factor authentication. You also need to ensure that users only have access to the data and systems they need for their role.

Latest guides