Cyber Essentials User Accounts: What UK Businesses Must Do in 2026

17 August 2026

Practical UK guide to meeting Cyber Essentials user account requirements: admin access, passwords, MFA, and user lifecycle management.

Why Cyber Essentials Controls User Accounts

User accounts are the front door to your IT systems. Cyber Essentials includes user access control as a key component because compromised accounts are behind most cyber attacks. For UK businesses, this is about protecting customer data, meeting GDPR obligations, and demonstrating due diligence to clients and insurers. The scheme expects you to manage accounts systematically: only give people access to what they need, remove access when it's no longer required, and make it hard for attackers to guess or steal credentials. Getting this right not only helps you pass the certification but also reduces the likelihood of a costly breach. Think of user account management as a basic hygiene practice, not a one-off exercise.

Key Requirements for Admin Accounts and Access Control

Cyber Essentials places special emphasis on administrative accounts because these have elevated privileges. You must limit the number of admin accounts to only those who genuinely need them for their role. Avoid using admin accounts for everyday tasks like reading email or browsing the web. Instead, set up separate standard user accounts for routine work. For UK businesses, a common mistake is giving everyone local admin rights on their laptops. This is against the spirit of the scheme. You also need to ensure that any legacy or unused admin accounts are removed. Regular reviews of access rights, especially for cloud services and Microsoft 365, are essential. Document your process so an assessor can see you have control.

Password Policy and Multi-Factor Authentication (MFA)

Cyber Essentials does not dictate a rigid password complexity rule, but it expects you to use strong authentication. The NCSC recommends using 8 characters or more, avoiding predictable patterns, and using a password manager to generate and store unique passwords. For internet-facing user accounts, such as those for cloud platforms or remote access, you must enable Multi-Factor Authentication (MFA) if it is supported. In the UK, that means enabling MFA for services like Microsoft 365, Google Workspace, or any VPN access. MFA provides a second layer of protection: even if a password is stolen, attackers cannot easily get in. Ensure MFA is enabled on all user accounts, not just administrators, for services that hold sensitive data.

Creating and Removing Accounts: User Lifecycle Management

Managing user accounts from creation to deletion is a core Cyber Essentials control. When a new employee joins, you should create an account with the least privilege needed to do their job. When someone changes roles, review and adjust their access. When a person leaves, disable or delete their account promptly. Cyber Essentials requires you to remove accounts that are no longer needed, and you should aim to do this within 30 days of a person's departure. Also reconsider accounts for contractors, temp staff, and suppliers. In the UK, many certification failures are due to forgotten accounts belonging to former employees. Keep a central register of all accounts, and perform regular access reviews to spot anomalous accounts before they become a risk.

Common Pitfalls and How to Pass Your Assessment

Common issues UK businesses face include using default passwords, having shared accounts, and failing to audit external user accounts. To pass your Cyber Essentials assessment, you need to demonstrate that your user account controls are documented and actually enforced. Use a technical audit to verify that admin accounts are limited, passwords are not set to 'never expire' without justification, and MFA is enabled on all internet-connected services. Don't forget about service accounts and application accounts. Rename them to something non-generic and ensure their passwords are long and strong. Finally, have a clear policy for password changes and breaks in employment. By avoiding these pitfalls, you will make your certification process smooth and your business more secure.

FAQ

Cyber Essentials requires MFA to be enabled for user accounts on internet-facing services that support it. This includes cloud email, file sharing, and remote access solutions. If a cloud provider supports MFA, you must enable it for all users, not just admins. For local accounts or services that don't support MFA, you need to use compensating controls like a strong password policy and restriction of access.

Latest guides