Cyber Essentials Password Requirements Explained

Written by Louise Ralston
Aug 18, 2026 - 4 minute read

Cyber Essentials mandates stronger authentication, including mandatory MFA, to combat sophisticated cyber threats. Learn how to meet evolving standards and prepare for a passwordless future.

Strong authentication has long been a cornerstone of good cybersecurity practice, but the expectations around it are rapidly changing. As attacks grow more sophisticated, it’s no longer sufficient to rely on old password practices. Cyber Essentials is evolving in response, placing greater emphasis on how organisations protect accounts.

For businesses looking to achieve or renew Cyber Essentials certification, then, the days of simple passwords and optional multi-factor authentication (MFA) are over. The standard is tightening and those who fail to adhere to it will lose out. But the right approach can ensure that strengthening authentication is neither complicated nor disruptive.

In this blog, we’ll discuss what Cyber Essentials now requires of organisations, how password policies fit into the picture and what the future of authentication looks like as password-less login methods gain in popularity and adoption.

 

Cyber Essentials, passwords and changing expectations

Cyber Essentials has always required organisations to demonstrate that their accounts are well-managed and protected, but recent updates to the standard mean authentication methods and account protections now play a decisive role in determining whether an applicant passes or fails.

Weak credentials, badly managed accounts and missing MFA can prevent an organisation from meeting requirements. As cyber-crime escalates, Cyber Essentials is resolute on this point. Outdated authentication, or a lack of basic controls like MFA, cause avoidable risks that must be addressed to pass.

Businesses also need to manage the full lifecycle of their accounts. In practice, this usually means developing a process of creating and approving accounts, as well as giving each user unique credentials, removing or disabling old accounts, and withdrawing privileges if a person changes role.

Cloud adoption, along with the rise of hybrid and remote working, has changed how users access systems. With more information stored online - and accessible anywhere - CE expects firms to have bolster their controls to prevent unauthorised access. So while password policies are still relevant, they are just one part of the equation.

 

Multi-factor authentication: now a critical requirement

Multi-factor authentication (MFA) is no longer just a nice-to-have. Under Cyber Essentials, it’s now mandatory for every cloud-based service that a business uses if the service supports MFA, whether natively or through a third-party single sign-on (SSO) service. On its own, a password is too easy to crack. Requiring a second factor drastically lowers the risk of accounts being compromised.

This has implications for businesses on cheaper software tiers, such as entry-level application plans that do not deliver MFA natively. While they might allow businesses to save money upfront, they may cause issues during a CE assessment if MFA is available only through an upgraded subscription or an SSO service.

The upshot of this is that businesses should choose software that supports MFA and avoid buying tools that fall short of basic security standards.

 

What good password hygiene looks like

Even with MFA in place, password quality is still critical. However, Cyber Essentials does not apply a universal eight-character minimum to every password-based account.

Where a password forms part of an MFA login, it must contain at least eight characters, with no maximum-length restriction.

For other password-based accounts, the organisation must use at least one of the following controls:

    • MFA;
    • a minimum password length of at least 12 characters, with no maximum-length restriction; or
    • a minimum length of at least eight characters, with no maximum-length restriction, combined with automatic blocking of common passwords through a deny list.

Longer, unique passwords generally provide greater protection than short passwords built around predictable character substitutions.

Contrary to traditional password advice, Cyber Essentials does not ask for a mix of uppercase and lowercase letters, numbers and special characters. In fact, its guidance says complexity rules often encourage people to adopt predictable patterns, such as replacing an “o” with a zero or adding an exclamation mark at the end.

 

Putting good password practice into action 

The National Cyber Security Centre (NCSC) often recommends using passphrases, such as three random words, to create lengthy yet memorable passwords.

Password reuse is another persistent problem. When one system is breached, attackers will inevitably try to use the same credentials across multiple platforms. Educating staff on safe password habits and providing tools such as password managers can reduce risk and facilitate CE compliance.

Password managers allow staff to generate and securely store a separate password for each account, which lowers the temptation to reuse credentials across business and personal services. Organisations need to give staff clear guidance on which password manager to use and how it should be used.

Cyber Essentials does not require passwords to be changed at regular intervals. Instead, passwords should be changed only when the organisation knows or suspects a password or account has been compromised.

Finally, enforcement of the above is critical in getting certified. Password policies should be applied consistently across all company devices and systems so no part of the network is left exposed by weaker or legacy settings.

 

Moving towards password-less authentication

There is a move away from passwords altogether; the latest Cyber Essentials requirements now give clearer recognition to passwordless authentication technologies. Passkeys, hardware tokens and physical security keys such as YubiKeys can offer far stronger protection than traditional credentials.

Full passwordless authentication won’t happen overnight, but businesses should begin exploring these methods now, particularly for privileged or administrative accounts where any compromise would be especially damaging. Preparing early will make the transition easier and will also make future Cyber Essentials updates simpler to adhere to.

 

What this means for you

Cyber Essentials is raising the bar, and has made authentication an explicit pass-or-fail area of assessment. For a first-time pass, business should avoid relying on outdated systems that lack adequate security and introduce MFA as a matter of course.

Start by reviewing every cloud service, user account and administrative account within the scope of your assessment. Confirm that MFA is enabled wherever it is available, remove accounts and privileges that are no longer required and make sure staff have a secure way to generate and store unique passwords.

Businesses that begin planning for a password-less future now will be far more future-proof as CE standards continue to expand. Those who modernise today will find certification a smoother and more straightforward process in the years ahead.

Is your business looking to attain or renew Cyber Essentials certification? Cyber Essentials is here to help. We work with businesses of all sizes to assist them get and remain certified. Get in touch with our expert team today for more information.

Topics: Cyber Essentials, Cyber Security, Passwords, 2MFA

author

More by Louise Ralston

Related articles
Cyber Essentials vs IASME Cyber Assurance: What’s the Difference and Which Do You Need?

Organisations need reassurance to trust other business with data, systems or supply chains. Recognised certification gives valuable evidence towards this.

Mobile Devices & Cyber Essentials: What's Required

Ensure your mobile devices comply with Cyber Essentials by using MDM or MAM, not just written policies, to mitigate risks and protect business data.

Is Cyber Essentials Worth It For Your Business?

Cyber Essentials is often seen as a box to tick for tenders, contracts or suppliers. But for many SMEs, it’s one of the simplest ways to find and fix the everyday cyber weaknesses attackers exploit.