Essential cookies only — Cookie Policy.

Cyber Essentials

Cyber Essentials Password Requirements for SMEs

📅 10 May 2026·⏱ 8 min·✍ Rachel Morris

47% of UK businesses hit by a cyber attack in the last year had one thing in common: weak or compromised passwords. Cyber Essentials — the UK government-backed certification — exists to fix exactly this, and its password controls are where most first-time applicants lose marks. Here’s exactly what Cyber Essentials requires for passwords in 2026, and how to build a compliant password policy your auditor will pass first time.

What Cyber Essentials Actually Requires for Passwords

Cyber Essentials (run by IASME on behalf of the NCSC) doesn’t demand a 100-page policy document. It demands five technical controls — firewalls, secure configuration, access control, malware protection, and patch management — and three of them touch passwords directly:

Why is MFA the sticking point? Because a password alone is something an attacker can phish, guess, or steal in a data breach — and then replay from anywhere in the world. A second factor that the attacker doesn’t have (an authenticator app, a hardware key, a one-time code) stops that replay dead. That is why assessors now treat MFA as the expected standard for any account reachable over the internet, and why the technical control requirement effectively means: lockout or MFA for everything, and MFA for anything important.

Note: Cyber Essentials does not require a written password policy as a certificate gate — but the audit requires you to demonstrate the controls, and a short written policy is the cheapest way to evidence them.

The NCSC Password Rules Underneath It

Cyber Essentials maps to NCSC guidance, which has moved away from forced complexity toward three principles:

The 2021 update to NCSC’s password guidance was a deliberate departure from the old security-policy clichés: forced periodic rotation was dropped (it drives people to weaker, more predictable passwords), and complexity rules were de-emphasised in favour of length and uniqueness. Your Cyber Essentials policy should reflect the current guidance, not the 2015 playbook — an auditor who sees “change every 90 days” in your policy will ask whether the rest of it is current too.

A Compliant Password Policy Template (Copy-Paste)

Adapt this template to your staff handbook — it covers what Cyber Essentials assessors actually check:

  1. All user and admin accounts on internet-facing services MUST have a unique password, never reused on another service.
  2. Passwords MUST be at least 12 characters (16+ for admin accounts) and either generated by an approved password generator or constructed from three random words.
  3. MFA MUST be enabled on every internet-facing user account and all admin accounts.
  4. Default passwords on any device or service MUST be changed before first use.
  5. Passwords MUST NOT be shared; shared accounts are prohibited except where unavoidable and then MUST use a secure password manager.
  6. Password resets MUST require identity verification; reset links expire within 15 minutes.
  7. All staff MUST use an approved password manager (recommended: a business-tier manager with central policy).
  8. Any suspected compromise MUST be reported and the password changed immediately.
NCSC SME guidance: The NCSC Small Business Guide covers password management as a priority action, alongside MFA and software updates. Both resources are free and written for non-technical business owners.

MFA — The Control That Actually Gets You Certified (or Rejected)

The most common Cyber Essentials assessment failure is missing MFA on Microsoft 365 or Google Workspace admin accounts. Work through this checklist before your assessment:

Common Compliance Failures

Common approachCompliant?Issue
Shared team password in a spreadsheet✗ NoNo access control, no audit log, no off-boarding mechanism
Router/firewall with default password✗ NoDefault credentials explicitly prohibited
Individual email accounts, no MFA⚠ RiskAccount lockout required; cloud email without MFA is high-risk
MFA available but optional✗ NoAuditors check enforcement, not availability
Business password manager, MFA on email✓ YesMeets access control requirements
Passwords in browser autofill only⚠ RiskNo access control, no audit trail — borderline

Beyond the table, the classic paperwork mistakes are: a policy document that contradicts practice (says “no sharing” while staff share a login), treating Cyber Essentials as a one-off event (re-certification is annual and re-tests everything), and training materials that demonstrate the opposite of the policy. Auditors are remarkably good at spotting the gap between what you wrote and what you do — the fix is to make the technical controls do the enforcement so the document and reality can’t drift apart.

Password Managers in a Cyber Essentials Environment

The scheme actively favours password managers — they make unique strong passwords practical. Choose a business edition with central admin (policy enforcement, shared vaults with permissions, breach monitoring). A password manager does NOT remove the MFA requirement — the two controls are complementary: the manager stores strong unique passwords, MFA protects the door to the account itself.

Cyber Essentials vs Cyber Essentials PLUS — Password Differences

Cyber Essentials: self-assessment plus an external vulnerability scan; controls are evidenced but not tested on-site. Cyber Essentials PLUS: the same controls plus an on-site technical audit where a test engineer verifies MFA and password configuration hands-on — including automated password-guessing tests against network devices. The password requirements are identical; PLUS just proves them harder.

Frequently Asked Questions

Does Cyber Essentials require a written password policy?

Not as a standalone document, but you must evidence the controls; a written policy is the standard way to do it.

Can SMS 2FA satisfy Cyber Essentials MFA?

Yes, SMS qualifies, though authenticator apps or hardware keys are stronger and recommended by the NCSC.

Are password managers allowed under Cyber Essentials?

Yes — encouraged. They make unique strong passwords practical for staff.

What happens if a staff member uses a weak password?

Enforcement is the auditor’s focus — technical controls (length policy, MFA) should make weak passwords impossible, not just discouraged.

Do we need to change passwords regularly?

Not on a fixed cycle — the NCSC advises changing only on suspicion of compromise. Forced rotation encourages weaker passwords.

The Minimum Compliant Setup

For most SMEs, the minimum compliant password posture is: a business password manager (Bitwarden Business, 1Password Teams) where all staff have individual vaults; MFA enabled on all cloud services (Microsoft 365, Google Workspace, CRM); all devices have changed default admin passwords; and a written off-boarding checklist for leavers. The Work Password Policy Builder generates a compliant policy paragraph you can add to your staff handbook.

Cyber Essentials SME password policy NCSC compliance
For informational purposes only. Consult a qualified IT security professional for advice specific to your organisation.

⚡ Try NordPassSave up to 53% on NordPass Premium + get 3 months extra and experience enterprise-grade password security at an affordable price. Features include zero-knowledge encryption, cross-platform sync, and breach monitoring.