Essential cookies only — Cookie Policy.

Cyber Essentials

Cyber Essentials Password Requirements for SMEs

📅 10 May 2026·⏱ 8 min·✍ Rachel Morris

Cyber Essentials is the UK government's baseline cybersecurity certification, required for government contracts and increasingly expected by enterprise customers. Password controls are one of the five technical control areas assessed. Understanding exactly what is required — and what common approaches fail the assessment — prevents surprises at certification time.

The Five Technical Controls — Password Requirement

Cyber Essentials assesses five control categories: firewalls, secure configuration, access control, malware protection, and patch management. The password requirements fall under Access Control. Specifically, assessors check:

Common Compliance Failures

Common approachCompliant?Issue
Shared team password in a spreadsheet✗ NoNo access control, no audit log, no off-boarding mechanism
Router/firewall with default password✗ NoDefault credentials explicitly prohibited
Individual email accounts, no MFA⚠ RiskAccount lockout required; cloud email without MFA is high-risk
Business password manager, MFA on email✓ YesMeets access control requirements
Passwords in browser autofill only⚠ RiskNo access control, no audit trail — borderline

The Minimum Compliant Setup

For most SMEs, the minimum compliant password posture is: a business password manager (Bitwarden Business, 1Password Teams) where all staff have individual vaults; MFA enabled on all cloud services (Microsoft 365, Google Workspace, CRM); all devices have changed default admin passwords; and a written off-boarding checklist for leavers. The Work Password Policy Builder generates a compliant policy paragraph you can add to your staff handbook.

NCSC SME guidance: The NCSC Small Business Guide covers password management as a priority action, alongside MFA and software updates. Both resources are free and written for non-technical business owners.
Cyber Essentials SME password policy NCSC compliance
For informational purposes only. Consult a qualified IT security professional for advice specific to your organisation.

⚡ Try NordPassSave up to 53% on NordPass Premium + get 3 months extra and experience enterprise-grade password security at an affordable price. Features include zero-knowledge encryption, cross-platform sync, and breach monitoring.