47% of UK businesses hit by a cyber attack in the last year had one thing in common: weak or compromised passwords. Cyber Essentials — the UK government-backed certification — exists to fix exactly this, and its password controls are where most first-time applicants lose marks. Here’s exactly what Cyber Essentials requires for passwords in 2026, and how to build a compliant password policy your auditor will pass first time.
What Cyber Essentials Actually Requires for Passwords
Cyber Essentials (run by IASME on behalf of the NCSC) doesn’t demand a 100-page policy document. It demands five technical controls — firewalls, secure configuration, access control, malware protection, and patch management — and three of them touch passwords directly:
- Secure configuration: remove or change default passwords on every device and service (routers, cameras, printers, cloud consoles). Default credentials are the number one way attackers walk into an SME
- Access control — MFA: multi-factor authentication must be enabled on all internet-facing user accounts and all admin accounts, including cloud services (Microsoft 365, Google Workspace) and remote-access tools. This is the control most applicants trip on
- Access control — password hygiene: user passwords must be strong; the scheme aligns with NCSC guidance (below). Where a password is the only factor, it must be robust
Why is MFA the sticking point? Because a password alone is something an attacker can phish, guess, or steal in a data breach — and then replay from anywhere in the world. A second factor that the attacker doesn’t have (an authenticator app, a hardware key, a one-time code) stops that replay dead. That is why assessors now treat MFA as the expected standard for any account reachable over the internet, and why the technical control requirement effectively means: lockout or MFA for everything, and MFA for anything important.
Note: Cyber Essentials does not require a written password policy as a certificate gate — but the audit requires you to demonstrate the controls, and a short written policy is the cheapest way to evidence them.
The NCSC Password Rules Underneath It
Cyber Essentials maps to NCSC guidance, which has moved away from forced complexity toward three principles:
- Use three random words — the NCSC’s flagship advice for human-chosen passwords (“cleft camerawork tuba”). Random-word combinations are easier to remember and harder to crack than “P@ssw0rd!”
- Length beats complexity — a 15-character three-random-word password beats a 10-character mixed-symbol password, because every extra character multiplies the guess space
- Reuse is the real enemy — the NCSC’s biggest single recommendation: never reuse passwords across important services. One breach of any site then compromises everything
The 2021 update to NCSC’s password guidance was a deliberate departure from the old security-policy clichés: forced periodic rotation was dropped (it drives people to weaker, more predictable passwords), and complexity rules were de-emphasised in favour of length and uniqueness. Your Cyber Essentials policy should reflect the current guidance, not the 2015 playbook — an auditor who sees “change every 90 days” in your policy will ask whether the rest of it is current too.
A Compliant Password Policy Template (Copy-Paste)
Adapt this template to your staff handbook — it covers what Cyber Essentials assessors actually check:
- All user and admin accounts on internet-facing services MUST have a unique password, never reused on another service.
- Passwords MUST be at least 12 characters (16+ for admin accounts) and either generated by an approved password generator or constructed from three random words.
- MFA MUST be enabled on every internet-facing user account and all admin accounts.
- Default passwords on any device or service MUST be changed before first use.
- Passwords MUST NOT be shared; shared accounts are prohibited except where unavoidable and then MUST use a secure password manager.
- Password resets MUST require identity verification; reset links expire within 15 minutes.
- All staff MUST use an approved password manager (recommended: a business-tier manager with central policy).
- Any suspected compromise MUST be reported and the password changed immediately.
MFA — The Control That Actually Gets You Certified (or Rejected)
The most common Cyber Essentials assessment failure is missing MFA on Microsoft 365 or Google Workspace admin accounts. Work through this checklist before your assessment:
- MFA enforced (not just available) on ALL internet-facing user accounts
- MFA on all admin accounts, including partner and guest accounts
- MFA on remote-access tools (VPN, RDP exposed via a gateway, TeamViewer/AnyDesk)
- Authenticator apps or hardware keys preferred over SMS — phishing-resistant methods are the NCSC recommendation
- MFA recovery codes stored securely (not in email)
Common Compliance Failures
| Common approach | Compliant? | Issue |
|---|---|---|
| Shared team password in a spreadsheet | ✗ No | No access control, no audit log, no off-boarding mechanism |
| Router/firewall with default password | ✗ No | Default credentials explicitly prohibited |
| Individual email accounts, no MFA | ⚠ Risk | Account lockout required; cloud email without MFA is high-risk |
| MFA available but optional | ✗ No | Auditors check enforcement, not availability |
| Business password manager, MFA on email | ✓ Yes | Meets access control requirements |
| Passwords in browser autofill only | ⚠ Risk | No access control, no audit trail — borderline |
Beyond the table, the classic paperwork mistakes are: a policy document that contradicts practice (says “no sharing” while staff share a login), treating Cyber Essentials as a one-off event (re-certification is annual and re-tests everything), and training materials that demonstrate the opposite of the policy. Auditors are remarkably good at spotting the gap between what you wrote and what you do — the fix is to make the technical controls do the enforcement so the document and reality can’t drift apart.
Password Managers in a Cyber Essentials Environment
The scheme actively favours password managers — they make unique strong passwords practical. Choose a business edition with central admin (policy enforcement, shared vaults with permissions, breach monitoring). A password manager does NOT remove the MFA requirement — the two controls are complementary: the manager stores strong unique passwords, MFA protects the door to the account itself.
Cyber Essentials vs Cyber Essentials PLUS — Password Differences
Cyber Essentials: self-assessment plus an external vulnerability scan; controls are evidenced but not tested on-site. Cyber Essentials PLUS: the same controls plus an on-site technical audit where a test engineer verifies MFA and password configuration hands-on — including automated password-guessing tests against network devices. The password requirements are identical; PLUS just proves them harder.
Frequently Asked Questions
Does Cyber Essentials require a written password policy?
Not as a standalone document, but you must evidence the controls; a written policy is the standard way to do it.
Can SMS 2FA satisfy Cyber Essentials MFA?
Yes, SMS qualifies, though authenticator apps or hardware keys are stronger and recommended by the NCSC.
Are password managers allowed under Cyber Essentials?
Yes — encouraged. They make unique strong passwords practical for staff.
What happens if a staff member uses a weak password?
Enforcement is the auditor’s focus — technical controls (length policy, MFA) should make weak passwords impossible, not just discouraged.
Do we need to change passwords regularly?
Not on a fixed cycle — the NCSC advises changing only on suspicion of compromise. Forced rotation encourages weaker passwords.
The Minimum Compliant Setup
For most SMEs, the minimum compliant password posture is: a business password manager (Bitwarden Business, 1Password Teams) where all staff have individual vaults; MFA enabled on all cloud services (Microsoft 365, Google Workspace, CRM); all devices have changed default admin passwords; and a written off-boarding checklist for leavers. The Work Password Policy Builder generates a compliant policy paragraph you can add to your staff handbook.