Essential cookies only — Cookie Policy.
Everything your SME needs to know about Cyber Essentials password controls: what the scheme requires, how NCSC guidance aligns, and how to meet both without a dedicated IT security team. Includes MFA requirements, password manager setup, and a ready-to-copy policy paragraph.
Cyber Essentials is a UK government-backed certification scheme administered by the National Cyber Security Centre (NCSC). It defines a baseline set of security controls designed to protect organisations — particularly small and medium enterprises — against the most common internet-based threats.
The scheme covers five technical controls: boundary firewalls, secure configuration, access control (including passwords), malware protection, and patch management. Password controls fall under access control and are one of the most frequently assessed requirements.
There are two certification levels: Cyber Essentials (self-assessment, ~£300) and Cyber Essentials Plus (independently tested, ~£800–1,500). Both require the same password controls on paper, but Plus includes automated testing.
The scheme does not mandate a specific password length or complexity formula. Instead, it requires that:
The NCSC Small Business Guide provides practical password recommendations that align with and support Cyber Essentials compliance:
Multi-factor authentication is effectively required for cloud services, remote access accounts, and administrator accounts under the updated Cyber Essentials scheme (2022 onwards). The technical control requirement — account lockout after max 10 attempts, or MFA — means that for internet-facing systems, MFA is the practical standard.
Password strength alone is not sufficient for cloud and remote access accounts. The combination of a strong generated password and MFA is what Cyber Essentials assessors expect.
For admin accounts, FIDO2 hardware security keys (YubiKey, Google Titan) are the gold standard, but TOTP authenticator apps are acceptable for most SMEs.
Work Password is a free, client-side password generator and policy builder designed specifically for Cyber Essentials and NCSC compliance. Here is how it maps to the scheme requirements:
crypto.getRandomValues(). Nothing transmitted, nothing stored. Safe for generating credentials before importing into your business password manager| Standard | Min length | MFA | Rotation | Password manager |
|---|---|---|---|---|
| Cyber Essentials | Not specified (8+ recommended) | Required for cloud/remote | On compromise only | Effectively required |
| NCSC Small Business | 8+ standard, 14+ admin | Strongly recommended | On compromise only | Recommended |
| NIST SP 800-63B 2025 | 15 characters | Required at AAL2+ | On compromise only | Not specified |
| Work Password (default) | 16 standard / 20 admin | Implement separately | On compromise only | Integrated workflow |
When preparing your password controls for a Cyber Essentials assessment, focus on these five actions:
Generate a compliant password and copy a ready-to-use policy paragraph — free, client-side, no sign-up required.
Open Policy Builder →