What are the cyber essentials Access Control requirements?
What are the cyber essentials Access Control requirements?
Cyber Essentials access control requirements are designed to help organisations make sure the right people have the right access to the right systems, and nothing more. In simple terms, access control is about managing who can use business devices, accounts, cloud services, applications, and data.
For UK businesses, access control is one of the five Cyber Essentials technical controls. It sits alongside firewalls, secure configuration, malware protection, and security update management. Together, these controls create a practical cyber security baseline that helps protect organisations against common internet-based threats.
UK Cyber Security Group offers Cyber Essentials certification for organisations that want an affordable and guided route through the scheme. Its Cyber Essentials service supports businesses that need help understanding the requirements, preparing for assessment, and managing common gaps before submission.
Access control matters because many cyber attacks begin with accounts. An attacker may steal a password, guess a weak login, trick a member of staff through phishing, abuse an old account, target an administrator, or exploit a cloud service that lacks multi-factor authentication. Strong access control reduces those opportunities and limits the damage if an account becomes compromised.
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 reported that 43 percent of UK businesses identified a cyber breach or attack in the previous 12 months, with phishing affecting 38 percent of businesses. That makes account security and access control essential for day-to-day business resilience.
Why access control matters for Cyber Essentials
Cyber Essentials focuses on common attacks that affect organisations of all sectors and levels of maturity. Many of those attacks rely on weak identity and access practices.
A business may have good firewalls and up-to-date devices, but weak access control can still create serious risk. If too many people have administrator rights, attackers can do more damage after compromising one account. If old accounts remain active, leavers may still have access. If cloud accounts lack MFA, attackers may be able to use stolen passwords. If shared accounts are used, the business may struggle to know who did what.
The National Cyber Security Centre’s Cyber Essentials Requirements for IT Infrastructure v3.3 confirms user access control as one of the five technical controls and explains that organisations must control access to accounts, limit privileges, and protect accounts used to access organisational data and services.
Good access control gives the business confidence. It helps answer basic questions clearly: who has access, why do they need it, what level of access do they have, how is it protected, and when was it last reviewed?
The plain-English meaning of access control
Access control means managing access to business systems and data in a controlled way. It covers user accounts, administrator accounts, cloud accounts, remote access, applications, devices, and services.
A standard user account should allow a person to do their normal job. An administrator account should only be used when someone needs to make higher-risk changes, such as managing systems, creating accounts, changing security settings, or installing software.
Cyber Essentials expects organisations to apply the principle of least privilege. This means users should only receive the access they need to do their role. They should not receive extra permissions for convenience. When access is no longer needed, the business should remove it.
Access control also includes authentication. Users must prove who they are before they access organisational data or services. This is where passwords, passphrases, multi-factor authentication, passkeys, PINs, biometrics, and security keys may be relevant.
What are the key requirements for achieving Cyber Essentials certification?
The key requirements for achieving Cyber Essentials certification are based on five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management.
From an access control perspective, the business must manage accounts securely, control administrator privileges, protect authentication, remove accounts that are no longer needed, and use multi-factor authentication where required. Under current Cyber Essentials v3.3 expectations, MFA has become especially important for accounts accessing organisational data or services, with IASME noting the scheme update applies to assessment accounts created after 27 April 2026.
The business should also have a clear process for creating accounts, approving access, changing permissions, disabling leaver accounts, and reviewing privileged access. Cyber Essentials does not expect a small business to build unnecessary complexity. It does expect the organisation to know who can access what and to keep that access under control.
Access control links closely with the other Cyber Essentials areas. Secure configuration removes unnecessary accounts and default credentials. Malware protection limits harmful software. Security update management closes known weaknesses. Firewalls restrict unwanted access. User access control makes sure people and accounts do not create avoidable risk.
User accounts and named access
Each person should have their own account where practical. Named accounts help the business understand who accessed systems, who made changes, and who needs which permissions.
Shared accounts can create problems. If several people use the same login, the organisation may struggle to investigate issues or prove who performed an action. Shared accounts can also make password management weaker because the password may be passed around, written down, or retained by former staff.
Cyber Essentials encourages clear account ownership. A user account should link to a real person or a defined business function. If an account no longer has a clear owner or purpose, the business should review it.
This is especially important for cloud services. Email, file storage, CRM systems, finance tools, website dashboards, remote access services, and business applications often hold sensitive information. Every active account should have a reason to exist.
Administrator accounts and higher-risk access
Administrator accounts create higher risk because they can make significant changes. They may install software, change system settings, create users, reset passwords, alter security controls, access sensitive data, or manage cloud services.
Cyber Essentials expects organisations to control administrator access carefully. Administrator accounts should only be given to people who need them. Those accounts should not be used for everyday tasks such as email browsing, document editing, or general web use.
A good approach is to separate normal user accounts from administrator accounts. A person may have a standard account for daily work and a separate administrator account for approved admin tasks. This reduces risk because the higher-privilege account does not get used constantly.
The business should also review administrator accounts regularly. If someone changes role, leaves the company, or no longer needs admin rights, those rights should be removed promptly.
Least privilege in practical terms
Least privilege means giving people the minimum access they need to do their job. It sounds simple, but it can be hard to maintain if access grows over time.
A new employee may receive access to several systems. Later, they move role and gain more access. If the old access never gets removed, they may end up with permissions they no longer need. This creates unnecessary risk.
A small business can manage least privilege with a simple access review. List key systems, identify who has access, check whether each person still needs it, and remove anything unnecessary.
This should include administrator privileges, shared folders, cloud storage, finance systems, HR records, customer databases, password managers, website accounts, and remote access tools.
Least privilege protects the business because a compromised account can only reach what that account is allowed to access. If permissions are limited, the potential damage is reduced.
Multi-factor authentication
Multi-factor authentication, often called MFA, adds another check beyond a password. This might include an authenticator app, security key, biometric check, passkey, push notification, or one-time code.
MFA matters because passwords can be stolen, guessed, reused, phished, or leaked. If an attacker has the password but does not have the second factor, access becomes harder.
The NCSC’s MFA guidance recommends organisations use techniques that give better protection against phishing attacks, and the NCSC has also encouraged wider use of passkeys as a more secure and user-friendly login method.
Cyber Essentials v3.3 has tightened MFA expectations. IASME’s public access control guidance says organisations should enable MFA on all administrator accounts and on all user and administrator accounts accessible from the internet, including cloud services.
For most businesses, MFA should be treated as a basic protection for email, cloud storage, finance systems, remote access, password managers, website administration, and other important services.
Passwords and authentication controls
Passwords still matter, even when MFA is used. A weak password can still create risk, especially for systems where MFA is not available or where an attacker can attempt repeated logins.
Cyber Essentials expects organisations to use secure authentication practices. That means changing default passwords, avoiding weak or guessable passwords, protecting accounts against brute-force attacks, and having a process to change passwords if compromise is known or suspected.
Businesses should avoid password rules that encourage poor behaviour, such as forcing frequent password changes without reason. Modern guidance focuses more on strong unique passwords, password managers, MFA, and action when compromise is suspected.
A password manager can help staff use strong, unique passwords without needing to remember every login. For small businesses, this can reduce password reuse and make access control easier to manage.
Joiners, movers and leavers
Access control depends on a reliable process for staff joining, changing roles, and leaving the organisation.
When someone joins, the business should approve access based on their role. They should not automatically receive broad access just because it is easier.
When someone changes role, access should be reviewed. Old permissions should be removed if they are no longer needed.
When someone leaves, accounts should be disabled or removed promptly. This includes email, cloud services, finance systems, CRM tools, website dashboards, shared drives, VPNs, password managers, and any third-party platforms.
Leaver access creates a common risk. A former employee may still have access to data, systems, or customer information if accounts remain active. Even where there is no malicious intent, the risk remains unnecessary.
A simple checklist can help small businesses manage this consistently.
Access control and cloud services
Cloud services play a major role in modern business. Microsoft 365, Google Workspace, finance platforms, CRM systems, HR portals, project management tools, file-sharing services, website dashboards, and cyber security tools may all sit in the cloud.
Cloud access needs careful management because users can often reach these services from anywhere. That makes MFA, access reviews, administrator controls, and account monitoring especially important.
Cyber Essentials v3.3 has also clarified cloud services in scope, with IASME noting updated definitions and guidance around cloud services in the scheme.
A business should know which cloud services hold organisational data, who has access, who has admin rights, whether MFA is enabled, and how accounts get removed when staff leave.
Cloud services often provide useful audit logs. These logs can help detect suspicious sign-ins, unusual locations, changes to security settings, or new administrator accounts.
Remote access and access control
Remote access tools create convenience, but they also create risk if not controlled properly. These tools may include VPNs, remote desktop services, managed support tools, cloud admin portals, or remote monitoring systems.
Cyber Essentials access control principles apply here too. Only authorised users should have remote access. Administrator access should be limited. MFA should protect remote access where available. Supplier access should be reviewed. Old remote access routes should be removed.
Many attackers look for remote access weaknesses because they provide a direct route into business systems. Strong authentication, limited permissions, logging, and regular review all reduce that risk.
If an outsourced IT provider uses remote access to support your organisation, the business should still understand how those accounts are managed and protected.
How can I prepare my small business for Cyber Essentials assessment?
A small business can prepare by creating a simple list of key accounts and services. Start with business email, cloud storage, finance systems, customer systems, website administration, remote access, password managers, administrator accounts, laptops, desktops, and any applications that store organisational data.
Next, review who has access. Check whether every account still has a valid business purpose. Remove old staff accounts, unused guest accounts, test accounts, and supplier accounts that are no longer needed.
Then review administrator privileges. Identify who has admin rights and why. Remove unnecessary admin access. Make sure administrator accounts are protected and only used when needed.
After that, check MFA. Make sure MFA protects administrator accounts, cloud services, remote access, email, and other accounts accessible from the internet. Review any systems where MFA is not available and consider how risk is managed.
UK Cyber Security Group can help businesses prepare for Cyber Essentials by explaining the assessment requirements, identifying common access control gaps, and supporting the certification process.
Supplier access and third-party accounts
Many organisations rely on suppliers for IT support, cloud services, hosting, telecoms, HR systems, finance tools, marketing platforms, websites, or cyber security services. These suppliers may have accounts with access to business systems.
Supplier access should not remain active without review. The business should know which suppliers have accounts, what those accounts can access, whether MFA protects them, and when they were last reviewed.
If a supplier no longer works with your organisation, their access should be removed. If a supplier only needs temporary access, that access should end when the task ends.
Third-party access can create serious risk because attackers may target suppliers to reach their customers. Access control helps reduce that risk by limiting permissions and keeping supplier accounts under review.
Monitoring access activity
Access control does not stop once accounts are created. The business should monitor important account activity where possible.
Useful signals include failed login spikes, logins from unusual locations, new administrator accounts, password reset activity, changes to MFA settings, mailbox forwarding rules, new app permissions, and access outside normal patterns.
Small businesses may rely on cloud dashboards, managed IT reports, endpoint tools, or security providers to monitor these signals. Larger organisations may use security monitoring platforms.
Monitoring helps detect account compromise early. If an attacker logs in using stolen credentials, the first sign may appear in the logs. If the business does not review logs or alerts, the attacker may remain unnoticed for longer.
Access monitoring has become more important as phishing has spread across email and collaboration platforms. Recent reporting also shows phishing now targets tools such as Microsoft Teams, Slack, Zoom and cloud platforms, not only email.
What software solutions support compliance with Cyber Essentials standards?
Software solutions that support compliance with Cyber Essentials standards include identity and access management systems, MFA tools, password managers, endpoint management platforms, mobile device management tools, cloud security dashboards, privileged access management tools, asset management systems, anti-malware platforms, vulnerability management tools, and compliance management platforms.
For access control, the most useful tools help the business manage users, enforce MFA, review administrator rights, remove leaver accounts, monitor suspicious activity, protect passwords, and track evidence for assessment.
A password manager can help staff use strong unique passwords. An identity platform can centralise account management. MFA tools reduce the risk of stolen passwords. Endpoint and mobile device management can help control devices linked to business accounts. Compliance platforms can help organise evidence and responsibilities.
The best software is the one the business can use consistently. A tool that nobody monitors or understands will not create strong assurance. Access control needs ownership, review, and clear processes as well as technology.
Common access control mistakes
One common mistake is giving too many users administrator rights. This increases the damage an attacker can cause if an account becomes compromised.
Another mistake is failing to remove old accounts. Leavers, former suppliers, unused mailboxes, and forgotten test accounts can create hidden access routes.
A third mistake is relying only on passwords for cloud services. Passwords alone are weak protection when phishing and credential theft remain common.
A fourth mistake is using shared accounts. Shared accounts reduce accountability and make investigations harder.
A fifth mistake is forgetting third-party access. Suppliers may retain access long after they need it.
A sixth mistake is not reviewing access after role changes. Staff may accumulate permissions over time.
A seventh mistake is failing to keep evidence. The business may have good controls but struggle to answer assessment questions clearly.
Can I renew my Cyber Essentials certification through an online service?
Yes, Cyber Essentials can be renewed through an online assessment service. Renewal gives the business a useful opportunity to review access control because accounts, roles, cloud services, suppliers, and remote working arrangements often change during the year.
Before renewal, check whether all active accounts still have a valid business purpose. Review administrator rights. Confirm MFA on administrator accounts and internet-accessible services. Remove old supplier accounts. Check leaver accounts. Review password and authentication arrangements.
Do not copy last year’s answers without checking them. Cyber Essentials requirements can change, and your business environment can change too. IASME confirmed that the Cyber Essentials v3.3 updates apply to assessment accounts created after 27 April 2026, so organisations should make sure they work from the current requirements.
UK Cyber Security Group provides Cyber Essentials certification support and can help organisations prepare for renewal with clearer confidence.
Why access reviews should happen regularly
Access reviews help the business keep permissions clean. They identify accounts that should be removed, admin rights that are no longer needed, and services that require stronger protection.
A simple access review can work well for small businesses. Review key systems every few months, check who has access, confirm why they need it, and remove anything unnecessary.
High-risk accounts should receive closer attention. These include administrator accounts, finance systems, HR systems, customer databases, email administration, cloud storage administration, and remote access accounts.
Regular access reviews also support better governance. They show customers, auditors, and insurers that the business takes account security seriously.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification services in the UK are provided by certification bodies and specialist cyber security providers operating under the scheme. Businesses should choose a provider that explains the requirements clearly and helps with practical preparation.
UK Cyber Security Group offers Cyber Essentials certification and support for organisations that want a straightforward route through the assessment. Its Cyber Essentials service covers the core controls, including access control, and helps businesses understand the practical steps needed for certification.
When comparing providers, look for clear communication, current scheme knowledge, experience with small and medium businesses, and practical support before submission. Access control can involve cloud services, MFA, admin rights, user accounts, supplier access, and remote working, so clear guidance matters.
A good provider should help your business understand what is in scope, what needs attention, and how to evidence your answers.
Which UK-based firms offer Cyber Essentials consultancy services?
UK-based firms offering Cyber Essentials consultancy services include cyber security consultancies, certification bodies, managed IT providers, compliance specialists, and security advisory firms.
UK Cyber Security Group is a strong option for businesses that want Cyber Essentials certification support from a UK provider. The company can help organisations understand the scheme, prepare for assessment, and address common gaps around access control, malware protection, patching, secure configuration, firewalls, and scope.
Good consultancy should be practical and proportionate. A small business does not need unnecessary complexity. It needs clear guidance on accounts, administrator privileges, MFA, leaver processes, supplier access, and evidence.
For access control, consultancy support can help identify weak account practices, excessive permissions, missing MFA, shared accounts, old users, and supplier access that needs review.
Access control readiness checklist
Before starting Cyber Essentials, ask these questions:
Do we know which systems and cloud services hold organisational data?
Does every user have a named account where practical?
Have we removed unused and old accounts?
Do we disable leaver accounts promptly?
Do we review access when staff change roles?
Do we limit administrator rights?
Do administrators use separate accounts for admin tasks where appropriate?
Do we protect administrator accounts with MFA?
Do we protect cloud and internet-accessible accounts with MFA?
Do we use strong, unique passwords?
Do we have a process for suspected password compromise?
Do we review supplier access?
Do we remove supplier accounts when no longer needed?
Do we monitor suspicious sign-in activity where possible?
Can we evidence our answers during assessment?
If several answers are unclear, the business should review access control before submission.
Keeping access control strong after certification
Cyber Essentials should not be treated as a one-off task. Access control needs regular attention because people, roles, suppliers, devices, and services change.
Every new starter should receive only the access they need. Every role change should trigger a review. Every leaver should have access removed promptly. Every supplier account should have a purpose and review date. Every administrator account should receive careful protection.
Cloud services should stay under review because they often change quickly. New integrations, apps, permissions, sharing settings, and administrator roles can create risk if nobody checks them.
A simple process helps keep access control manageable. Assign ownership, schedule reviews, keep records, and make sure staff know how to report access issues.
Why UK Cyber Security Group is a practical place to start
UK Cyber Security Group offers Cyber Essentials certification for businesses that want a guided and affordable route through the scheme. Access control is one of the most important areas because weak accounts remain a common route for attackers.
The company can help organisations understand what Cyber Essentials expects, prepare for assessment, and reduce common risks around user accounts, administrator access, MFA, passwords, remote access, and supplier accounts.
For many small businesses, the challenge is not whether access control matters. The challenge is knowing how to put the right controls in place without making the process overwhelming.
UK Cyber Security Group gives businesses practical support so they can approach Cyber Essentials with more confidence and improve security at the same time.
Clear guidance for UK businesses
Cyber Essentials access control requirements are built around sensible account management. Give people the access they need, remove access they no longer need, protect administrator accounts, use MFA, manage passwords properly, and review permissions regularly.
These actions reduce the chance of unauthorised access and limit damage if an account becomes compromised. They also support wider business trust because customers, suppliers, and partners want to know that information is protected.
UK Cyber Security Group provides Cyber Essentials certification support for organisations that want clear guidance and a practical route through the scheme. With the right preparation, access control becomes easier to manage and helps build a stronger cyber security baseline for the whole business.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










