What are the cyber essentials Password-Based Authentication requirements?
Effective password-based authentication is central to Cyber Essentials, which expects UK organisations to manage passwords, accounts and login attempts in a structured, risk-aware way. The scheme focuses on making accounts hard to guess, limiting the damage from stolen credentials, and proving that you are using modern, sensible practices rather than relying on outdated password rules.
What are the Cyber Essentials Password-Based Authentication requirements?
The UK Cyber Security Group offers Cyber Essentials certification at a low cost through its services, giving smaller organisations an accessible route into formal cyber assurance.
Cyber Essentials in plain English: why passwords get so much attention
Cyber Essentials is a UK government-backed certification scheme that sets out a practical baseline of technical controls to protect against common cyber attacks. It revolves around five control areas:
- Firewalls and internet gateways
- Secure configuration
- User access control
- Malware protection
- Patch management
User access control is where password-based authentication lives. If attackers can guess, steal or brute-force passwords, they can often bypass all your other defences. That is why the scheme puts particular emphasis on:
- How passwords are created and managed
- How many attempts an attacker can make
- How administrator and remote accounts are protected
Cyber Essentials is now widely seen as the minimum bar for UK organisations wanting to demonstrate basic cyber hygiene. It is already mandatory across all lots of the G‑Cloud 15 framework, with at least basic Cyber Essentials required for cloud software and support suppliers. That gives a good sense of how seriously the UK public sector takes these controls.
What password-based authentication covers under Cyber Essentials
When people think about password requirements, they often jump straight to rules about length and complexity. Cyber Essentials takes a broader view, looking at all the moving parts around a password:
- Accounts – how user and administrator accounts are set up and managed
- Password quality – how easy they are to guess or reuse
- Guessing protection – how many failed attempts are allowed and how that is handled
- Additional factors – when multi-factor authentication (MFA) is expected
- Default and shared credentials – how vendor-supplied and generic accounts are treated
The scheme is aligned with modern guidance from the National Cyber Security Centre, which emphasises long, memorable passwords or passphrases, reducing the burden on users while still making guessing attacks impractical.
Core Cyber Essentials rules for passwords and accounts
Unique, attributable accounts
At the heart of Cyber Essentials is the simple idea that every person should have their own account. This means:
- A unique username for each employee and regular contractor
- No generic shared accounts for everyday access
- Audit logs that can be traced back to named individuals
This principle applies to both user and administrator accounts. It is the foundation for accountability and makes it much easier to investigate suspicious activity.
Separating standard and administrator accounts
The scheme expects you to:
- Give staff standard user accounts for their day-to-day work
- Provide separate administrator accounts only to those who genuinely need them
- Use admin accounts only for administrative tasks, not for email or general browsing
This separation is crucial. If an attacker compromises a standard user account, their ability to cause serious damage is limited. If they compromise an admin account, they may be able to take over systems, disable protection and move laterally much more easily.
Password length and strength
Cyber Essentials does not force one rigid password formula, but it does expect you to implement sensible controls so that passwords:
- Are long enough to resist brute-force guessing
- Are not trivial (for example, “Password123” or common dictionary words on their own)
- Are not reused across different systems and services
Modern guidance tends to favour:
- Longer passphrases over short, complex strings
- Avoiding frequent forced reset schedules, which can encourage weak patterns
- Supporting password managers to reduce reuse and encourage unique credentials
For Cyber Essentials, what matters is being able to show that:
- Default passwords have been replaced
- Minimum password standards are defined and enforced
- Staff are guided towards strong, memorable choices
Protecting against password guessing: lockouts and throttling
A key requirement under Cyber Essentials is to reduce the effectiveness of brute-force attacks. This usually means:
- Locking accounts for a period after a small number of failed attempts
- Or throttling login attempts so that attackers cannot make rapid guesses
For example:
- After a certain number of incorrect passwords, an account might be locked and require admin intervention or a timed reset
- Or the system might enforce a delay between attempts, making large-scale guessing unworkable
The scheme is not prescriptive about exact numbers, but it is clear that leaving logins completely open to unlimited guesses is not acceptable.
Multi-factor authentication (MFA) and high-risk accounts
Although Cyber Essentials focuses mainly on technical basics, it explicitly encourages and, in some contexts, expects multi-factor authentication:
- Administrator access to cloud services and management consoles should be protected by MFA wherever the platform supports it
- Remote access solutions are strongly expected to offer MFA, particularly for admin-level access
Business-reporter notes that many Cyber Essentials requirements can be met by enabling features that already exist in common platforms, such as MFA and conditional access rules. That makes it easier for a small business to strengthen password-based authentication without buying new tools.
Handling default and vendor-supplied credentials
Cyber Essentials is very clear that:
- Default usernames and passwords must be changed before systems are put into use
- Unnecessary default accounts should be disabled or removed altogether
This applies to:
- Network equipment (for example, routers, firewalls, wireless access points)
- Operating systems and applications
- Cloud services where initial admin accounts come with default settings
Leaving defaults in place is one of the most common and easily exploitable weaknesses, so assessors pay close attention to this area.
Password-based authentication in different scenarios
Local machine logins
For desktops, laptops and other user devices, Cyber Essentials expects:
- Password-protected login for every user
- Separate accounts so staff do not share the same login on a device
- No standard users with local admin rights unless there is a clear justification and additional controls
This is often where organisations first bring their password policies into line with the scheme: ensuring that all devices require authentication and that users cannot casually install software or change security settings.
Cloud services and SaaS
Cloud platforms and software-as-a-service applications are now central to most UK businesses. Under Cyber Essentials, you should:
- Ensure each user has their own account for each cloud service they use
- Apply minimum password standards consistently across those services
- Turn on MFA wherever possible, especially for admin accounts and access to sensitive data
Because cloud admin portals are prime targets, assessors may ask specifically how those accounts are protected. Using features built into platforms like major email and productivity suites often goes a long way here.
Remote access and VPNs
If staff can access internal systems remotely, Cyber Essentials expects:
- Remote access solutions to be hardened and limited to those who need them
- Strong authentication for remote logins, preferably MFA
- Strict control over who can use remote tools and from where
From a password perspective, remote access accounts should be protected more strongly than internal-only accounts, because they are directly exposed to the internet.
Third-party and supplier access
If suppliers or partners have access to your systems, the scheme expects you to:
- Control and monitor those accounts with the same rigour as internal ones
- Ensure that passwords and MFA arrangements are at least equivalent to your own standards
- Remove access promptly when contracts end or roles change
This is increasingly important as more organisations rely on managed service providers, outsourced support and cloud integrations.
Preparing a small business: getting practical about passwords
How can I prepare my small business for Cyber Essentials assessment?
To answer How can I prepare my small business for Cyber Essentials assessment? in a password-specific way, you can follow a straightforward plan:
- List your systems and services
Write down all the systems your staff log into: email, file storage, CRM, finance, remote access, cloud platforms, Wi‑Fi admin pages, and so on. - Identify account types
For each system, note whether there are:- User accounts
- Admin or super-user accounts
- Service accounts (used by software, not people)
- Any default or generic accounts
- Check for unique users
Make sure each staff member has their own login. Remove or restrict generic shared accounts where possible. - Review admin rights
Create a list of everyone with administrator access and why they need it. Remove admin rights from accounts that do not genuinely require them. - Update weak and default passwords
Identify any accounts using default or obviously weak passwords and change them. Ensure devices and routers no longer use factory credentials. - Implement lockout or throttling
Work with whoever manages your IT to make sure your systems block or slow down repeated login attempts. - Enable MFA where practical
Turn on MFA for cloud admin portals, remote access tools and any system containing sensitive information, starting with the highest-risk accounts. - Document what you have done
Keep a simple record of your password policies, admin accounts, and what mechanisms are in place to protect against guessing. This will be useful when answering the assessment questions.
By working through these steps, you will address most of the password-based authentication concerns that Cyber Essentials examiners look for.
Answering the bigger picture: key requirements and software support
What are the key requirements for achieving Cyber Essentials certification?
In the context of passwords and authentication, What are the key requirements for achieving Cyber Essentials certification? can be summarised as:
- Unique, identifiable accounts for all users
- Separation of standard and administrator accounts
- Sensible password standards (length, strength, not easily guessable)
- Protection against brute-force attacks through lockouts or throttling
- Removal or change of default credentials
- Stronger protection (including MFA) for admin and remote access accounts
- Clear joiner, mover and leaver processes for enabling and disabling accounts
These sit alongside the other four technical control areas, but account and password management is a major part of the scheme’s core.
What software solutions support compliance with Cyber Essentials standards?
For What software solutions support compliance with Cyber Essentials standards?, you do not necessarily need exotic tools. Many organisations use:
- Directory and identity services – to centralise account management and enforce password policies
- Single sign-on and MFA platforms – to add extra protection to logins, especially for high-risk systems
- Password managers – to help staff generate and store unique, strong passwords without resorting to reuse
- Endpoint management tools – to ensure devices are joined to a central directory, enforce login rules and limit local admin rights
- Cloud platform security features – such as conditional access, login risk analysis and built-in MFA in mainstream productivity suites
Business-reporter notes that many Cyber Essentials requirements can be met using existing platform features and freely available tools. The trick is to turn those features on and configure them intentionally, rather than leaving defaults in place.
Certification logistics: renewals, providers and consultancy
Can I renew my Cyber Essentials certification through an online service?
Yes, Can I renew my Cyber Essentials certification through an online service? is an easy one: most organisations complete both initial and renewal assessments online.
The typical pattern is:
- You work with an approved certification body
- You complete the self-assessment questionnaire via their portal
- You provide clarifications or evidence where needed
- When changes are required (for example, if an answer reveals a gap), you address them and confirm the fix
As long as you maintain your controls during the year, renewals become more of a tidy-up than a scramble. This is particularly convenient for small businesses and distributed teams.
Which companies provide Cyber Essentials certification services in the UK?
For Which companies provide Cyber Essentials certification services in the UK?, there is a range of accredited certification bodies and service providers that:
- Operate assessment portals
- Provide guidance on how to interpret the questions
- Offer both basic Cyber Essentials and Cyber Essentials Plus (which adds independent technical testing)
The UK Cyber Security Group is one such provider, offering Cyber Essentials certification at a low cost. It is part of a broader ecosystem of UK firms focused on helping organisations meet the scheme’s requirements across all five control areas, including passwords and account management.
Which UK-based firms offer Cyber Essentials consultancy services?.
The question Which UK-based firms offer Cyber Essentials consultancy services?. is a little broader. Beyond certification bodies, many UK-based consultancies and managed service providers offer:
- Readiness assessments and gap analysis against the scheme
- Hands-on help configuring account and password settings in common platforms
- Drafting of straightforward password and access control policies
- Staff awareness training focused on phishing, credential security and good password habits
These firms range from micro-consultancies specialising in SME support through to larger cyber practices. The UK Cyber Security Group itself, and related organisations under the same umbrella, offer consultancy alongside certification, helping organisations move from current state to assessment-ready without guesswork.
Common password pitfalls that trip up Cyber Essentials assessments
Even organisations with reasonable IT setups can stumble on the details. Some frequent issues include:
- Staff with local admin rights on their own machines “for convenience”
- Default passwords left on routers, Wi‑Fi access points or admin portals
- Generic logins used for everyday work, making it impossible to attribute activity
- Remote access or cloud admin accounts without MFA, even when the platform supports it
- Password policies that look strong on paper but are not enforced in practice
These are all fixable, but they tend to surface when completing the questionnaire. Working through an internal checklist beforehand helps avoid surprises.
Crafting a password policy that works in the real world
A Cyber Essentials-aligned password policy does not need to be long or complicated. It should:
- Use plain language
- Focus on what staff should actually do
- Align with what the technology enforces
Typical elements include:
- Encouraging long, memorable passwords or passphrases rather than short, complex strings
- Requiring unique passwords for work systems (no reuse between work and personal accounts)
- Prohibiting sharing of passwords, including between colleagues “just for today”
- Explaining how and when passwords need to be changed (for example, after suspected compromise)
- Setting expectations for the use of password managers where provided
This policy then sits alongside technical enforcement in your systems, so users are guided towards good practice rather than relying purely on memory.
Using Cyber Essentials as a stepping stone
Getting password-based authentication right for Cyber Essentials does more than help you pass an assessment. It lays groundwork for:
- Stronger identity and access management across your organisation
- Easier compliance with other frameworks and customer requirements
- Reduced risk from common attacks such as phishing, credential stuffing and brute-force attempts
Given how many UK contracts and frameworks now expect Cyber Essentials certification, including major government frameworks like G‑Cloud 15, investing in sensible password and account management is a practical, business-focused step. With the right mix of platform features, straightforward policies and, where needed, external support, even very small businesses can reach a level of password-based security that stands up well to both attackers and assessors.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










