Monitor

Blog › Article

11 August 2026 · Article

Cyber Essentials password and MFA requirements

The password rules are simpler than most people think, and less strict in the places people expect. MFA is the opposite: stricter than it has ever been, and now one of the automatic-fail requirements.

MFA on cloud services: automatic fail

Start here, because it's the part that can fail an assessment on its own. Since 27 April 2026, two of the four automatic-fail questions are about multi-factor authentication on cloud services:

"Cloud service" is broader than most organisations assume. It isn't just Microsoft 365 or Google Workspace: it's any online service holding organisational data — accounting, CRM, file sharing, HR, project tools. The service that fails the assessment is usually the one nobody remembered to list.

The password rules: pick one of three

Where passwords are still used, the scheme asks for one of these options per system. You don't have to use the same option everywhere.

OptionMinimum lengthCondition
18 charactersWith multi-factor authentication
212 charactersOn its own
38 charactersWith automatic blocking of common passwords (a deny list)

Whichever you choose, there must be no maximum length. A legacy system that caps passwords at 16 characters is a finding in its own right.

What the rules don't require

A lot of what gets written about Cyber Essentials passwords is out of date or simply wrong:

Protection against guessing: pick one of three

Separately from length, every login needs protection against brute-force guessing. Again, one of three:

Cloud platforms usually do this by default. The gap is usually local accounts: Windows doesn't lock out local accounts unless a lockout policy has been set, so a machine can meet every other requirement and still fail this one.

Unlocking devices

Devices that someone physically uses — laptops, desktops, phones, tablets — need a PIN, password or biometric to unlock, with the same protection against guessing. A PIN or password used only to unlock the device needs at least six characters. If the same credential also signs in to other services, the full password rules above apply to it instead.

Administrator accounts

Administrator accounts are held to the same password rules, and to a stricter rule about use: they're for administration only. No email, no web browsing, no day-to-day work on an account that can change the whole system. And they need MFA on cloud services, like every other account.

Where this goes wrong in practice. It's rarely the policy. It's the exceptions: the cloud service added last month without MFA, the local account with no lockout, the old application with a length cap, the admin who reads email on their admin account. Each is easy to fix once someone knows it's there.

A quick self-check

Quick answers

What is the minimum password length for Cyber Essentials?

Eight characters with MFA or with a deny list of common passwords, or twelve characters on their own. Six characters for a PIN or password used only to unlock a device.

Does Cyber Essentials require passwords to be changed regularly?

No. Passwords should be changed when there's reason to think they're compromised, not on a schedule.

Is MFA mandatory for Cyber Essentials?

On cloud services that offer it, yes: for both administrator and user accounts, and a missing one is an automatic fail.