Blog › Article
Cyber Essentials password and MFA requirements
The password rules are simpler than most people think, and less strict in the places people expect. MFA is the opposite: stricter than it has ever been, and now one of the automatic-fail requirements.
MFA on cloud services: automatic fail
Start here, because it's the part that can fail an assessment on its own. Since 27 April 2026, two of the four automatic-fail questions are about multi-factor authentication on cloud services:
- MFA enabled for administrator accounts on every cloud service that offers it;
- MFA enabled for user accounts on every cloud service that offers it.
"Cloud service" is broader than most organisations assume. It isn't just Microsoft 365 or Google Workspace: it's any online service holding organisational data — accounting, CRM, file sharing, HR, project tools. The service that fails the assessment is usually the one nobody remembered to list.
The password rules: pick one of three
Where passwords are still used, the scheme asks for one of these options per system. You don't have to use the same option everywhere.
| Option | Minimum length | Condition |
|---|---|---|
| 1 | 8 characters | With multi-factor authentication |
| 2 | 12 characters | On its own |
| 3 | 8 characters | With automatic blocking of common passwords (a deny list) |
Whichever you choose, there must be no maximum length. A legacy system that caps passwords at 16 characters is a finding in its own right.
What the rules don't require
A lot of what gets written about Cyber Essentials passwords is out of date or simply wrong:
- No forced expiry. Changing passwords every 30 or 90 days isn't required, and current guidance advises against it. Passwords should change when there's reason to think one has been compromised.
- No complexity rules. Mandatory symbols and mixed case aren't required. Length does more, and three random words is easier to remember.
- No 14-character tier. Some guides quote one. The scheme doesn't have it.
Protection against guessing: pick one of three
Separately from length, every login needs protection against brute-force guessing. Again, one of three:
- MFA;
- throttling to no more than 10 guesses in 5 minutes;
- lockout after no more than 10 failed attempts.
Cloud platforms usually do this by default. The gap is usually local accounts: Windows doesn't lock out local accounts unless a lockout policy has been set, so a machine can meet every other requirement and still fail this one.
Unlocking devices
Devices that someone physically uses — laptops, desktops, phones, tablets — need a PIN, password or biometric to unlock, with the same protection against guessing. A PIN or password used only to unlock the device needs at least six characters. If the same credential also signs in to other services, the full password rules above apply to it instead.
Administrator accounts
Administrator accounts are held to the same password rules, and to a stricter rule about use: they're for administration only. No email, no web browsing, no day-to-day work on an account that can change the whole system. And they need MFA on cloud services, like every other account.
Where this goes wrong in practice. It's rarely the policy. It's the exceptions: the cloud service added last month without MFA, the local account with no lockout, the old application with a length cap, the admin who reads email on their admin account. Each is easy to fix once someone knows it's there.
A quick self-check
- Is every cloud service listed, and does each have MFA on for admins and users?
- Does every system meet one of the three password options, with no maximum length?
- Does every login, including local Windows accounts, lock out or throttle after ten attempts?
- Do devices lock, with at least a six-character unlock PIN or password?
- Are administrator accounts used only for administration?
- Is there a process for changing a password promptly if it may be compromised?
Quick answers
What is the minimum password length for Cyber Essentials?
Eight characters with MFA or with a deny list of common passwords, or twelve characters on their own. Six characters for a PIN or password used only to unlock a device.
Does Cyber Essentials require passwords to be changed regularly?
No. Passwords should be changed when there's reason to think they're compromised, not on a schedule.
Is MFA mandatory for Cyber Essentials?
On cloud services that offer it, yes: for both administrator and user accounts, and a missing one is an automatic fail.