Cyber Essentials requires multi-factor authentication for cloud services wherever MFA is available. This applies to ordinary user accounts as well as administrator accounts. If a cloud service offers MFA as a free, included or paid option, leaving it disabled can cause the assessment to fail.

The requirement is broader than protecting privileged administrators. Organisations need to identify every in-scope cloud service and ensure that the people who authenticate to it use MFA, regardless of whether they have standard or administrative access.

This includes familiar platforms such as Microsoft 365 and Google Workspace, but it can also include accounting systems, customer relationship management platforms, file-sharing services, HR systems, code repositories, backup platforms and other services that store or process organisational data.

What the Cyber Essentials MFA requirement means

For Cyber Essentials, authentication to an in-scope cloud service must use MFA wherever the service makes it available. It is not enough to enable MFA only for global administrators, IT staff or other privileged users.

  • Standard user accounts accessing cloud services need MFA.
  • Administrator and other privileged cloud accounts need MFA.
  • MFA must be used if it is free, included in the subscription or available as a paid option.
  • Cloud services that store or process organisational data must be considered in scope.
  • Services cannot simply be excluded because enabling MFA is inconvenient.

The current Cyber Essentials requirements published by the NCSC state that authentication to cloud services must always use MFA where it is available. IASME also confirms that failure to implement it for cloud services results in an automatic assessment failure.

Important distinction: the cloud-service rule applies to both normal and administrative users. Cyber Essentials also expects organisations to control administrative privileges carefully, use separate administrative accounts and protect those accounts with MFA where available.

What counts as a cloud service?

Cyber Essentials describes a cloud service as an on-demand, scalable service hosted on shared infrastructure and accessed through the internet. For assessment purposes, it is typically accessed using an account and stores or processes data for the organisation.

The definition reaches beyond infrastructure platforms such as AWS, Microsoft Azure and Google Cloud. Most organisations use a much wider collection of software-as-a-service products that must also be reviewed.

Productivity and email

Microsoft 365, Google Workspace, hosted email, document sharing and collaboration platforms.

Business applications

CRM, accounting, payroll, HR, project management and customer-support systems.

Technical platforms

Cloud hosting, source-code repositories, monitoring, backup, remote support and administration tools.

Specialist services

Industry platforms, supplier portals and other online services that store or process business information.

A service does not fall outside the requirement merely because it is used by only one department or purchased directly by an employee. Shadow IT is one of the reasons a cloud-service inventory is essential.

Which accounts require MFA?

Account type Does it require MFA? What to check
Normal user accessing a cloud service Yes, where MFA is available Confirm MFA is enforced, not merely offered as an optional enrolment.
Cloud administrator Yes, where MFA is available Use a separate administrative account and avoid using it for routine work.
External user or contractor Yes, if the account authenticates to an in-scope cloud service Check guest, partner and supplier access rather than assuming their organisation enforces MFA.
Shared account MFA does not make a shared account good practice Replace shared access with identifiable individual accounts wherever possible.
Service or machine identity Needs separate technical consideration Use an appropriate non-interactive authentication method and restrict privileges; do not treat it as a human login.

Accepted authentication methods

MFA uses two or more independent factors. These may include something the user knows, something they possess or something inherent to them. Passwordless methods such as properly implemented passkeys can also satisfy the requirement because authentication combines possession of the authenticator with user verification.

Passkeys and security keys

Phishing-resistant options based on public-key cryptography. Strong choices for administrators and higher-risk access.

Authenticator applications

Time-based codes or number-matching prompts are widely supported and stronger than password-only access.

Push approval

Convenient, but configure number matching or additional context to reduce accidental approval and MFA fatigue attacks.

SMS or email codes

These add protection but are more vulnerable to interception and account compromise than phishing-resistant methods.

The best method is one that the service supports, users can operate reliably and the organisation can recover securely. Where practical, favour phishing-resistant authentication such as passkeys or hardware security keys, particularly for privileged accounts.

How to prepare for assessment

  1. Build a cloud-service inventory. Include centrally managed platforms and services purchased or used by individual teams.
  2. Identify every account. Review normal users, administrators, guests, contractors, emergency accounts and dormant access.
  3. Check whether MFA is available. Record whether it is included, free or requires a different subscription. A paid option still counts as available.
  4. Enforce MFA. A policy that allows users to opt in is weaker than central enforcement. Confirm that unenrolled users cannot continue signing in with only a password.
  5. Deal with legacy authentication. Disable older protocols and interfaces that can bypass the normal MFA process.
  6. Separate administrator access. Give administrators distinct privileged accounts and use them only when elevated access is required.
  7. Plan secure recovery. Protect backup methods and recovery codes. Test the process without creating an easy route around MFA.
  8. Collect evidence. Keep policy settings, account reports and other evidence that shows MFA is enforced across the assessment scope.

If you are unsure whether your services and accounts meet the requirements, use the Cyber Essentials readiness assessment before submitting your certification application.

Common reasons organisations get this wrong

Protecting administrators but not normal users

This is the main misunderstanding. Administrator protection is essential, but it does not satisfy the cloud-service requirement on its own. Ordinary users also authenticate to the service and can expose organisational data if their credentials are stolen.

Enabling MFA without enforcing it

An MFA feature may be switched on while enrolment remains optional. Check the effective policy and test it with representative accounts.

Missing departmental cloud services

Finance, HR, sales and development teams may use different platforms. An inventory based only on services managed by IT is often incomplete.

Assuming paid MFA does not count as available

IASME explicitly states that the requirement applies whether MFA is free, included or offered as a paid option. Cost does not make an available control unavailable.

Leaving a bypass route

Legacy mail protocols, application passwords, poorly controlled recovery processes or excluded user groups may allow password-only access even when the main login screen uses MFA.

Frequently asked questions

Is MFA mandatory for all Cyber Essentials cloud users?

Yes. Where an in-scope cloud service makes MFA available, authentication to that service must use it. This includes ordinary users and administrators.

Is MFA only required for administrator accounts?

No. That was a common misunderstanding. Administrative accounts require strong protection, but the Cyber Essentials requirement for cloud services applies to normal user accounts as well.

What if MFA costs extra?

If the provider offers MFA as a paid option, IASME treats it as available. The organisation must enable it or choose a service and subscription that can meet the requirement.

Can a cloud service be excluded from the assessment scope?

Cloud services that store or process organisational data must be considered in scope and cannot simply be excluded to avoid the control requirements.

Does passwordless authentication count as MFA?

It can. Properly implemented passkeys and FIDO2 authenticators are recognised as MFA because possession of the authenticator is combined with user authentication, such as a device PIN or biometric check.

Are SMS codes acceptable?

One-time codes sent by SMS are a form of additional authentication, although stronger phishing-resistant methods are preferable. Use the strongest practical method supported by the service.

Does MFA replace strong passwords?

No. Where passwords remain in use, they must still meet the relevant Cyber Essentials requirements. MFA reduces the harm caused by credential theft but does not remove the need for sound password and account management.

Check the whole cloud estate

The practical task is not simply enabling MFA in Microsoft 365 and declaring the work complete. Certification requires a defensible view of the cloud services in scope, the people who access them and the controls that actually apply when they sign in.

Review normal users and administrators, close bypass routes, protect recovery methods and keep enough evidence to demonstrate that MFA is enforced. This strengthens the organisation as well as preparing it for assessment.

Need help preparing for Cyber Essentials?

I help UK organisations identify gaps, implement the required controls and prepare evidence for Cyber Essentials and Cyber Essentials Plus.

Cyber Essentials services