CYBER ESSENTIALS
Cyber Essentials MFA Requirements
A password alone is no longer enough.

Passwords can be stolen, guessed, reused or compromised through phishing attacks and other exposures. Walk through any corporate office after hours and chances are you will stumble across a telltale post it note or two with words that look suspiciously like they may be someone’s password.
Multi-factor authentication (MFA) provides an additional layer of protection by requiring users to prove their identity in more than one way.
Under Cyber Essentials, multi-factor authentication must be used for access to cloud services, where the service supports MFA.
This is particularly important for accounts with access to sensitive information, business systems or administrative functions.
Password compromised + MFA enabled = an attacker still has another security barrier to overcome.
MFA is one of the simplest and most effective ways of reducing the risk of account compromise.
Where MFA Applies
For Cyber Essentials, MFA is particularly relevant to cloud services.
That can include services used for:
- File storage and sharing
- Microsoft 365 and Google Workspace
- CRM and accounting platforms
- Cloud infrastructure
- HR and payroll systems
- Collaboration platforms
- Remote administration
- Other cloud-hosted business applications
If users access an organisational cloud service, MFA should be enabled where the service provides the capability.
Don't forget administrators
Administrative and privileged accounts deserve particular attention.
These accounts can often change configurations, create users, access sensitive information or alter security controls.
Compromise of an administrator account can therefore be considerably more damaging than compromise of a standard user account.
The greater the privilege, the greater the potential impact of compromise.
What Counts as MFA?
MFA requires more than one form of authentication.
Typically, this combines two or more different factors:
Something you know
A password or PIN.
Something you have
A smartphone, authenticator application, security token or hardware key.
Something you are
A biometric characteristic such as a fingerprint or facial recognition.
The important point is that simply asking for two passwords or two pieces of memorable information isn't true multi-factor authentication. They are both examples of "something you know".
Not all MFA methods are equally strong
SMS codes can provide an additional layer of security, but authenticator apps, passkeys and hardware security keys can offer stronger protection against certain attacks.
Where possible, organisations should use the strongest practical authentication methods supported by their systems.
Common MFA Gaps
This is the section I'd make particularly practical, because organisations can quite easily believe they have "implemented MFA" while leaving significant holes.
MFA enabled — but not for everyone
MFA may have been introduced for administrators or senior staff while other users remain protected only by passwords.
Check: Are all relevant cloud-service users covered?
Forgotten administrator accounts
Old or rarely used administrative accounts can sometimes escape normal MFA policies.
Check: Are all privileged accounts protected?
Legacy authentication
Older applications or protocols may sometimes bypass modern authentication controls.
Check: Are legacy authentication methods still enabled unnecessarily?
New users aren't automatically enrolled
MFA may be configured correctly for existing employees but not consistently applied when new accounts are created.
Check: Is MFA part of your standard user onboarding process?
Former users remain active
An account belonging to somebody who has left the organisation may remain accessible. MFA isn't a substitute for good user-access management.
Check: Are unused and former user accounts promptly disabled or removed?
Exceptions have become permanent
Temporary MFA exclusions are sometimes created for troubleshooting, applications or individual users and then forgotten.
Check: Regularly review exclusions and exceptions.
MFA exists but isn't enforced
There is an important difference between MFA being available and MFA being required. Giving users the option to enable MFA is not the same as enforcing it.
Check: Can a user still sign in using only a password? If the answer is yes, you may still have a gap.
Why This Matters
Consider what happens when an employee's username and password are captured through a convincing phishing email.
Password only
Username + stolen password → Account access
The attacker potentially has everything they need.
Password + MFA
Username + stolen password → Additional authentication required → Attack potentially stopped
The password can still be compromised, but the attacker has another barrier to overcome.
This is why MFA is so effective.
It doesn't make passwords irrelevant and it doesn't eliminate every form of attack, but it can significantly reduce the likelihood that a stolen password alone results in a successful account takeover.
Practical MFA Checklist
When reviewing your organisation, ask:
- Which cloud services do we use?
Create an inventory rather than relying on memory. - Who has access to them?
Include employees, administrators, contractors and third parties. - Does each service support MFA?
Determine what authentication options are available. - Is MFA actually enforced?
Don't confuse availability with enforcement. - Are administrator accounts covered?
Privileged accounts should receive particular attention. - Are there exclusions?
Identify users, applications or authentication methods bypassing normal MFA policies. - Are unused accounts disabled?
Remove access when it is no longer required. - Is MFA checked when new users are created?
Make secure authentication part of the onboarding process. - Are authentication controls reviewed regularly?
People, systems and access requirements change.
Related Guidance
MFA shouldn't operate in isolation. It forms part of a broader approach to controlling who can access your systems and what they can do once authenticated.
- User Access Control — ensuring users only receive the access they genuinely require.
- Administrative Privileges — limiting powerful administrator permissions.
- Password Security — protecting authentication credentials.
- Account Management — removing obsolete and unused accounts.
- Secure Configuration — ensuring authentication and security controls are configured appropriately.
Together, these controls answer three fundamental questions:
Who are you? → What are you allowed to access? → Do you still need that access?
How SecureX7 Helps
The challenge isn't understanding that MFA is important. The challenge is knowing whether your security controls are configured correctly and consistently.
SecureX7 helps organisations assess their security posture and identify configuration weaknesses that can leave systems unnecessarily exposed.
By continuously assessing configuration against recognised security requirements, SecureX7 can help teams identify areas requiring attention, understand the associated risk and take appropriate remediation action.
Rather than relying solely on questionnaires, assumptions or occasional manual reviews, organisations gain greater visibility into their actual security posture.
Assess. Identify the gap. Understand the risk. Remediate. Reassess.
Cyber Essentials isn't about answering questions correctly. It's about making sure your environment is configured correctly.


