Skip to main content

Cyber Essentials changed its MFA rules in April 2026. Here's what to update.

Cyber Essentials

Cyber Essentials updated its multi-factor authentication (MFA) rule in April 2026. The short version: if an account supports two-factor authentication, you should have it switched on.

It's an easy one to overlook, because it now covers the everyday accounts people used to skip, not just email and admin logins.

Here's what changed, and a simple order to work through your own accounts.

What changed in April 2026

Until April 2026, Cyber Essentials required 2FA on specific account types: email, admin access, and remote working systems. Everything else was optional.

The April 2026 update changed that. The new requirement is simpler: if an account supports two-factor authentication, you should be using it. There's no longer a distinction between accounts that need it and ones that don't.

In practice, that means every piece of software your business uses day-to-day: email, accounting, cloud storage, project management, social media, payment platforms. If it offers 2FA, turn it on.

The accounts most businesses need to check

The gaps are usually in the same places. Business email is often already covered. Accounting software frequently isn't. Cloud storage tends to be mixed: on for some accounts, off for others. Business social media is often patchy.

The aim is 2FA active on every account that supports it. The most common method is an authenticator app on your phone. Google Authenticator and Microsoft Authenticator are both free.

Why this matters for Cyber Essentials

This change applies to any Cyber Essentials assessment from April 2026 onwards. If you're preparing for certification, your assessor will check that 2FA is active on all accounts that support it. It's not a grey area in the updated guidance.

The wider reason this matters: most breaches start with a stolen password. Someone clicks a phishing link, enters their login on a fake page, and the attacker has their credentials. With 2FA active, that stolen password is useless on its own. The attacker would also need access to your phone.

Accounts that look low-stakes often aren't. Your accounting software has bank feeds and financial data. Your business social media can be used to impersonate the company. Cyber Essentials is trying to close those gaps across the board, not just on the accounts we've traditionally treated as high value.

How to work through it

Go account by account. A sensible order:

  1. 1

    Business email.

    Google Workspace or Microsoft 365. Your email is the master key to everything else: if someone gets in there, they can reset every other password you own. Look in Security settings. Two-step verification will be listed there.

  2. 2

    Accounting software.

    Xero, QuickBooks, and FreeAgent all support it. Settings > Security in each.

  3. 3

    Cloud storage.

    Google Drive, Dropbox, and OneDrive. Same process.

  4. 4

    Everything else.

    Any other tools your team uses daily: project management, CRM, payment platforms, business social media.

If you're not sure where to start, begin with the accounts that hold money or client data. Then work outward from there.

If you're working towards Cyber Essentials and want a clear view of where you stand across all five controls, Cyber Nova AI is free to use. cybernovaai.co.uk

Related guide

How to Prepare for Cyber Essentials Certification

A plain-English walkthrough of the five controls, the self-assessment process, and what to expect at each step.

Get your free Security Score

See exactly how your business scores against all five Cyber Essentials controls, including the updated MFA requirements. Free to start, no credit card required.

Register free