The Cyber Essentials MFA rule: one missing setting now fails your whole assessment
Since 27 April 2026 (requirements v3.3), the rule is blunt: if a cloud service you use offers multi-factor authentication and you haven't turned it on, your Cyber Essentials assessment automatically fails. Not marked down — failed. It doesn't matter whether MFA is free, bundled, or a paid add-on. Here's exactly what's in scope, the second auto-fail hiding beside it, and the platform-by-platform fix list.
The rule in one paragraph
Every cloud service within your assessment scope must have MFA enabled for all users — admins and standard users alike — wherever the service supports it. “Supports it” is read harshly: free feature, licence upgrade, connected identity provider — if MFA can be enabled, it must be. One service without it, answered honestly, fails the assessment outright under the v3.3 marking rules. There is no discretion and no appeal on this point.
“But what counts as a cloud service?” — the question that catches everyone
More than most organisations think. If your people sign into it over the internet and it holds or touches organisational data, it's in the frame: Microsoft 365 and Google Workspace, obviously — but also your accounting software, CRM, payroll portal, project tools, file storage, e-signature service, website admin, booking systems and remote-access tools. Two traps in particular:
- Shadow IT: the Dropbox someone set up in 2019, the Trello board with client names in it — informally adopted services are still services. Scope follows the data (our scope guide covers the device side of the same logic).
- Personal accounts touching work data: a personal Gmail receiving company files brings the arrangement into scope-conversation territory — the clean fix is proper organisational accounts, not clever answers.
The twin auto-fail nobody talks about: 14-day patching
v3.3 added a second automatic fail alongside MFA: high-risk and critical security updates must be installed within 14 days of release — across operating systems, applications, browser extensions, and (the one everyone forgets) router and firewall firmware. Answer “no” to either patching question and the assessment fails just as hard as missing MFA. For a small organisation the honest route is automatic updates everywhere they exist, plus a monthly calendar habit for the kit that can't auto-update — the router being the usual orphan.
The fix list, platform by platform
- Microsoft 365: turn on Security Defaults (Entra admin centre) or, on business plans, Conditional Access requiring MFA for all users. Check for legacy protocols still allowing basic auth.
- Google Workspace: Admin console → enforce 2-Step Verification for all organisational units, with a sensible enrolment window.
- Accounting software (Xero, QuickBooks, Sage, FreeAgent): all offer MFA — Xero already mandates it; enable and enforce for every user, including your accountant's logins.
- Everything else: inventory first — list every service anyone signs into for work, check each for an MFA setting, enable it, and record the handful that genuinely don't offer it (those you document rather than fail on).
- Method: authenticator apps or passkeys beat SMS where the choice exists — v3.3 explicitly smiles on passwordless sign-in.
Certificates issued under the old rules renew against the new ones — the standard moved underneath you. Industry estimates put tens of thousands of existing certificate holders at risk of failing renewal on MFA alone. If your assessment account was created before 27 April 2026 you had a six-month window under the old question set — that window closes in late October 2026; after it, v3.3 applies to everyone, no exceptions.
Do the five-minute check before the assessor does
List your cloud services, mark MFA yes/no on each, and check updates are set to automatic — that's most of the two auto-fails dealt with in an afternoon. Our free readiness check walks the whole question set the same way and shows what would currently fail; and if the fixing itself is the obstacle — nobody in the building owns “IT” — that gap is exactly what our fixed-price, done-for-you support exists to close.
Would you pass the two auto-fails today?
Five minutes, no sign-up: the readiness check tells you what fails before you've spent a pound — including the MFA and patching questions that now decide everything.
Take the readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd