Skip to main content
    NixInfinity-AI
    Five Controls

    Cyber Essentials Access Control Requirements

    Published 8 June 2026

    What the control covers

    User access control is one of the five Cyber Essentials technical controls. The principle is simple: only people who need access have it, and the most powerful accounts are protected and used sparingly. The IASME question set translates that into specific requirements.

    What you must demonstrate

    1. Every account belongs to a real person

    Or, where it doesn't (service accounts, shared mailboxes), there's a documented owner and a reason. Old leaver accounts are an immediate flag. Run an admin export of M365 or Google Workspace and reconcile against your HR list before you submit.

    2. New starters get access through a documented process

    The process doesn't need to be heavy. A one-page note that says "manager raises ticket, IT provisions standard role, MFA enrolled within 24 hours" is enough for a small business. The assessor wants to see it isn't ad-hoc.

    3. Leavers lose access promptly

    The standard expectation is access disabled within one working day of departure. For trusted-role leavers, faster. Document who triggers it and how it's confirmed.

    4. Admin and standard accounts are separated

    The CTO browses the web and reads email as a standard user. They use a separate admin account for elevation, with stronger MFA and no email enabled on it. This is the single most-missed item among small UK businesses.

    5. MFA on every cloud user account

    Under the current Danzell question set, MFA must be on every cloud user account – not just admins. The fail pattern is one third-party SaaS no one remembered (the tax-return tool, the design app, the mailing-list service). See our MFA requirements guide.

    6. Strong authentication for admins

    Admin MFA should where possible use a stronger second factor – authenticator app or FIDO2 key, not SMS. Cyber Essentials doesn't ban SMS outright, but the direction of travel is clear.

    Service accounts – the awkward middle

    Cron jobs, integrations, monitoring tools – these accounts can't easily do MFA. Cyber Essentials accepts service-account exemptions if:

    • Each is documented (purpose, owner, scope of access).
    • The credential is long, random and stored in a secrets manager.
    • Access is restricted to the IPs or systems that need it.
    • The credential is rotated periodically.

    What assessors look at

    • An export of all active M365 / Google Workspace accounts with last-login dates.
    • The leavers list against the active-account list.
    • MFA enforcement evidence (Conditional Access policy or 2-step verification report).
    • A short admin-separation note – which accounts are admin, who uses them.
    • A short service-accounts list with purposes and owners.

    Where teams slip

    • One leaver missed because the manager didn't raise the ticket.
    • The founder still using their global admin for daily email.
    • MFA on M365 but not on the marketing team's standalone Mailchimp.
    • A shared mailbox with a static password and no MFA.
    • Admin role assigned "temporarily" 14 months ago and never removed.

    Sit alongside secure configuration and firewalls, this completes the human-side half of the five controls.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions