Cyber Essentials Checklist for Google Workspace
Published 30 April 2026
The Google Workspace settings the assessor will look for
1. 2-Step Verification (2SV) enforced for everyone
Admin console > Security > Authentication > 2-Step Verification. Set Enforcement to "On for everyone" with no enrolment grace period for new users. Acceptable methods: security keys, Google prompts, authenticator apps, backup codes. SMS is permitted but no longer best practice.
2. Less Secure Apps disabled
Admin console > Security > Less Secure Apps > "Disable access". This blocks legacy authentication that bypasses 2SV.
3. Strong password policy
Admin console > Security > Password management. Minimum length 12 characters, prevent password reuse, enforce on next sign-in.
4. Context-aware access (recommended)
Restrict access by device type, location or IP. Not strictly required, but a strong control that helps with assessor confidence.
5. Advanced Mobile Management
Devices > Mobile & endpoints > Settings. Enforce screen lock, encryption and remote wipe on managed devices.
6. Admin role separation
Super Admin accounts must not be used for day-to-day email or web browsing. Create separate admin accounts and protect them with hardware security keys.
Evidence for the assessor
- Screenshot of 2SV enforcement page showing "On for everyone"
- Screenshot of Less Secure Apps "Disable access"
- Screenshot of password policy
- List of Super Admin accounts and their named owners
- Mobile device list from Devices console
