Skip to main content
    NixInfinity-AI
    Google Workspace

    Cyber Essentials Checklist for Google Workspace

    Published 30 April 2026

    The Google Workspace settings the assessor will look for

    1. 2-Step Verification (2SV) enforced for everyone

    Admin console > Security > Authentication > 2-Step Verification. Set Enforcement to "On for everyone" with no enrolment grace period for new users. Acceptable methods: security keys, Google prompts, authenticator apps, backup codes. SMS is permitted but no longer best practice.

    2. Less Secure Apps disabled

    Admin console > Security > Less Secure Apps > "Disable access". This blocks legacy authentication that bypasses 2SV.

    3. Strong password policy

    Admin console > Security > Password management. Minimum length 12 characters, prevent password reuse, enforce on next sign-in.

    4. Context-aware access (recommended)

    Restrict access by device type, location or IP. Not strictly required, but a strong control that helps with assessor confidence.

    5. Advanced Mobile Management

    Devices > Mobile & endpoints > Settings. Enforce screen lock, encryption and remote wipe on managed devices.

    6. Admin role separation

    Super Admin accounts must not be used for day-to-day email or web browsing. Create separate admin accounts and protect them with hardware security keys.

    Evidence for the assessor

    • Screenshot of 2SV enforcement page showing "On for everyone"
    • Screenshot of Less Secure Apps "Disable access"
    • Screenshot of password policy
    • List of Super Admin accounts and their named owners
    • Mobile device list from Devices console

    Companion guides

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions