Cyber Essentials MFA Requirements (2026)
Exactly what multi-factor authentication is required under the Danzell question set, in force since 27 April 2026 – cloud admins, all users, BYOD and the documented exceptions.
Where MFA must be enabled
Cloud admin accounts
Mandatory MFA. No exceptions for IT admins, tenant admins, billing admins.
All cloud user accounts
Mandatory under the Danzell question set (live since 27 April 2026). Microsoft 365, Google Workspace, AWS, Azure, SaaS apps.
BYOD devices
MFA applies to the cloud account, not the device. Required if device touches in-scope services.
Remote access (VPN)
MFA required for any remote admin or user access to internal systems.
Accepted MFA methods
- Authenticator apps – Microsoft Authenticator, Google Authenticator, Authy. Preferred.
- Passkeys (FIDO2) – explicitly accepted under the Danzell question set (live since 27 April 2026). Strongest method.
- Hardware tokens – YubiKey, Titan key, Feitian.
- Push notifications – e.g. Microsoft Authenticator approve/deny prompt.
- SMS or voice codes – accepted but no longer best practice; phasing out is recommended.
Not accepted as MFA: email codes alone, security questions, or "remembered device" alone.
Common Cyber Essentials MFA failures
- MFA enabled for admins only, missed for general users (now a fail under Danzell).
- Legacy authentication (POP, IMAP, SMTP basic auth) still enabled in Microsoft 365, allowing MFA bypass.
- Service accounts with no compensating controls and no documented exception.
- Conditional Access policies that exempt entire IP ranges – the assessor will challenge this.
- SaaS apps not federated to the main IdP and missing MFA entirely.
What the Danzell question set changed (live since 27 April 2026)
The Danzell question set – which went live on 27 April 2026 and now underpins every Cyber Essentials assessment – tightened MFA in three meaningful ways:
- Scope extended to all cloud user accounts, not only admins.
- Passkeys explicitly accepted as a valid MFA method.
- Bypass paths must be confirmed closed – e.g. legacy authentication must be disabled in Microsoft 365.
Renewing your certificate? See the Cyber Essentials Renewal guide for the full list of changes now in force.
