The Cyber Essentials MFA Rule That’s Failing Businesses in 2026
Of all the 2026 changes to Cyber Essentials, one trips up more businesses than any other: multi-factor authentication (MFA). It’s now a hard pass-or-fail, and the way it fails people is sneaky. Here’s exactly what’s required and how to get it right.
What the rule actually says
Multi-factor authentication — that’s the extra step where you confirm a login with a code on your phone or an app — is now mandatory on every account that accesses your organisation’s data, wherever the service offers it. Not just administrators. Everyone.
And it isn’t scored gently. One in-scope account without MFA fails the entire user-access control section. No partial marks.
Why businesses that “have MFA” still fail
Here’s the part that catches people out. Most failing businesses do use MFA on their main accounts — they just missed it somewhere less obvious. The usual culprits:
- Shared mailboxes (info@, accounts@) that several people log into.
- Business social media accounts — LinkedIn, Facebook, Instagram, X. These count as cloud services and need MFA too.
- Finance and accounting tools set up years ago and rarely touched.
- Service or admin accounts created during a software setup and forgotten.
- That one app a single team member uses that nobody else thinks about.
If the service offers MFA and it’s switched off, that’s a fail — even if every “normal” account is covered.
What counts as MFA
- An authenticator app (Microsoft Authenticator, Google Authenticator) — recommended.
- A passkey or hardware security key (FIDO2) — these count.
- A code by text message — allowed, but increasingly discouraged in favour of apps.
How to fix it: the checklist
- List every online tool your team logs into. All of them — email, accounting, CRM, file storage, marketing tools, social media. This is the step people skip, and it’s where the hidden gaps live.
- Check MFA is on for each one. Log in and look at the security settings.
- Pay special attention to shared and forgotten accounts — the ones above.
- Turn MFA on wherever it’s off, ideally using an authenticator app.
It’s genuinely not difficult once you can see the full list — the hard part is knowing every account you need to check.
The bottom line
The MFA rule isn’t there to catch you out — it’s the single most effective thing a small business can do to stay secure. But because it’s now pass-or-fail, one overlooked account costs you the certificate. The fix is simple; the trick is making sure nothing’s missed.