All guidesMFA deep-dive

The Cyber Essentials MFA Rule That’s Failing Businesses in 2026

Of all the 2026 changes to Cyber Essentials, one trips up more businesses than any other: multi-factor authentication (MFA). It’s now a hard pass-or-fail, and the way it fails people is sneaky. Here’s exactly what’s required and how to get it right.

What the rule actually says

Multi-factor authentication — that’s the extra step where you confirm a login with a code on your phone or an app — is now mandatory on every account that accesses your organisation’s data, wherever the service offers it. Not just administrators. Everyone.

And it isn’t scored gently. One in-scope account without MFA fails the entire user-access control section. No partial marks.

Why businesses that “have MFA” still fail

Here’s the part that catches people out. Most failing businesses do use MFA on their main accounts — they just missed it somewhere less obvious. The usual culprits:

  • Shared mailboxes (info@, accounts@) that several people log into.
  • Business social media accounts — LinkedIn, Facebook, Instagram, X. These count as cloud services and need MFA too.
  • Finance and accounting tools set up years ago and rarely touched.
  • Service or admin accounts created during a software setup and forgotten.
  • That one app a single team member uses that nobody else thinks about.

If the service offers MFA and it’s switched off, that’s a fail — even if every “normal” account is covered.

What counts as MFA

  • An authenticator app (Microsoft Authenticator, Google Authenticator) — recommended.
  • A passkey or hardware security key (FIDO2) — these count.
  • A code by text message — allowed, but increasingly discouraged in favour of apps.

How to fix it: the checklist

  1. List every online tool your team logs into. All of them — email, accounting, CRM, file storage, marketing tools, social media. This is the step people skip, and it’s where the hidden gaps live.
  2. Check MFA is on for each one. Log in and look at the security settings.
  3. Pay special attention to shared and forgotten accounts — the ones above.
  4. Turn MFA on wherever it’s off, ideally using an authenticator app.

It’s genuinely not difficult once you can see the full list — the hard part is knowing every account you need to check.

The bottom line

The MFA rule isn’t there to catch you out — it’s the single most effective thing a small business can do to stay secure. But because it’s now pass-or-fail, one overlooked account costs you the certificate. The fix is simple; the trick is making sure nothing’s missed.