Cyber Essentials outlines clear requirements for password-based authentication. These are designed to protect small and medium-sized businesses from common cyber threats. Here’s our straightforward guide to what your password policy needs to include to meet the latest Cyber Essentials requirements.
Passwords Must Be Unique
Every user account must be secured with a unique password. This means no shared logins and no default passwords left unchanged.
Passwords Must Be Protected
To protect against brute-force attacks (where attackers try many passwords quickly), you must implement at least one of the following:
- Multi-factor authentication (MFA)
- Throttling login attempts (e.g. increasing wait time after each failed attempt)
- Locking accounts or devices after 10 failed attempts
Set Minimum Password Lengths
Cyber Essentials allows two routes here. Passwords must have:
- A minimum of 12 characters
- Or, a minimum of 8 characters, combined with automatic blocking of common passwords (using a deny list to block common or simple passwords like “password123”)
You should not set a maximum password length, although where a system has a maximum limit due to a technical constraint, this is fine.
Avoid Complexity Rules and Expiry Policies
Contrary to older advice, Cyber Essentials recommends:
- Not enforcing regular password changes
- Not requiring complex combinations of symbols and numbers
These rules often lead to weaker passwords or users writing them down. Instead, you should encourage users to create passphrases made from three or more random words. The NCSC encourages organisations to teach their users the “Three random words” method for choosing strong and secure passwords (Three random words – NCSC.GOV.UK).
Support Your Users in Creating Strong Passwords
Your password policy should help your staff make good choices by:
- Educating them about avoiding common passwords
- Promoting the use of password managers or secure storage
- Encouraging the use of the three random words technique
This makes it easier for users to remember secure passwords without resorting to risky habits.
Use Multi-Factor Authentication (MFA) Wherever Possible
MFA adds an extra layer of protection. In Cyber Essentials, it’s required for:
- All cloud services
- All administrative accounts
Acceptable second factors include apps on trusted devices, physical tokens, or push notifications. While SMS is allowed, more secure options are preferred.
Have a Process for Password Changes
If a password is suspected to be compromised, there must be a clear and prompt process for resetting it. This helps limit the damage from phishing or data leaks.
Passwordless Options Are Encouraged
Cyber Essentials now recognises passwordless authentication methods. These include:
- Biometrics (like fingerprint or facial recognition)
- Security keys or tokens
- One-time codes or push notifications
These methods can reduce the risks associated with traditional passwords and improve user experience.
A Cyber Essentials-compliant password policy should support a culture of security that protects your business, your staff, and your customers. As with all the controls Cyber Essentials requires you to implement, by following the criteria above, you’ll not only meet the certification requirements but also strengthen your organisation’s overall cyber resilience.
We provide free template policies and procedures that are fully compliant with Cyber Essentials requirements. These resources are available to all our customers, helping to simplify implementation and ensure alignment with best practices.
Evolve North is a Cyber Essentials Certification Body and an NCSC Assured Service Provider for the Cyber Advisor scheme. Our consultants are certified to provide clear, jargon free advice that’s tailored to your organisation’s needs. We are not a software reseller, which means we’re perfectly positioned to provide vendor-agnostic, practical guidance based on what’s best for your organisation.
Need support with Cyber Essentials compliance or password policy implementation? Call us on 01748 905 002 or email info@evolvenorth.com to speak to a consultant.
