Skip to content

Multi-factor authentication

Is MFA mandatory under v3.3?

Implement MFA wherever it is available, and for authentication to cloud services. IASME treats available MFA as including paid or connected options; a licence cost does not create an exemption. Document genuinely unsupported services with the assessor. Check user, administrator and third-party access; registration without enforcement is insufficient, while a new MFA prompt on every session is not universally required.

Short answer

Implement MFA wherever it is available, and for authentication to cloud services. IASME treats available MFA as including paid or connected options; a licence cost does not create an exemption. Document genuinely unsupported services with the assessor. Check user, administrator and third-party access; registration without enforcement is insufficient, while a new MFA prompt on every session is not universally required.

Why this matters

An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.

Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.

What to check next

  • Check every user account, not just staff with Microsoft 365 licences.
  • Disable legacy authentication paths that cannot support MFA.
  • Separate day-to-day and administrator accounts and protect both with MFA.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.