Short answer
Implement MFA wherever it is available, and for authentication to cloud services. IASME treats available MFA as including paid or connected options; a licence cost does not create an exemption. Document genuinely unsupported services with the assessor. Check user, administrator and third-party access; registration without enforcement is insufficient, while a new MFA prompt on every session is not universally required.
Why this matters
An MFA licence or registration is not proof of enforcement. Check the actual authentication paths: MFA is required where available, and cloud authentication must use MFA.
Assessors need to understand user, administrator and third-party access. Verify effective policies and prevent bypasses of mandatory cloud MFA. Phishing-resistant administrator authentication is strong additional practice; a fresh prompt on every request is not a universal scheme rule.
What to check next
- Check every user account, not just staff with Microsoft 365 licences.
- Disable legacy authentication paths that cannot support MFA.
- Separate day-to-day and administrator accounts and protect both with MFA.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.