Join our Newsletter — 33% off our NHI Course

Cyber Essentials 2026 and SaaS MFA gaps: are your controls ready?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Cyber Essentials 2026 will widen compliance scope to any cloud service accessed with a business email or account, and require MFA to be enforced wherever it is available, according to Push Security. The shift exposes shadow apps, ghost logins, and incomplete app visibility as governance failures, not just audit issues.

Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “Cyber Essentials April 2026 update: Mandatory MFA on ALL cloud services (and how Push can help)”.

Key questions

Q: What breaks when SaaS apps are used outside SSO and central IAM?

A: The main failure is lifecycle control.

Q: Why do apps with optional or add-on MFA create audit risk?

A: Optional MFA creates risk because the organisation cannot assume protection at the account level unless it is enforced on every in-scope login.

Q: How should security teams handle MFA gaps across SaaS applications?

A: Security teams should treat SaaS MFA as a coverage problem, not a single control deployment.

Practitioner guidance

  • Map the true SaaS access surface Build an inventory from observed browser logins, not only from the IdP application list, so shadow apps and alternate credentials are visible.
  • Eliminate parallel login paths Review each in-scope app for local passwords, personal email sign-ins, and other fallback methods that can bypass the federated route.
  • Verify MFA at the account level Check whether MFA is enforced on every account, not merely available in the tenant, and remove exceptions that leave ghost logins active.

Bottom line: Cyber Essentials 2026 shifts the problem from proving that SSO exists to proving that every in-scope SaaS login path is protected and visible.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 11 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Cyber Essentials 2026 turns SaaS login paths into a governance problem, not an attestation afterthought. The scheme now reaches beyond the IdP boundary and into every cloud service accessed with a business account, which means visibility of the real authentication path becomes the control surface. Organisations that still equate SSO coverage with complete access governance will miss the accounts most likely to fail assessment.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: Should organisations treat contractor and third-party accounts differently in Cyber Essentials reviews?

A: They should treat them as part of the same identity surface, because externally managed users often use separate browsers, local credentials, or unmanaged sign-in methods. If those accounts are excluded from reviews, the organisation can pass policy checks on paper while missing real access risk.

👉 Read our full editorial: Cyber Essentials 2026 expands the identity gap in SaaS access


This post was modified 11 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.