Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations treat contractor and third-party accounts differently…
Governance, Ownership & Risk

Should organisations treat contractor and third-party accounts differently in Cyber Essentials reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They should treat them as part of the same identity surface, because externally managed users often use separate browsers, local credentials, or unmanaged sign-in methods. If those accounts are excluded from reviews, the organisation can pass policy checks on paper while missing real access risk.

Why contractor and third-party accounts should be reviewed as one access population

Cyber Essentials reviews are meant to reflect actual access, not internal org charts. Contractor, supplier, partner, and outsourced support accounts often authenticate differently, use separate browsers or endpoints, and carry a distinct offboarding path, but they still create the same exposure if they can reach business systems. Treating them separately is where blind spots start.

That is why externally managed accounts should be counted in the same review population as staff accounts, then assessed for sponsor ownership, business need, and expiry. A separate label does not make them a separate risk class if they can log in, hold privileges, or access the same data.

What changes when an account is external to the organisation?

The account is often created, used, and retired under different operational assumptions. The organisation may not control the user’s device, password hygiene, browser state, or local session persistence, and it may have less visibility into how the account is actually used day to day. That makes the review question less about employment status and more about control boundary.

In practice, the same identity can be higher risk when it is externally managed because the account may be shared across projects, kept alive past the work end date, or used through a federated path that looks legitimate but bypasses normal corporate endpoint controls. The access path matters as much as the account label.

For third-party access models and governance patterns, see Third-Party, B2B and Contractor Access Guide and the broader identity control baseline in IAM and IGA Basics.

How to review external accounts without creating false comfort

Start with inventory, then ask whether the account is sponsored, time-bound, and tied to a named business owner. Reviews should confirm that access still has a current business purpose, that the entitlement matches the task, and that any federation, shared mailbox, or vendor portal access is still needed. If the answer depends on an external manager, verify the control with evidence rather than assumption.

Reviews should also look for drift between the access method and the review record. A contractor may be approved as a named user, while the real access path is a shared vendor account, a long-lived token, or a local credential on an unmanaged laptop. When that happens, the review passes administratively but fails operationally.

NHIMG’s Top 10 NHI Issues is useful here because many external-access failures show up as the same patterns of sprawl, over-privilege, stale access, and weak offboarding.

When contractor and third-party accounts become a material review risk

The risk rises when external accounts are excluded from recertification, reviewed only by list membership, or left without an expiry date. That creates a clean policy report while leaving live access in place. It also increases the odds that a stolen external credential, reused login, or forgotten supplier account becomes an easy entry point into internal systems.

Externally managed accounts also tend to carry more third-party dependency risk. If the vendor’s own access governance is weak, the organisation can inherit over-privilege, delayed revocation, or poor session discipline without seeing it directly. Those are review failures as much as they are technical failures.

For incident patterns that show how third-party access turns into real compromise, Scania insurance portal breach 2025 and Marks and Spencer cyberattack 2025 are both strong reminders that external-user handling is not a paperwork issue.

Risk and Threat Considerations

External accounts are attractive because they often sit outside normal corporate controls, yet still reach sensitive systems. If they are excluded from review cycles, the organisation can retain dormant access, miss unmanaged sign-in methods, or overlook a compromised vendor login that is still trusted by the target environment.

Failure mechanism: The review process counts the account as “third party” and therefore outside scope, while the actual access path remains live, privileged, and insufficiently governed. Attackers or careless users then exploit that control gap through stale access, shared credentials, or unmanaged session reuse.

Impact: Organisations can lose visibility into who can reach production systems, fail to revoke access after work ends, and create a straightforward route for data theft or account takeover without any policy exception appearing in the review output.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)External contractor accounts are non-organizational users needing controlled authentication.
AC-2 — Account ManagementContractor and third-party accounts need inventory, review, and timely disabling.
IA-5 — Authenticator ManagementExternal accounts often depend on passwords, tokens, or other authenticators that must be rotated and retired.
Recommendation — Apply IA-8 to authenticate and govern external user accounts with the same review rigor as internal users. Use AC-2 to recertify, expire, and disable external accounts on schedule. Use IA-5 to manage external authenticators through rotation, revocation, and lifecycle control.
ISO/IEC 27001:2022A.5.18 — Access rightsExternal accounts require periodic review and removal when access is no longer needed.
A.5.19 — Information security in supplier relationshipsThird-party accounts are governed through supplier security expectations and oversight.
A.5.20 — Addressing information security within supplier agreementsContractor access should be contractually bounded, including ownership and revocation terms.
Recommendation — Review and revoke third-party access rights when the business need ends. Define supplier access expectations and verify them during access reviews. Embed access review, sponsorship, and offboarding obligations in supplier agreements.
CIS Controls v8CIS-5 — Account ManagementExternal accounts must be inventoried, reviewed, and removed when no longer needed.
CIS-6 — Access Control ManagementThird-party access should be limited to the minimum needed and regularly reviewed.
Recommendation — Inventory and disable contractor and third-party accounts with the same account-management process as employees. Restrict external access to least privilege and review entitlements routinely.
SOC 2 (AICPA)CC6.1 — Logical and Physical Access ControlsThe subject concerns access control over external users and review of who can reach systems.
Recommendation — Verify that logical access for contractors and third parties is authorised, approved, and removed when no longer needed.

Practitioner Guidance

What to verify: Confirm that contractor and third-party accounts appear in the same recertification population as employee accounts, even if the approval workflow is different. The review should show owner, sponsor, expiry, and current business purpose for each external identity.

Decision rule: If an externally managed account can authenticate to a business system, treat it as in-scope for access review and offboarding controls. If the access cannot be tied to a named sponsor or a time-bound need, escalate it as an exception rather than accepting it as “vendor-owned”.

Practitioner takeaway: The key judgement is not whether the user is employed by you, it is whether the access is still active, justified, and revocable under your control.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org