Willow A5.5

If yes to question A5.4, which authentication option do you use?

Section A5: Secure Configuration  ·  Cyber Essentials Willow

Restructured in Willow to present authentication as a clear tiered choice.

What this question is really asking

Select the authentication method protecting your external-facing services. Option A (multi-factor authentication) is the preferred and strongest choice. Option B covers certificate-based authentication. Option C covers password-only access, subject to the standard's password strength requirements. MFA is required for cloud services under A7 and is increasingly the expected baseline for all external services.

What satisfies this requirement

A MFA + min 8 chars
B Automatic blocking of common passwords + min 8 chars
C Min 12 chars
D Passwordless (describe)
E None of the above (describe)
Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

Option A (MFA) is by far the safest choice and the clear direction the standard is heading. If you are using option C (password only) for any service, be prepared to demonstrate technical enforcement of the password requirements — assessors will probe this specifically. If cloud services are involved, MFA is mandatory under A7 regardless, so aligning everything to option A is the most coherent approach.

How this question sits across CE versions

Willow You are here
If yes to question A5.4, which authentication option do you use?
Montpellier View →
If yes to question A5.4, which option of password-based authentication do you use?
Danzell View →
If yes to question A5.4, which authentication option do you use?

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.