MFA must cover the cloud services in scope
Multi-factor authentication is mandatory for cloud services where it is available. Under the updated marking criteria, leaving it disabled can result in an automatic failure, whether the option is free, included with the service or paid for separately.
That means checking more than Microsoft 365. Review every business cloud account that stores or processes company data, including finance, CRM, backup, remote access and line-of-business platforms.
Critical updates need evidence, not good intentions
The assessment now places greater weight on installing high-risk or critical security updates within 14 days. The checks cover operating systems, router and firewall firmware, applications, and associated files or extensions.
A practical readiness review should identify who owns each update process, how failures are reported and how the business proves that every in-scope device is covered. Updating only the sample devices selected for a Plus audit is not a sustainable route to compliance.
Scope needs to describe the real organisation
Cloud services that store or process organisational data cannot simply be excluded. The 2026 rules also ask for clearer descriptions of what is included, what is out of scope and how excluded networks are separated.
Businesses with several legal entities, sites or separately managed networks should settle the intended scope before the assessment starts. This avoids discovering late in the process that an unsupported device, overlooked cloud service or inherited firewall is part of the certification boundary.
A sensible readiness checklist
- List every device, firewall, router, server, application and cloud service in scope.
- Confirm that all in-scope software is supported on the intended certification date.
- Enable and verify MFA across every cloud service where it is available.
- Check that critical and high-risk updates are installed within the required 14-day window.
- Remove unused accounts and confirm that administrator access is limited and separate.
- Document exclusions and the technical separation that keeps them outside the scope.
Official sources and further reading
These primary sources were checked when this article was last reviewed.
