Skip to content
Technical Guides

Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)

Use password managers to support Cyber Essentials password controls: unique credentials, secure storage, MFA, breach monitoring, access management and useful evidence.

red padlock on black computer keyboard

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

6 min read

Share

Section 01

Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)

A password manager is a useful way to provide secure storage and unique work passwords; Cyber Essentials does not mandate a particular manager or reject memorised passwords automatically. The NCSC requirements, pages 21-22, permit different password-quality controls. A manager's health score or breach report does not itself prove that the service enforces those controls.

Section 02

1. Why a password manager matters for Cyber Essentials v3.3

Choose a technical password-quality route: MFA (with at least eight characters for its password element), at least twelve characters without a maximum-length restriction, or at least eight characters without a maximum-length restriction and automatic common-password deny-list blocking.

Separately protect guessing through MFA, increasing throttling or lockout. Throttling alone is not the eight-character deny-list alternative. Do not enforce regular password expiry or complexity rules as a scheme requirement; change credentials promptly where compromise is known or suspected.

Support unique work passwords and usable secure storage. A manager can generate and store credentials and help manage access; a secure locked cabinet is another storage example in the requirements. Cloud password-manager authentication itself needs MFA.

Section 03

2. 1Password Business / Teams configuration

Check the actual plan and sign-in model before describing settings. 1Password's business security guidance explains account protection, team reports and shared-vault access. Business and Teams features should not be assumed identical.

Apply effective MFA to cloud sign-in, control membership and shared-vault access, and test account removal and recovery. A vault unlock after a verified login is not necessarily a new cloud authentication event.

Business reports include Watchtower information. Read their scope and update behaviour; a report of stored credentials is not proof of every destination service's policy or every user's MFA enforcement. SCIM/SSO can help with lifecycle management where supported, but is not compulsory for certification.

Section 04

3. Bitwarden (cloud or self-hosted)

Review Bitwarden's current Enterprise policies for your plan and account model. Configure effective cloud-login MFA, the applicable password controls and collection permissions. Avoid presenting a mixed-case/special-character rule as a Cyber Essentials requirement.

Reports can identify weak, reused or exposed credentials for remediation. Export restrictions and recovery features have policy and role dependencies; verify their actual scope rather than assuming a universal block on all regular-user exports.

For self-hosting, maintain supported host and application components, automatic updates where possible and required fixes within fourteen days. Backup and tested recovery are recommended resilience measures, separately from the technical scheme minimum.

Section 05

4. Dashlane Business

Use Dashlane's current professional-plan policies to check available MFA, SSO, sharing and recovery controls. The applicable sign-in design and licence determine which settings exist.

Password Health helps prioritise weak, reused and compromised stored credentials. Cyber Essentials does not require a score of eighty, and a high score does not prove destination-service enforcement.

Assign access by role and remove unnecessary membership. SCIM/SSO, dark-web monitoring and collection controls can help your process but are not universal scheme prerequisites.

Section 06

5. Shared credentials - use sparingly

Cyber Essentials emphasises user access control, which is at odds with shared logins. Most shared credentials can be eliminated:

  • SaaS tools with per-seat licences - provision individual accounts
  • Service accounts - move to SSO + API keys tied to named users
  • Legacy systems without per-user login - document business need, rotate when staff leave, confine to a small shared vault with restricted group membership

There is no fifty-credential scheme threshold. Review each shared interactive credential against unique-user authentication and access control; a shared vault does not turn a shared login into an individual account.

Section 07

6. Breach monitoring

Breach monitoring detects exposure after the event and is useful for changing affected credentials promptly. It is different from a service rejecting common passwords when they are set.

If you rely on the eight-character common-password deny-list quality route, verify preventive automatic blocking at the authenticating service. A retrospective Watchtower, Password Health or similar report does not establish that control.

Section 08

7. Recovery and backup

Document and safely test the recovery process available in your actual product, plan and sign-in model. Secret keys, recovery codes, administrator-assisted recovery and SSO recovery have different conditions; do not assume every account has the same recovery method.

Protect recovery material and remove unnecessary access. Manager backup is resilience practice; it does not replace effective MFA or required credential controls.

Section 09

8. Evidence assessors expect

  • Tenant admin console URL and admin list
  • Registration coverage plus effective enforcement and representative sign-in evidence for every required human cloud account; there is no 95-percent allowance
  • Breach / weak-password report showing remediation cadence
  • SCIM / SSO integration screenshot
  • List of shared vaults and their membership

Section 10

9. Common failure points

1. Uncontrolled business credential storage. Confirm secure storage and the organisation's control of access. A personal or business plan label alone is not the scheme pass/fail criterion.

2. 2FA not enforced - usually a small tail of holdout users. Enforce at policy level with a cutover date.

3. Old shared vault from 2019 containing every credential ever used. Audit and reduce.

4. Weak master passwords surfaced by Watchtower / Password Health. Cycle the affected users.

Section 11

What Fig Group checks

Fig Group reviews the applicable password controls and cloud MFA from your submission and supporting evidence. Share policy or coverage evidence when requested, avoiding exports containing live secrets. Health reports support remediation but do not replace enforcement evidence or guarantee a pass.

Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group