Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)
Use password managers to support Cyber Essentials password controls: unique credentials, secure storage, MFA, breach monitoring, access management and useful evidence.

Section 01
Cyber Essentials and password managers (1Password, Bitwarden, Dashlane)
A password manager is a useful way to provide secure storage and unique work passwords; Cyber Essentials does not mandate a particular manager or reject memorised passwords automatically. The NCSC requirements, pages 21-22, permit different password-quality controls. A manager's health score or breach report does not itself prove that the service enforces those controls.
Section 02
1. Why a password manager matters for Cyber Essentials v3.3
Choose a technical password-quality route: MFA (with at least eight characters for its password element), at least twelve characters without a maximum-length restriction, or at least eight characters without a maximum-length restriction and automatic common-password deny-list blocking.
Separately protect guessing through MFA, increasing throttling or lockout. Throttling alone is not the eight-character deny-list alternative. Do not enforce regular password expiry or complexity rules as a scheme requirement; change credentials promptly where compromise is known or suspected.
Support unique work passwords and usable secure storage. A manager can generate and store credentials and help manage access; a secure locked cabinet is another storage example in the requirements. Cloud password-manager authentication itself needs MFA.
Section 03
2. 1Password Business / Teams configuration
Check the actual plan and sign-in model before describing settings. 1Password's business security guidance explains account protection, team reports and shared-vault access. Business and Teams features should not be assumed identical.
Apply effective MFA to cloud sign-in, control membership and shared-vault access, and test account removal and recovery. A vault unlock after a verified login is not necessarily a new cloud authentication event.
Business reports include Watchtower information. Read their scope and update behaviour; a report of stored credentials is not proof of every destination service's policy or every user's MFA enforcement. SCIM/SSO can help with lifecycle management where supported, but is not compulsory for certification.
Section 04
3. Bitwarden (cloud or self-hosted)
Review Bitwarden's current Enterprise policies for your plan and account model. Configure effective cloud-login MFA, the applicable password controls and collection permissions. Avoid presenting a mixed-case/special-character rule as a Cyber Essentials requirement.
Reports can identify weak, reused or exposed credentials for remediation. Export restrictions and recovery features have policy and role dependencies; verify their actual scope rather than assuming a universal block on all regular-user exports.
For self-hosting, maintain supported host and application components, automatic updates where possible and required fixes within fourteen days. Backup and tested recovery are recommended resilience measures, separately from the technical scheme minimum.
Section 05
4. Dashlane Business
Use Dashlane's current professional-plan policies to check available MFA, SSO, sharing and recovery controls. The applicable sign-in design and licence determine which settings exist.
Password Health helps prioritise weak, reused and compromised stored credentials. Cyber Essentials does not require a score of eighty, and a high score does not prove destination-service enforcement.
Assign access by role and remove unnecessary membership. SCIM/SSO, dark-web monitoring and collection controls can help your process but are not universal scheme prerequisites.
Section 06
5. Shared credentials - use sparingly
Cyber Essentials emphasises user access control, which is at odds with shared logins. Most shared credentials can be eliminated:
- SaaS tools with per-seat licences - provision individual accounts
- Service accounts - move to SSO + API keys tied to named users
- Legacy systems without per-user login - document business need, rotate when staff leave, confine to a small shared vault with restricted group membership
There is no fifty-credential scheme threshold. Review each shared interactive credential against unique-user authentication and access control; a shared vault does not turn a shared login into an individual account.
Section 07
6. Breach monitoring
Breach monitoring detects exposure after the event and is useful for changing affected credentials promptly. It is different from a service rejecting common passwords when they are set.
If you rely on the eight-character common-password deny-list quality route, verify preventive automatic blocking at the authenticating service. A retrospective Watchtower, Password Health or similar report does not establish that control.
Section 08
7. Recovery and backup
Document and safely test the recovery process available in your actual product, plan and sign-in model. Secret keys, recovery codes, administrator-assisted recovery and SSO recovery have different conditions; do not assume every account has the same recovery method.
Protect recovery material and remove unnecessary access. Manager backup is resilience practice; it does not replace effective MFA or required credential controls.
Section 09
8. Evidence assessors expect
- Tenant admin console URL and admin list
- Registration coverage plus effective enforcement and representative sign-in evidence for every required human cloud account; there is no 95-percent allowance
- Breach / weak-password report showing remediation cadence
- SCIM / SSO integration screenshot
- List of shared vaults and their membership
Section 10
9. Common failure points
1. Uncontrolled business credential storage. Confirm secure storage and the organisation's control of access. A personal or business plan label alone is not the scheme pass/fail criterion.
2. 2FA not enforced - usually a small tail of holdout users. Enforce at policy level with a cutover date.
3. Old shared vault from 2019 containing every credential ever used. Audit and reduce.
4. Weak master passwords surfaced by Watchtower / Password Health. Cycle the affected users.
Section 11
What Fig Group checks
Fig Group reviews the applicable password controls and cloud MFA from your submission and supporting evidence. Share policy or coverage evidence when requested, avoiding exports containing live secrets. Health reports support remediation but do not replace enforcement evidence or guarantee a pass.
Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for iPhone / iOS: configuration guide
Prepare iPhones and iPads for Cyber Essentials: supported software, device credentials, patching, application controls and evidence, with MDM or other management.
Read articleTechnical Guides
MFA for Microsoft 365: the Cyber Essentials v3.3 configuration
Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.
Read articleTechnical Guides
Cyber Essentials v3.3: admin account requirements and stronger authentication
Individual administrator credentials, separate day and admin accounts, effective MFA and optional phishing-resistant authentication and emergency-access hardening.
Read article

