We're due to undergo Cyber Essentials Plus next week, and we're unclear about the account-separation requirement for cloud services. Our assessor hasn't explained it clearly or responded to our emails.
For example, one department uses DocuSign. We were told that any administrative work must be done with a separate admin account, while normal activity should use a standard user account. That seems straightforward for platforms with business or team accounts and separate roles, but many SaaS services don't work that way. Some only provide a single account, or make additional users available only on more expensive plans.
Does the requirement mean that administrator accounts must not be used for routine work, rather than requiring every cloud service to have two separate accounts? If a service has no distinct administrator role, is there anything practical to separate? Could it instead mean that tenant or global administrator accounts must not be used to sign up for or routinely access other cloud services?
The guidance I've found says account separation applies to cloud administrators and that admin accounts should not be used for day-to-day activity. I'd appreciate some clarification on how this is normally handled during assessment, particularly for services such as DocuSign or single-user accounting subscriptions.
3 Answers
I’d prioritise the major cloud platforms first: make sure global, tenant, or root administrator accounts are separate from normal user identities, and make sure MFA is enabled for the relevant cloud services. Check that ordinary user accounts aren’t also members of those privileged roles.
For other SaaS applications, document whether they support roles, whether separate accounts would cost extra, and how the service is actually used. If there is genuinely no admin tier, you can explain that account separation isn’t technically available rather than pretending two equivalent accounts provide additional security.
The requirement can become awkward with smaller SaaS products. Some services provide only one user on the basic plan, and the difference between an admin and a standard user may simply be the ability to invite other users. It seems unreasonable to upgrade solely to create a second account when the service is only used in a limited way.
In practice, an assessor may accept a documented explanation that a particular service has no separate admin facility or is only used administratively. The difficulty is that interpretation can vary between assessors, so get the rationale written down and be prepared to explain it.
Your second interpretation is probably closer: the main point is that accounts with administrative privileges shouldn’t be used for ordinary day-to-day work. This is clear for platforms such as Microsoft 365, AWS, or Google Workspace, where you can create a separate admin identity.
For a service that has no separate admin role, there may be no meaningful account separation to implement. Make a list of your cloud services, record which ones have administrative roles, and document how each is handled. That gives the assessor something concrete to review. It would also be worth escalating the lack of response through the certification body before the assessment.

That matches what we’ve seen. The assessment focused heavily on MFA and checking that global administrator accounts weren’t being used as normal user accounts. The rules can feel broad, so keeping the same assessor and documenting decisions consistently helps, but it’s still best to confirm any borderline cases in writing beforehand.