MFA: Why Your Insurer and Your Certificate Now Both Demand It
A rule changed in April that most small businesses haven't been told about: miss multi-factor authentication on a cloud service and you don't lose a mark, you fail the whole assessment. What changed, what your insurer now wants, and why the type you choose matters as much as having it.
The short version
- Since April 2026, MFA is mandatory on every cloud service where it's available — missing it is an automatic fail
- Cloud services can no longer be excluded from scope, so the awkward system can't be left out
- Insurers now want evidence rather than a verbal yes, and what you declare is a warranty
- Text-message codes are the weakest tier; passkeys and hardware keys are the only ones that stop session theft