Mobile Devices & Cyber Essentials: What's Required

Written by Louise Ralston
Jul 15, 2026 - 5 minute read

Ensure your mobile devices comply with Cyber Essentials by using MDM or MAM, not just written policies, to mitigate risks and protect business data.

If a device can access business data, it's in scope for Cyber Essentials - and a written policy alone won't get you certified. Here's what your mobile device management actually need to cover, and how to check your devices are compliant.

In the age of remote and hybrid working, mobile device management has become central to how organisations work, communicate and collaborate.

But as smartphones and tablets are used to access more sensitive data, new risks have begun to emerge – and because Cyber Essentials treats these devices as part of your certification scope, getting mobile security right is mandatory if you want to pass.

This quick guide covers what counts as an in-scope device, and the steps you can take to stay compliant.

Quick Links

 

When are mobile devices in scope?

If a device can be used to access business data, it's in scope for Cyber Essentials. This includes company-issued phones, tablets and personal devices under a BYOD arrangement. (BYOD simply refers to employees using their own devices for work purposes.)

So, whether someone logs in to check their emails or a shared calendar, posts marketing content via an app, communicates via Teams or otherwise handles business information on the device, the device they used needs to meet Cyber Essentials standards.

There is now very little room for ambiguity. If a device connects to the internet and accesses organisational data, whether it’s Microsoft 365, Google Workspace or another cloud service, it must meet the relevant Cyber Essentials technical controls.

A mobile is only considered out of scope if it's used exclusively for traditional phone calls, SMS messaging or authenticator apps, but this is a narrow exemption. As soon as it accesses email, cloud services, business apps or internal systems, it falls within scope of Cyber Essentials.

 

Why written policies aren’t enough

Small businesses may have a written policy advising staff on how they should manage and secure their phones. These policies can be helpful, but on their own they don't deliver assurance that you have met the Cyber Essentials requirements.

Relying on individuals to keep their devices updated, encrypted and configured correctly simply isn't reliable, even with a small staff. Technical controls - tools that automatically apply and check settings like encryption, updates and PIN requirements, rather than leaving it to the user - provide comprehensive assurance that devices are compliant in practice.

Cyber Essentials requires you to be able to enforce these controls, not simply ask staff to follow them. Cyber Tec assessors regularly find devices that are not running compliant operating systems. A quick way to check your own devices is to look at the OS version in settings and compare it against the latest release for that device. If it's more than 14 days behind, it's likely non-compliant.

Cyber Essentials requires high-risk and critical security updates to be installed within 14 days of a given release. If devices are running unsupported operating systems, beta software or overdue security updates, it could cause an assessment to fail.

 

MDM and MAM: the practical way to stay compliant

There are two main approaches to making sure you have full mobile security:

    • Mobile Device Management (MDM): Gives full device-level control. It allows you to enforce OS updates, ensure encryption is enabled, set minimum PIN requirements, block jailbroken devices and keep every setting on the device consistent with your security requirements.
    • Mobile Application Management (MAM): More suitable for BYOD setups. Instead of controlling the whole device, MAM governs only the business apps and data, but still ensures the device is compliant. This protects email, Teams and other work apps while leaving personal content private, by isolating the business data, ringfencing it on the device.

Most companies will already have access to these capabilities. Microsoft 365 and Google Workspace both include mobile management tools, which an MSP should be able to enable and configure with minimal disruption.

But in terms of demonstrating mobile and device compliance, there's no substitute for technical controls. Whether you allow BYOD or issue company devices to staff, MDM or MAM are reliable ways to cover yourself.

Crucially, these controls should prevent users from disabling security settings or repeatedly postponing updates.

 

Common issues

The recurring problems that surface during Cyber Essentials assessments are usually straightforward to fix once identified - the issue is that they often go unnoticed until an assessment flags them. 

For example, iPhones and iPads are often found running outdated or unsupported versions of iOS, leaving them vulnerable. It’s common for users to repeatedly defer updating, and if this leaves critical vulnerabilities unpatched beyond the permitted 14-day period, the device may fail to meet Cyber Essentials requirements.

Apple Macs can also present similar risks, particularly when they aren't centrally managed and users run as local administrators.

BYOD devices are another weak spot. Without enforced controls, users may rely on short PINs, skip updates or set up their device in ways that leave it exposed, for example, disabling encryption, staying signed in permanently, or turning off screen locks. All of these can lead to non-compliance in a Cyber Essentials assessment.

 

What is Different for Mobile Devices in Cyber Essentials Plus?

Cyber Essentials Plus goes beyond the self-assessment used for the basic certification. An assessor carries out hands-on technical checks against a sample of the devices included in your scope.

For mobile devices, it might include verifying operating system and patch versions, checking lock and authentication settings, confirming that rooted or jailbroken devices are blocked and testing whether applications can be installed outside of the approved sources.

Where MAM is used, the assessor may also check that your organisation’s data can’t be copied or transferred into unmanaged personal applications, which may make justifying BYOD devices difficult during assessment.

To cover all bases before the assessment, make sure to identify every personal device that can access organisational data, and ensure it is enrolled in your MDM or MAM platform ahead of time. Any device that can’t be brought into compliance should ideally have its access to business accounts and data removed.

 

A quick compliance checklist

To meet Cyber Essentials requirements, mobile devices must:

    • Run a supported operating system, that is patched and up-to-date within 14-days of patch release.
    • Not be jailbroken or rooted. (Jailbreaking or rooting means removing the manufacturer's built-in restrictions, which also strips away many of the device's security protections.)
    • Have a minimum six-digit PIN or equivalent authentication.
    • Be managed through MDM or MAM rather than relying on a written policy alone.

These rules apply to phones, tablets and any other portable device used for business purposes, whether BYOD or company owned.

Mobile devices are an indispensable part of the way we work today, but they're also a potential entry point for cybersecurity threats.

Cyber Essentials can help eliminate many of these threats by ensuring organisations take control of every device that's used to handle business data. Mobile management tools make compliance far simpler and offer stronger protection.

Cyber Tec Security specialises in helping organisations of all sizes achieve Cyber Essentials and Cyber Essentials Plus certification. Find out more by contacting our team today.

Topics: Compliance, Cyber Essentials, Cyber Essentials Plus, Business Security

author

More by Louise Ralston

Related articles
Is Cyber Essentials Worth It For Your Business?

Cyber Essentials is often seen as a box to tick for tenders, contracts or suppliers. But for many SMEs, it’s one of the simplest ways to find and fix the everyday cyber weaknesses attackers exploit.

The Difference Between Cyber Essentials and Cyber Essentials Plus

Cyber threats are ever-growing and businesses are seeking accreditation like Cyber Essentials and Cyber Essentials Plus - but which is right for you?

How to Complete the Cyber Essentials Questionnaire

Learn how to navigate the Cyber Essentials self-assessment questionnaire and ensure your business meets the five key technical controls for successful certification.