In the age of remote and hybrid working, mobile device management has become central to how organisations work, communicate and collaborate.
But as smartphones and tablets are used to access more sensitive data, new risks have begun to emerge – and because Cyber Essentials treats these devices as part of your certification scope, getting mobile security right is mandatory if you want to pass.
This quick guide covers what counts as an in-scope device, and the steps you can take to stay compliant.
If a device can be used to access business data, it's in scope for Cyber Essentials. This includes company-issued phones, tablets and personal devices under a BYOD arrangement. (BYOD simply refers to employees using their own devices for work purposes.)
So, whether someone logs in to check their emails or a shared calendar, posts marketing content via an app, communicates via Teams or otherwise handles business information on the device, the device they used needs to meet Cyber Essentials standards.
There is now very little room for ambiguity. If a device connects to the internet and accesses organisational data, whether it’s Microsoft 365, Google Workspace or another cloud service, it must meet the relevant Cyber Essentials technical controls.
A mobile is only considered out of scope if it's used exclusively for traditional phone calls, SMS messaging or authenticator apps, but this is a narrow exemption. As soon as it accesses email, cloud services, business apps or internal systems, it falls within scope of Cyber Essentials.
Small businesses may have a written policy advising staff on how they should manage and secure their phones. These policies can be helpful, but on their own they don't deliver assurance that you have met the Cyber Essentials requirements.
Relying on individuals to keep their devices updated, encrypted and configured correctly simply isn't reliable, even with a small staff. Technical controls - tools that automatically apply and check settings like encryption, updates and PIN requirements, rather than leaving it to the user - provide comprehensive assurance that devices are compliant in practice.
Cyber Essentials requires you to be able to enforce these controls, not simply ask staff to follow them. Cyber Tec assessors regularly find devices that are not running compliant operating systems. A quick way to check your own devices is to look at the OS version in settings and compare it against the latest release for that device. If it's more than 14 days behind, it's likely non-compliant.
Cyber Essentials requires high-risk and critical security updates to be installed within 14 days of a given release. If devices are running unsupported operating systems, beta software or overdue security updates, it could cause an assessment to fail.
There are two main approaches to making sure you have full mobile security:
Most companies will already have access to these capabilities. Microsoft 365 and Google Workspace both include mobile management tools, which an MSP should be able to enable and configure with minimal disruption.
But in terms of demonstrating mobile and device compliance, there's no substitute for technical controls. Whether you allow BYOD or issue company devices to staff, MDM or MAM are reliable ways to cover yourself.
Crucially, these controls should prevent users from disabling security settings or repeatedly postponing updates.
The recurring problems that surface during Cyber Essentials assessments are usually straightforward to fix once identified - the issue is that they often go unnoticed until an assessment flags them.
For example, iPhones and iPads are often found running outdated or unsupported versions of iOS, leaving them vulnerable. It’s common for users to repeatedly defer updating, and if this leaves critical vulnerabilities unpatched beyond the permitted 14-day period, the device may fail to meet Cyber Essentials requirements.
Apple Macs can also present similar risks, particularly when they aren't centrally managed and users run as local administrators.
BYOD devices are another weak spot. Without enforced controls, users may rely on short PINs, skip updates or set up their device in ways that leave it exposed, for example, disabling encryption, staying signed in permanently, or turning off screen locks. All of these can lead to non-compliance in a Cyber Essentials assessment.
Cyber Essentials Plus goes beyond the self-assessment used for the basic certification. An assessor carries out hands-on technical checks against a sample of the devices included in your scope.
For mobile devices, it might include verifying operating system and patch versions, checking lock and authentication settings, confirming that rooted or jailbroken devices are blocked and testing whether applications can be installed outside of the approved sources.
Where MAM is used, the assessor may also check that your organisation’s data can’t be copied or transferred into unmanaged personal applications, which may make justifying BYOD devices difficult during assessment.
To cover all bases before the assessment, make sure to identify every personal device that can access organisational data, and ensure it is enrolled in your MDM or MAM platform ahead of time. Any device that can’t be brought into compliance should ideally have its access to business accounts and data removed.
To meet Cyber Essentials requirements, mobile devices must:
These rules apply to phones, tablets and any other portable device used for business purposes, whether BYOD or company owned.
Mobile devices are an indispensable part of the way we work today, but they're also a potential entry point for cybersecurity threats.
Cyber Essentials can help eliminate many of these threats by ensuring organisations take control of every device that's used to handle business data. Mobile management tools make compliance far simpler and offer stronger protection.
Cyber Tec Security specialises in helping organisations of all sizes achieve Cyber Essentials and Cyber Essentials Plus certification. Find out more by contacting our team today.