Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices
Under v3.3, the BYOD question is harder than it looks. A clear walkthrough of which personal devices are in scope, the sub-set exclusion rules, and how to document both approaches.

Section 01
Cyber Essentials BYOD rules in 2026: phones, laptops, personal devices
Cyber Essentials v3.3 defines scope by organisational data/services access and the explicit role/ownership exceptions. Employee, volunteer and trustee BYOD accessing work is in scope, apart from the native voice/text/MFA-only exceptions. The practical question is how to scope BYOD cleanly without certifying every personal phone in the company.
This guide walks through the rules as assessors apply them in 2026.
Section 02
The underlying rule
Assess devices accessing organisational data or services, including email, files, messaging, SaaS applications and virtual desktops. Apply the scheme's role/ownership table and explicit exceptions; ownership matters for third-party contractors and MSPs, as explained below. A lack of local storage is not itself an exemption.
In practice this means:
- A personal iPhone used to check work email: in scope.
- A personal laptop used to access SharePoint: in scope.
- A personal iPad used only for personal photos and no work apps: out of scope.
- A privately owned home router that your work laptop connects to: out of scope. An organisation-supplied router is in scope. Apply the firewall controls on the endpoint; a corporate VPN can put the internet boundary on the company or virtual/cloud firewall.
Devices used only for native voice, native text or MFA applications are out of scope under the NCSC v3.3 requirements. Access to organisational services, including virtual desktops, counts even without local file storage.
Section 03
The "sub-set exclusion" option
A sub-set is a separately managed part of the organisation segregated by a firewall or VLAN. Agree its boundary with the assessor; a BYOD policy or data-storage restriction does not create this boundary. For a no-BYOD policy, verify in practice that personal devices cannot access organisational data or services, for example:
- The device cannot open work email, calendar, or files.
- The device cannot access company SaaS (Slack, M365, Google Workspace, CRM, ticketing).
- The device cannot VPN into the corporate network.
- The device cannot store or sync any work document.
Actual access determines device scope, subject to the explicit native voice/text/MFA-only exceptions. "We told staff not to use personal phones for work" does not establish a segregated organisational sub-set. Unsupported software has a stricter exclusion condition: a defined sub-set preventing all traffic to or from the internet.
Section 04
The three common patterns
Pattern 1 - No BYOD
All work is done on company-issued devices. Personal devices are excluded by policy AND by technical controls - no personal devices enrolled in the corporate MDM, no personal devices allowed on the corporate network, no personal email accounts configured with work apps.
This is the cleanest pattern. BYOD is simply out of scope.
Pattern 2 - BYOD with MDM
Personal devices are allowed but must be enrolled in a mobile device management (MDM) solution (Intune, Jamf, Workspace ONE, Kandji) before they can access any work resource.
The personal device remains in scope. Verify the actual passcode, lock, supported-software and update controls and policy coverage. Encryption is useful hardening. MDM capability depends on platform, ownership and enrolment; enrolment alone does not prove assessor acceptance.
Pattern 3 - BYOD with conditional access (no MDM)
Personal devices access work resources (typically email, Teams, a narrow set of SaaS apps) only when they meet conditional-access rules: up-to-date OS, device encryption, passcode, not jailbroken. Enforced at the identity provider layer (Entra ID, Okta, Google Workspace).
Conditional Access can block access based on signals available to the identity provider. Verify that those signals cover the device and required controls; app protection or a sign-in policy alone does not establish whole-device compliance. Document actual enforcement and other access routes.
Section 05
The home router question (v3.3)
Under v3.3 (Danzell A2.5), normal home routers used by remote workers are explicitly out of scope. The Danzell assessor guide is unambiguous: "Details of routers and firewalls in the home environment must not be included." The boundary instead follows the device that touches organisational data; the device's software firewall handles enforcement against the home network.
What is in scope for a remote-working solicitor is therefore:
- The work laptop, with its software firewall enabled, default-deny on inbound, and configured so a standard user cannot disable it.
- The MDM or device-management posture if applied (Intune, Jamf, Conditional Access).
- The cloud services accessed (M365, Google Workspace, practice management).
Reliance on the software firewall for home and remote workers must be noted in A2.5 of the questionnaire. The Danzell guide expects something like: "Home and remote workers rely on the device's software firewall as the boundary; no home routers in scope."
Where the home router IS in scope: if the firm supplies a corporate router to the home worker (i.e., issues the router as managed kit, not the worker's own ISP-provided router), that router is corporate equipment and is in scope. Assess it as you would any office-edge device.
What does not work: saying "staff work from home, their router is their problem" without the software-firewall notes. The Danzell rule is clear that home routers are excluded, but the device-level firewall picture must be described.
Section 06
Documenting BYOD for the assessor
The CE questionnaire asks: "Does the organisation permit BYOD?" If yes, it asks you to describe the policy and controls.
A clear answer looks like:
> "BYOD permitted for personal iOS and Android phones only, limited to access of M365 email and Teams. Personal devices are enrolled in Intune before access is granted; Intune applies the supported passcode and locking policies; we verify vendor support, required vulnerability fixes and actual policy coverage. Disk encryption and biometric unlock are additional local hardening choices. Personal laptops are not permitted to access work resources under any circumstances."
An unclear answer looks like:
> "We allow staff to use personal devices if they sign our acceptable-use policy."
An answer needs supporting evidence of actual coverage and controls. Neither sample wording guarantees acceptance.
Section 07
Special cases
Contractors and consultants
NCSC page 12 distinguishes role and ownership: organisation-owned devices loaned to third parties are included; a third-party contractor's own or personally owned device is outside the assessment scope. Organisation-owned accounts remain in scope and you retain responsibility for confirming interacting devices are configured correctly. VDI or blocked local storage is not what creates the ownership-based exclusion; employee BYOD accessing Citrix or AWS WorkSpaces remains in scope.
Directors and non-execs
Board papers on a personal iPad are organisational data. A managed board-paper app (Diligent, BoardPad) does not automatically exclude the iPad: viewing the papers is access to organisational data or services.
Family members of staff
If a staff member's family member has a login on a laptop that is used to access work, the laptop is in scope. The rule is about the device, not the user.
Section 08
Bottom line
Under v3.3, scope BYOD deliberately. Either exclude all personal devices with technical controls, or allow them under MDM / conditional access and put them in scope. The in-between - "personal devices allowed, policy-based" - does not pass assessment.
The good news: once scoped correctly, BYOD is straightforward to certify. The bad news: most organisations discover they are in-between on first review and need a small amount of remediation before their first CE submission passes.
Check your BYOD readiness | See the 14-day patching rule | Get certified in 6 hours
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials Firewall Requirements: What Assessors Actually Check
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, what v3.3 (Danzell) actually says about home routers for remote workers, default credentials, and the cloud firewall configuration assessors expect in 2026.
Read articleTechnical Guides
Cyber Essentials Scoping: What Is In, What Is Out, and How to Not Get It Wrong
Scoping is the single most misunderstood part of the Cyber Essentials submission. Get it wrong and your whole assessment is compromised. This guide covers remote workers, BYOD, cloud services, legacy systems, sub-set scoping, and the five scoping traps that most often fail assessments.
Read articleTechnical Guides
Malware Protection for Cyber Essentials: What Qualifies and What Does Not
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
Read article

