Skip to content
Technical Guides

Cyber Essentials for Android: configuration guide

Prepare Android phones and tablets for Cyber Essentials: model-specific OEM support, patch deadlines, Android Enterprise options, application control and evidence.

green frog iphone case beside black samsung a

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials for Android: configuration guide

Android preparation starts with the exact device model and OEM security-update support. Android Enterprise management can make configuration and evidence easier, but a brand, OS number, Work Profile or MDM enrolment is not automatic compliance. Verify the actual supported controls and patch installation on every in-scope device.

Section 02

1. Pick the right Android Enterprise mode

  • Fully managed: work-only corporate devices. Best for high-security roles where the organisation needs full control.
  • Personally owned Work Profile: separates work apps/data from personal apps/data, with management scoped to the work profile.
  • Corporate-owned device with a Work Profile: work and personal use on organisation-owned equipment, with different management capabilities.

None guarantees a pass. Microsoft's current enrolment guidance distinguishes supported methods and ownership. Legacy Device Administrator management is deprecated/unavailable for GMS devices in Intune; check the actual vendor and platform rather than presenting the API name as a scheme clause.

Section 03

2. Supported OS and patch inventory

Record model, OS version, patch level and vendor support end date. Google lists Pixel support by model; Samsung and other OEM commitments also vary by device, region and release. There is no blanket supported Android 13+ rule or universal monthly patch requirement.

An unsupported device remains a failing in-scope device if still used for work; it does not automatically become out of scope. Replace or upgrade it, or meet the actual exclusion conditions. A security-patch date older than 90 days can prompt investigation, but 90 days is not tighter than the 14-day release-based rule. Google Play system updates do not cover every OEM or app vulnerability fix.

Section 04

3. Baseline management policy

Use an Android-capable tool such as Intune or Workspace ONE; check platform support rather than recommending Apple-only Jamf/Mosyle management for Android. Choose settings that the device, ownership and management mode can actually enforce.

Swipe across the table to view all columns.

AreaConfiguration approach
CredentialsApply device-only six-character minimum where relevant, appropriate quality and guess protection; check authentication reuse
LockingAppropriate lock controls; two minutes is an illustrative local policy
Application controlApprove applications and restrict installation using a qualifying allowlisting route
UpdatesAutomatic updates where possible; check vendor-required fixes and actual installation
Additional hardeningEncryption, Play Protect, integrity/verified-boot checks and selective work-profile wipe where supported

Complexity settings and ten-attempt wipe are local choices, not the scheme's universal configuration. Play Protect and verified boot add protection but do not alone establish application allowlisting.

Section 05

4. Work Profile specifics (BYOD)

Configure supported work-profile authentication and data-transfer restrictions. Selective wipe can remove work data on departure. The phone remains in scope when it accesses organisational data or services; work-profile isolation or blocked local storage does not exempt the whole endpoint. Devices used only for native voice, native text or MFA apps have explicit scope exceptions.

Section 06

5. Google Play and Managed Google Play

Use Managed Google Play to distribute approved business apps, including controlled private apps where appropriate. Check both work-profile and device installation permissions. Play Store availability is not by itself an organisational approval list; developer sideloading needs an actual qualifying control, not just a documented exception. Assess the allowlisting route on the applicable device and configuration.

Section 07

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 08

6. Evidence and common failure points

Prepare a complete device/model inventory, current support evidence, configuration and assignment reports, patch installation records and application-control evidence. Report missing or offline devices as well as enrolled devices.

Investigate expired OEM support, unsupported enrolment methods, unmanaged installation routes and policies that never reached devices. Mixed work/personal use without a Work Profile is not automatically impossible to certify; the applicable controls still need evidence. Knox Mobile Enrollment is a deployment tool rather than a universal scheme prerequisite.

Section 09

What Fig Group checks

The readiness check supports preparation. Share relevant Android evidence when requested. Report ingestion, detailed configuration access and first-attempt success rates need verified capability and cohort records; a flagship brand or Work Profile cannot guarantee a pass.

Start Cyber Essentials - from £299.99 + VAT | Pricing | CE Plus with on-device testing

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group