Skip to content
Technical Guides

Cyber Essentials for Chromebook / ChromeOS: configuration guide

How ChromeOS maps to Cyber Essentials: supported updates, application controls, Google Admin policies and evidence. Chromebooks can be the easiest device class for a suitable managed fleet.

white Acer Chromebook laptop

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

6 min read

Share

Section 01

Cyber Essentials for Chromebook / ChromeOS: configuration guide

Chromebooks are probably the easiest end-user device to certify under Cyber Essentials v3.3 when their built-in protections and supported management fit the organisation's needs. This is editorial positioning rather than a measured device-class comparison. Verified Boot, sandboxing, encrypted user data and automatic updates provide useful protections, but all five controls and actual scope still need review.

Section 02

1. Why ChromeOS is Cyber-Essentials-friendly

Swipe across the table to view all columns.

ControlChromeOS preparation
FirewallVerify the actual network/device firewall boundary and required protection, especially for remote use; absence of ordinary inbound services is not automatic exemption
Secure configurationReview unnecessary accounts/apps/services, credentials and locking rather than assuming defaults always comply
Security update managementConfirm model support, updates enabled and required fixes installed on time
Malware protectionVerify qualifying application allowlisting; sandboxing, Safe Browsing and Play Protect alone do not establish the route
User access controlNamed accounts, needed privileges and effective Workspace/cloud MFA

No four-control automatic pass is implied. A regular release cadence does not prove release-based vulnerability-fix deadlines.

Section 03

2. Auto Update Expiration (AUE)

Check every model against Google's Auto Update policy, including applicable extended-update conditions. AUE identifies the support horizon; a device without qualifying vulnerability-fix support must be upgraded/replaced or meet a valid scheme exclusion.

Replacing within six months of expiry is optional planning advice. At purchase, verify the actual model's remaining support; ChromeOS Flex has its own certified-model support list and should not be conflated with Chromebook AUE. Record update version and installation evidence, not just expiry dates.

Section 04

3. Enrolment into Google Workspace

Chrome Enterprise Upgrade and Google Admin can help enforce device and user policies. Verify current licence/pricing and enrolment support with Google or the supplier; a universal under-£30 licence is not asserted. Organisational Units organise policy assignment.

Enterprise enrolment is a management approach, not a universal Cyber Essentials requirement. An unmanaged device still needs effective controls and reliable evidence; ownership or a personal Google account alone does not determine a pass.

Section 05

4. Google Admin policy examples

Where supported, review sign-in restrictions, forced re-enrolment, guest mode, developer mode and user installation permissions. Configure approved applications and restrict unapproved execution. Local policies can include a ten-minute lock timer, immediate password on wake, enhanced browsing protection and an approved password manager. These are examples to verify against actual control needs, not a mandatory bundle or fixed scheme timer.

Section 06

5. Password / user access control

Enforce effective Google Workspace 2SV for cloud authentication, including relevant contractor accounts and recovery/direct sign-in paths. Security keys or passkeys can provide stronger authentication; there is no blanket scheme FIDO2-only admin rule. Use unique accounts and separate standard daily work from administrative tasks.

Apply the actual password-quality alternatives rather than claiming twelve characters is the only scheme route. Device-only unlock credentials and credentials reused for authentication have different requirements.

Section 07

6. Android apps on Chromebook

If Android apps are enabled, approve the business applications and configure supported installation restrictions. Managed Google Play and Play Protect can help; neither alone proves organisational allowlisting. Developer-mode or sideloading exceptions need an effective qualifying control, not only a business explanation.

Section 08

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 09

7. Evidence and common failure points

Prepare the full serial/model/version/AUE inventory, actual policy assignment/state, required-fix installation records, application-control evidence and effective MFA coverage. Account for offline devices and personal equipment accessing work; native voice/text/MFA-only exceptions remain applicable.

Investigate expired support, missing required controls, unapproved app execution, shared logins and password-only cloud routes. A six-month replacement window is planning, not an automatic failure deadline.

Section 10

What Fig Group checks

The readiness check supports preparation. Share relevant inventory and policy evidence when requested. Exact Google Admin integration and first-pass percentages need verified service/cohort records. ChromeOS can be the easiest mobile platform to certify for a well-supported managed fleet, as an editorial judgement rather than a proven universal ranking or guaranteed pass.

Start Cyber Essentials - from £299.99 + VAT | Pricing | CE Plus

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group