Cyber Essentials for Chromebook / ChromeOS: configuration guide
How ChromeOS maps to Cyber Essentials: supported updates, application controls, Google Admin policies and evidence. Chromebooks can be the easiest device class for a suitable managed fleet.

Section 01
Cyber Essentials for Chromebook / ChromeOS: configuration guide
Chromebooks are probably the easiest end-user device to certify under Cyber Essentials v3.3 when their built-in protections and supported management fit the organisation's needs. This is editorial positioning rather than a measured device-class comparison. Verified Boot, sandboxing, encrypted user data and automatic updates provide useful protections, but all five controls and actual scope still need review.
Section 02
1. Why ChromeOS is Cyber-Essentials-friendly
Swipe across the table to view all columns.
| Control | ChromeOS preparation |
|---|---|
| Firewall | Verify the actual network/device firewall boundary and required protection, especially for remote use; absence of ordinary inbound services is not automatic exemption |
| Secure configuration | Review unnecessary accounts/apps/services, credentials and locking rather than assuming defaults always comply |
| Security update management | Confirm model support, updates enabled and required fixes installed on time |
| Malware protection | Verify qualifying application allowlisting; sandboxing, Safe Browsing and Play Protect alone do not establish the route |
| User access control | Named accounts, needed privileges and effective Workspace/cloud MFA |
No four-control automatic pass is implied. A regular release cadence does not prove release-based vulnerability-fix deadlines.
Section 03
2. Auto Update Expiration (AUE)
Check every model against Google's Auto Update policy, including applicable extended-update conditions. AUE identifies the support horizon; a device without qualifying vulnerability-fix support must be upgraded/replaced or meet a valid scheme exclusion.
Replacing within six months of expiry is optional planning advice. At purchase, verify the actual model's remaining support; ChromeOS Flex has its own certified-model support list and should not be conflated with Chromebook AUE. Record update version and installation evidence, not just expiry dates.
Section 04
3. Enrolment into Google Workspace
Chrome Enterprise Upgrade and Google Admin can help enforce device and user policies. Verify current licence/pricing and enrolment support with Google or the supplier; a universal under-£30 licence is not asserted. Organisational Units organise policy assignment.
Enterprise enrolment is a management approach, not a universal Cyber Essentials requirement. An unmanaged device still needs effective controls and reliable evidence; ownership or a personal Google account alone does not determine a pass.
Section 05
4. Google Admin policy examples
Where supported, review sign-in restrictions, forced re-enrolment, guest mode, developer mode and user installation permissions. Configure approved applications and restrict unapproved execution. Local policies can include a ten-minute lock timer, immediate password on wake, enhanced browsing protection and an approved password manager. These are examples to verify against actual control needs, not a mandatory bundle or fixed scheme timer.
Section 06
5. Password / user access control
Enforce effective Google Workspace 2SV for cloud authentication, including relevant contractor accounts and recovery/direct sign-in paths. Security keys or passkeys can provide stronger authentication; there is no blanket scheme FIDO2-only admin rule. Use unique accounts and separate standard daily work from administrative tasks.
Apply the actual password-quality alternatives rather than claiming twelve characters is the only scheme route. Device-only unlock credentials and credentials reused for authentication have different requirements.
Section 07
6. Android apps on Chromebook
If Android apps are enabled, approve the business applications and configure supported installation restrictions. Managed Google Play and Play Protect can help; neither alone proves organisational allowlisting. Developer-mode or sideloading exceptions need an effective qualifying control, not only a business explanation.
Section 08
Scheme baseline and local hardening
NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.
For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.
Section 09
7. Evidence and common failure points
Prepare the full serial/model/version/AUE inventory, actual policy assignment/state, required-fix installation records, application-control evidence and effective MFA coverage. Account for offline devices and personal equipment accessing work; native voice/text/MFA-only exceptions remain applicable.
Investigate expired support, missing required controls, unapproved app execution, shared logins and password-only cloud routes. A six-month replacement window is planning, not an automatic failure deadline.
Section 10
What Fig Group checks
The readiness check supports preparation. Share relevant inventory and policy evidence when requested. Exact Google Admin integration and first-pass percentages need verified service/cohort records. ChromeOS can be the easiest mobile platform to certify for a well-supported managed fleet, as an editorial judgement rather than a proven universal ranking or guaranteed pass.
Start Cyber Essentials - from £299.99 + VAT | Pricing | CE Plus
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for iPhone / iOS: configuration guide
Prepare iPhones and iPads for Cyber Essentials: supported software, device credentials, patching, application controls and evidence, with MDM or other management.
Read articleTechnical Guides
Cyber Essentials for Microsoft Azure: configuration guide
Prepare Azure Cyber Essentials controls and evidence: Entra ID authentication, shared responsibility, firewall rules, supported VMs and optional Secure Score hardening.
Read articleTechnical Guides
Cyber Essentials for Google Cloud (GCP): configuration guide
Configure GCP for Cyber Essentials v3.3 - Workspace identity, Organization Policies, Security Command Center, VPC firewalls, and OS Patch Management. Exact settings and the evidence assessors expect.
Read article

