Skip to content
Technical Guides

Cyber Essentials for iPhone / iOS: configuration guide

Prepare iPhones and iPads for Cyber Essentials: supported software, device credentials, patching, application controls and evidence, with MDM or other management.

woman holding black iphone 5

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

6 min read

Share

Section 01

Cyber Essentials for iPhone / iOS: configuration guide

iPhones and iPads accessing organisational data or services are in scope, including work BYOD. Devices used only for native voice, native text or MFA applications have explicit exceptions. Configure and evidence the actual device controls; MDM and app protection can help but neither enrolment nor a managed app automatically establishes compliance.

Section 02

1. What the scheme tests

Swipe across the table to view all columns.

ControliOS preparation
FirewallVerify the applicable network/firewall boundary and platform treatment with the assessor; lack of a user firewall toggle is not itself a blanket scope exemption
Secure configurationAppropriate authentication, credential quality, guess protection and locking; remove unnecessary accounts/apps/services
Security update managementSupported model/release, automatic updates where possible and required fixes within the release-based deadline
User access controlUnique user accounts, needed access and effective MFA wherever available, always for cloud authentication
Malware protectionQualifying application allowlisting with app approval and installation restrictions; sandboxing or App Store review alone is not an organisational allowlist

Section 03

2. Corporate-owned supervised devices

Apple Business Manager and supported MDM enrolment can enable supervised controls. Verify exact platform, ownership and payload support before applying settings. Passcode, lock and update configuration should implement the scheme controls. A two-minute lock timer, non-simple passcode, encrypted backup and ten-attempt wipe can be stronger local policy rather than a universal mandatory bundle.

A thirty-day update deferral cannot postpone a required fix beyond its fourteen-day release deadline. Different update types and supported enforcement methods need separate review. Confirm installation and restarts, not only a profile screenshot.

Section 04

3. BYOD iPhones

Intune app protection can apply supported app PIN, data-transfer and selective-wipe controls. Capability differs by app/platform and identity configuration; do not assume Jamf app configuration or another vendor has identical MAM functionality.

MAM does not prove whole-device patching, support, locking or application-control compliance. A personal phone accessing email, Teams, Slack or webmail remains in scope without MDM. It can be managed differently if the actual required controls and evidence are maintained.

Section 05

4. Supported OS and update evidence

Check current Apple security releases and exact model compatibility/support rather than iOS 17/18 or a universal N-1 cutoff. Some older-device releases receive fixes; that is not proof that all relevant vulnerabilities are covered. Record active vendor vulnerability-fix support, actual available fixes and deployed dates for each in-scope device.

Section 06

5. Jailbreak and access-path checks

Check what your actual MDM or app-protection product can detect and enforce, including delayed/offline reporting. Detection, access blocking and wipe are different actions. Browser webmail and native-app access need separate policy testing: blocking Exchange ActiveSync does not by itself block Safari webmail. Verify direct sign-in, recovery and other routes as well as the preferred app.

Section 07

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 08

6. Evidence and common failure points

Prepare a complete device/model inventory, supported-version evidence, configuration/assignment records, required-fix installation dates, effective MFA and app-approval controls. Device counts need not equal user counts. MDM exports and app-protection reports are supporting evidence within their actual scope.

Investigate unsupported software, missing controls, unprotected browser access and policies requiring supervision that never applied. Four-digit device-only PINs do not meet the six-character minimum; biometric methods and fallback credentials need the applicable protections. Avoid wiping/re-enrolling devices as a universal answer before checking ownership, support and data preservation.

Section 09

What Fig Group checks

The readiness check supports preparation. Share relevant device and policy evidence when requested. Exact integration/report-import capability and first-attempt success percentages need service and cohort records; no pass or exhaustive issue detection is guaranteed.

Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus slot

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group