Cyber Essentials for iPhone / iOS: configuration guide
Prepare iPhones and iPads for Cyber Essentials: supported software, device credentials, patching, application controls and evidence, with MDM or other management.

Section 01
Cyber Essentials for iPhone / iOS: configuration guide
iPhones and iPads accessing organisational data or services are in scope, including work BYOD. Devices used only for native voice, native text or MFA applications have explicit exceptions. Configure and evidence the actual device controls; MDM and app protection can help but neither enrolment nor a managed app automatically establishes compliance.
Section 02
1. What the scheme tests
Swipe across the table to view all columns.
| Control | iOS preparation |
|---|---|
| Firewall | Verify the applicable network/firewall boundary and platform treatment with the assessor; lack of a user firewall toggle is not itself a blanket scope exemption |
| Secure configuration | Appropriate authentication, credential quality, guess protection and locking; remove unnecessary accounts/apps/services |
| Security update management | Supported model/release, automatic updates where possible and required fixes within the release-based deadline |
| User access control | Unique user accounts, needed access and effective MFA wherever available, always for cloud authentication |
| Malware protection | Qualifying application allowlisting with app approval and installation restrictions; sandboxing or App Store review alone is not an organisational allowlist |
Section 03
2. Corporate-owned supervised devices
Apple Business Manager and supported MDM enrolment can enable supervised controls. Verify exact platform, ownership and payload support before applying settings. Passcode, lock and update configuration should implement the scheme controls. A two-minute lock timer, non-simple passcode, encrypted backup and ten-attempt wipe can be stronger local policy rather than a universal mandatory bundle.
A thirty-day update deferral cannot postpone a required fix beyond its fourteen-day release deadline. Different update types and supported enforcement methods need separate review. Confirm installation and restarts, not only a profile screenshot.
Section 04
3. BYOD iPhones
Intune app protection can apply supported app PIN, data-transfer and selective-wipe controls. Capability differs by app/platform and identity configuration; do not assume Jamf app configuration or another vendor has identical MAM functionality.
MAM does not prove whole-device patching, support, locking or application-control compliance. A personal phone accessing email, Teams, Slack or webmail remains in scope without MDM. It can be managed differently if the actual required controls and evidence are maintained.
Section 05
4. Supported OS and update evidence
Check current Apple security releases and exact model compatibility/support rather than iOS 17/18 or a universal N-1 cutoff. Some older-device releases receive fixes; that is not proof that all relevant vulnerabilities are covered. Record active vendor vulnerability-fix support, actual available fixes and deployed dates for each in-scope device.
Section 06
5. Jailbreak and access-path checks
Check what your actual MDM or app-protection product can detect and enforce, including delayed/offline reporting. Detection, access blocking and wipe are different actions. Browser webmail and native-app access need separate policy testing: blocking Exchange ActiveSync does not by itself block Safari webmail. Verify direct sign-in, recovery and other routes as well as the preferred app.
Section 07
Scheme baseline and local hardening
NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.
For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.
Section 08
6. Evidence and common failure points
Prepare a complete device/model inventory, supported-version evidence, configuration/assignment records, required-fix installation dates, effective MFA and app-approval controls. Device counts need not equal user counts. MDM exports and app-protection reports are supporting evidence within their actual scope.
Investigate unsupported software, missing controls, unprotected browser access and policies requiring supervision that never applied. Four-digit device-only PINs do not meet the six-character minimum; biometric methods and fallback credentials need the applicable protections. Avoid wiping/re-enrolling devices as a universal answer before checking ownership, support and data preservation.
Section 09
What Fig Group checks
The readiness check supports preparation. Share relevant device and policy evidence when requested. Exact integration/report-import capability and first-attempt success percentages need service and cohort records; no pass or exhaustive issue detection is guaranteed.
Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus slot
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials for Mac / macOS: configuration guide
Prepare Mac and macOS controls for Cyber Essentials with or without MDM: firewall, supported software, patching, malware protection and optional FileVault hardening.
Read articleTechnical Guides
Cyber Essentials for Microsoft Intune: configuration guide
Use Microsoft Intune configuration, compliance, app protection and update policies to prepare Cyber Essentials evidence across supported platforms.
Read articleTechnical Guides
Cyber Essentials for Android: configuration guide
Prepare Android phones and tablets for Cyber Essentials: model-specific OEM support, patch deadlines, Android Enterprise options, application control and evidence.
Read article

