Skip to content
Technical Guides

Cyber Essentials for Mac / macOS: configuration guide

Prepare Mac and macOS controls for Cyber Essentials with or without MDM: firewall, supported software, patching, malware protection and optional FileVault hardening.

silver iMac ad wireless keyboard

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials for Mac / macOS: configuration guide

Cyber Essentials applies to in-scope Macs used for organisational data or services. Prepare firewall, secure configuration, supported software, updates, user access and a qualifying malware route. FileVault, stealth mode and MDM can strengthen management, but they are not a universal required bundle. Manual preparation is possible when you can maintain reliable evidence.

Section 02

1. What the scheme tests on macOS

Swipe across the table to view all columns.

ControlWhat to verify
FirewallApplicable firewall protection and only necessary approved inbound services
Secure configurationRemove unnecessary accounts/software; appropriate authentication, credential quality, guess protection and locking
Security update managementExact supported model/release, automatic updates where possible, required fixes within 14 days of release
User access controlStandard daily work and separate admin tasks; effective MFA wherever available and always for cloud authentication
Malware protectionQualifying anti-malware or application allowlisting; XProtect is malware detection, not an allowlist

Section 03

2. Without MDM (illustrative small fleet, ≤ 10 Macs)

Ten Macs is an illustrative management scale, not the employee-based purchase tier. Review each Mac, record its configuration and support, and maintain checks for drift and required updates. A signed user attestation can support evidence, but is not a universal assessor requirement or proof of effective controls throughout the year.

In the supported System Settings interface:

  • Enable applicable firewall protection and restrict unnecessary incoming services. Stealth mode can be additional hardening.
  • Verify approved application installation and the chosen malware protection route.
  • Enable automatic software/security updates where possible and check installation evidence.
  • Apply an appropriate lock policy; ten minutes with immediate password on wake is one consistent illustrative choice, not a scheme timer.
  • Use a standard account for daily work, separate admin access and disable unnecessary automatic login.
  • Consider FileVault, recovery-key storage and theft-recovery tools as additional local hardening.

Check exact menu locations and capabilities for the installed release. Avoid older blanket spctl commands; use Apple's supported settings or management payloads and verify the result.

Section 04

3. With MDM

Jamf Pro, Kandji, Intune, Mosyle, Addigy and Workspace ONE can help manage supported Mac settings. Check the actual profile payload and observed state. MDM can improve scale and drift management; it does not eliminate scope gaps or prove compliance on its own.

Section 05

4. Supported macOS versions

Verify current Apple security releases, model compatibility and vendor vulnerability-fix support for the exact OS. Do not treat macOS 15 as permanently current, macOS 14 as a fixed minimum or N-1 as a universal Apple/scheme rule. An older release receiving some fixes does not prove every relevant vulnerability is covered. Upgrade or replace unsupported equipment rather than declaring it exempt while it still accesses work.

Section 06

5. Antivirus / malware protection

Apple explains XProtect and Gatekeeper: XProtect detects malware; Gatekeeper checks provenance/signing. Do not label XProtect as an allowlist. For anti-malware, verify the full scheme route, including malicious-file prevention, required malicious-website protection, updates and user protection. For allowlisting, verify actual approval and prevention of unapproved execution. Third-party EDR is an implementation option, not automatically mandatory or automatically sufficient.

Deploy agents and required permissions through supported methods. Manual installation can work on a small fleet if coverage and effective operation are evidenced; MDM installation is not itself compulsory.

Section 07

Scheme baseline and local hardening

NCSC v3.3 requirements defines the required controls. Device-only passwords or PINs need at least six characters, technical quality controls and effective guess protection. Credentials also used for authentication need the full User Access Control password requirements. Use MFA wherever available and always for cloud-service authentication. Twelve-character passwords, shorter lock timers, encryption and remote wipe can be useful local hardening choices rather than universal scheme minima.

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor calls the vulnerability high/critical, its CVSS v3 base score is 7 or above, or the vendor gives no severity details. Enable automatic updates where possible. Cover OS, applications and other in-scope software; a patch-level age or deferral setting alone does not establish compliance. Unsupported software must be removed from in-scope devices or excluded through a defined sub-set preventing all traffic to or from the internet. Merely labelling a device out of scope or documenting a business exception is insufficient.

For Windows and macOS, use qualifying anti-malware or application allowlisting; other platforms use application allowlisting. Check the actual mechanism and configuration, not a product name alone.

Section 08

6. Evidence and common failure points

Prepare a complete scoped inventory, configuration state, supported-version evidence, vulnerability-fix installation records and malware-route coverage. MDM exports or a maintained manual register can support this; the assessor determines evidence needed for the actual submission.

Investigate unsupported releases, unapproved application execution, daily work using an admin account, disabled required updates and unmanaged devices. FileVault being off breaches your encryption policy where adopted; it is not by itself a universal Cyber Essentials failure.

Section 09

What Fig Group checks

The readiness check supports preparation. Share Mac evidence when requested. Exact integration/import capability and comparative MDM/manual first-pass rates need operational records; no unsupported 95% versus 88% comparison or guarantee that every issue will be found is asserted here.

Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group