Cyber Essentials v3.3 and device unlock: what the scheme expects
Device unlock for Cyber Essentials v3.3: six-character device-only passwords or PINs, brute-force protection, biometrics and credentials also used for authentication.

Section 01
Cyber Essentials v3.3 and device unlock: what the scheme expects
Device locking and unlocking sit under secure configuration. The NCSC v3.3 requirements, page 16, set a six-character minimum for passwords or PINs used only to unlock a device. That minimum is valid; four characters are insufficient for that password/PIN route.
Section 02
The general rule
Before a physically present user gains access to the device's services, require a biometric, password or PIN. Use technical credential-quality controls and protect the method against brute-force guessing.
Where configurable, use increasing throttling allowing no more than ten guesses in five minutes, or locking after no more than ten unsuccessful attempts. Where the vendor does not permit those settings, use its default protection.
Device-only credentials: a password or PIN needs at least six characters. A numeric PIN therefore needs at least six digits.
Credentials also used for authentication: apply the full User Access Control password requirements, not just the six-character device-only minimum. For password-based MFA the password minimum is eight characters. Other password-quality and management controls still apply.
The scheme does not impose universal fifteen-minute Windows, five-minute macOS or two-minute mobile lock timers. Choose appropriate locking controls for your environment; stricter timers can be a local hardening policy.
Section 03
Windows
Use an appropriate password, PIN or Windows Hello biometric, with effective locking and guess protection. Determine whether the credential only unlocks the device or also authenticates to organisational services. The product name alone does not answer that question.
Group Policy, Intune and native settings can implement controls. Intune enrolment is not compulsory for every Windows device.
Section 04
macOS
Configure appropriate locking and require a credential before access. Touch ID can provide device unlock, but check the fallback password and whether it also authenticates. The scheme does not prescribe a universal mixed-case/numbers complexity rule or five-minute timer.
FileVault is valuable hardening for data at rest; it is not a universal technical Cyber Essentials requirement.
Section 05
iOS and iPadOS
For a device-only passcode, set at least six digits or use a suitable longer password. Check Face ID or Touch ID and the fallback passcode, locking and vendor guess protection. A four-digit device-only PIN does not meet the six-character minimum.
Choose an appropriate auto-lock setting. A two-minute timer can be your policy, but is not the universal scheme threshold.
Section 06
Android
Use a credential with effective guess protection and technical quality controls. A device-only PIN needs at least six digits; do not describe four digits as merely borderline. Verify biometric fallback and the actual vendor configuration.
Encryption and a short auto-lock timer are sensible hardening choices, but the scheme does not mandate universal Android encryption or a two-minute timer.
Section 07
Home routers
Ordinary privately owned home routers are out of scope. Organisation-supplied routers are in scope. Remote-worker devices need appropriate software-firewall protection on untrusted networks; that is separate from device unlocking.
Section 08
BYOD devices
Personal devices accessing organisational data or services are in scope. Apply and verify the relevant locking, credential-quality and guessing-protection controls. MDM is a useful enforcement and reporting method, not a universal enrolment or remote-wipe requirement. A written instruction alone does not demonstrate effective technical settings.
Section 09
Kiosk and shared devices
Check authentication before organisational access, unique human credentials and appropriate locking for the actual use. Restricting applications and clearing sessions between users are useful design measures; a shared-device label does not exempt the required controls.
Section 10
What to prepare for the assessor
Show the actual credential configuration and guessing protection, using native settings or management reports as appropriate. Explain credentials reused for authentication and the fallback behind biometrics. Evidence of a fifteen-minute timer or MDM enrolment alone does not establish compliance.
For Plus, the applicable specification and assessor-selected sample determine the live checks.
Section 11
Common gaps
- A four-digit device-only password or PIN.
- No credential before access to device services.
- Missing or ineffective guess protection.
- Applying only the six-character minimum to a credential also used for authentication.
- Describing a management product without verifying the settings on the relevant devices.
Section 12
Preparing your submission
Document the actual unlock method, fallback and technical protections for each relevant platform. Keep local timer and encryption policies separate from the scheme minimum.
Start Cyber Essentials | See the 14-day patching rule | See pricing
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials v3.3 and passwordless authentication: what the scheme allows
Passwordless sign-in with FIDO2, Windows Hello, and mobile credentials is rising fast. This article explains how v3.3 treats passwordless authentication and what to declare in the self-assessment.
Read articleTechnical Guides
Cyber Essentials v3.3: admin account requirements and stronger authentication
Individual administrator credentials, separate day and admin accounts, effective MFA and optional phishing-resistant authentication and emergency-access hardening.
Read articleTechnical Guides
Cyber Essentials for iPhone / iOS: configuration guide
Prepare iPhones and iPads for Cyber Essentials: supported software, device credentials, patching, application controls and evidence, with MDM or other management.
Read article

