Skip to content
Technical Guides

Cyber Essentials v3.3 and device unlock: what the scheme expects

Device unlock for Cyber Essentials v3.3: six-character device-only passwords or PINs, brute-force protection, biometrics and credentials also used for authentication.

space gray iPhone 6

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials v3.3 and device unlock: what the scheme expects

Device locking and unlocking sit under secure configuration. The NCSC v3.3 requirements, page 16, set a six-character minimum for passwords or PINs used only to unlock a device. That minimum is valid; four characters are insufficient for that password/PIN route.

Section 02

The general rule

Before a physically present user gains access to the device's services, require a biometric, password or PIN. Use technical credential-quality controls and protect the method against brute-force guessing.

Where configurable, use increasing throttling allowing no more than ten guesses in five minutes, or locking after no more than ten unsuccessful attempts. Where the vendor does not permit those settings, use its default protection.

Device-only credentials: a password or PIN needs at least six characters. A numeric PIN therefore needs at least six digits.

Credentials also used for authentication: apply the full User Access Control password requirements, not just the six-character device-only minimum. For password-based MFA the password minimum is eight characters. Other password-quality and management controls still apply.

The scheme does not impose universal fifteen-minute Windows, five-minute macOS or two-minute mobile lock timers. Choose appropriate locking controls for your environment; stricter timers can be a local hardening policy.

Section 03

Windows

Use an appropriate password, PIN or Windows Hello biometric, with effective locking and guess protection. Determine whether the credential only unlocks the device or also authenticates to organisational services. The product name alone does not answer that question.

Group Policy, Intune and native settings can implement controls. Intune enrolment is not compulsory for every Windows device.

Section 04

macOS

Configure appropriate locking and require a credential before access. Touch ID can provide device unlock, but check the fallback password and whether it also authenticates. The scheme does not prescribe a universal mixed-case/numbers complexity rule or five-minute timer.

FileVault is valuable hardening for data at rest; it is not a universal technical Cyber Essentials requirement.

Section 05

iOS and iPadOS

For a device-only passcode, set at least six digits or use a suitable longer password. Check Face ID or Touch ID and the fallback passcode, locking and vendor guess protection. A four-digit device-only PIN does not meet the six-character minimum.

Choose an appropriate auto-lock setting. A two-minute timer can be your policy, but is not the universal scheme threshold.

Section 06

Android

Use a credential with effective guess protection and technical quality controls. A device-only PIN needs at least six digits; do not describe four digits as merely borderline. Verify biometric fallback and the actual vendor configuration.

Encryption and a short auto-lock timer are sensible hardening choices, but the scheme does not mandate universal Android encryption or a two-minute timer.

Section 07

Home routers

Ordinary privately owned home routers are out of scope. Organisation-supplied routers are in scope. Remote-worker devices need appropriate software-firewall protection on untrusted networks; that is separate from device unlocking.

Section 08

BYOD devices

Personal devices accessing organisational data or services are in scope. Apply and verify the relevant locking, credential-quality and guessing-protection controls. MDM is a useful enforcement and reporting method, not a universal enrolment or remote-wipe requirement. A written instruction alone does not demonstrate effective technical settings.

Section 09

Kiosk and shared devices

Check authentication before organisational access, unique human credentials and appropriate locking for the actual use. Restricting applications and clearing sessions between users are useful design measures; a shared-device label does not exempt the required controls.

Section 10

What to prepare for the assessor

Show the actual credential configuration and guessing protection, using native settings or management reports as appropriate. Explain credentials reused for authentication and the fallback behind biometrics. Evidence of a fifteen-minute timer or MDM enrolment alone does not establish compliance.

For Plus, the applicable specification and assessor-selected sample determine the live checks.

Section 11

Common gaps

  • A four-digit device-only password or PIN.
  • No credential before access to device services.
  • Missing or ineffective guess protection.
  • Applying only the six-character minimum to a credential also used for authentication.
  • Describing a management product without verifying the settings on the relevant devices.

Section 12

Preparing your submission

Document the actual unlock method, fallback and technical protections for each relevant platform. Keep local timer and encryption policies separate from the scheme minimum.

Start Cyber Essentials | See the 14-day patching rule | See pricing

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group