Skip to content

Scoping and devices

Is BYOD in scope under v3.3?

Personal devices accessing organisational data or services are generally in scope, including devices used to access a virtual desktop. VDI, MDM or Conditional Access does not automatically remove an endpoint from scope. Agree any separately managed, network-segregated subset with your assessor. Devices used only for native voice, native text or MFA applications have a specific exception.

Short answer

Personal devices accessing organisational data or services are generally in scope, including devices used to access a virtual desktop. VDI, MDM or Conditional Access does not automatically remove an endpoint from scope. Agree any separately managed, network-segregated subset with your assessor. Devices used only for native voice, native text or MFA applications have a specific exception.

Why this matters

Scoping is where many Cyber Essentials submissions fail. The assessor needs to understand which users, devices, networks, and cloud services can access organisational data. A policy statement alone is not enough if the technical environment still allows access.

Agree the organisation, network boundary and locations with the assessor. A separately managed subset needs the required network segregation and a justified boundary. MDM, Conditional Access or a virtual desktop can help manage access, but none automatically excludes an endpoint or cloud service from assessment.

What to check next

  • List all devices and cloud services that access organisational data.
  • Document any exclusions and the technical enforcement behind them.
  • Check BYOD, home working, and production cloud environments before submitting.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.