Short answer
Personal devices accessing organisational data or services are generally in scope, including devices used to access a virtual desktop. VDI, MDM or Conditional Access does not automatically remove an endpoint from scope. Agree any separately managed, network-segregated subset with your assessor. Devices used only for native voice, native text or MFA applications have a specific exception.
Why this matters
Scoping is where many Cyber Essentials submissions fail. The assessor needs to understand which users, devices, networks, and cloud services can access organisational data. A policy statement alone is not enough if the technical environment still allows access.
Agree the organisation, network boundary and locations with the assessor. A separately managed subset needs the required network segregation and a justified boundary. MDM, Conditional Access or a virtual desktop can help manage access, but none automatically excludes an endpoint or cloud service from assessment.
What to check next
- List all devices and cloud services that access organisational data.
- Document any exclusions and the technical enforcement behind them.
- Check BYOD, home working, and production cloud environments before submitting.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.