Skip to main content
    NixInfinity-AI
    BYOD Guide

    Cyber Essentials BYOD Rules Explained

    Published 22 June 2026

    The rule, in one sentence

    A device is BYOD-in-scope if it accesses any organisational data, regardless of who owns it. The most common BYOD case in 2026 is staff checking work email or Slack on personal phones.

    Three scenarios, three different answers

    Scenario A: "We don't allow BYOD"

    You provide every staff member with a corporate laptop and a corporate phone. Personal devices are blocked from cloud services via Conditional Access or equivalent. You answer "no BYOD" on the questionnaire and you must be able to prove it via a Conditional Access policy or MDM enrolment requirement.

    Scenario B: "BYOD for mobile only"

    Staff use corporate laptops for work, but check email/Slack on their own phones. This is the most common SME pattern. BYOD is in scope for mobile devices only. Apply MFA on the cloud account, require supported OS, and have a written BYOD policy.

    Scenario C: "Full BYOD"

    Staff use their own laptops as well as their own phones. This is harder for CE because the laptop must meet every CE control – software firewall, supported OS, AV, patching, secure configuration. Practically possible, but you'll need either MDM or a strict policy plus user attestation.

    The controls you must apply to BYOD-in-scope devices

    Boundary firewall

    For mobile, this is generally satisfied by the device's built-in firewall and the carrier/Wi-Fi network. For BYOD laptops, the device's software firewall must be enabled.

    Secure configuration

    Auto-lock with PIN/biometric on all devices. No default admin passwords. Disk encryption on laptops (FileVault/BitLocker).

    User access control

    MFA on the cloud account is the critical one. Under the Danzell question set, MFA must apply to all cloud user accounts including from BYOD.

    Malware protection

    For mobile: install only from the official app store (App Store / Google Play). For BYOD laptops: active AV (Defender on Windows, built-in protections on macOS).

    Security update management

    Auto-update enabled. The user is responsible. Document this in the BYOD policy and have the user attest.

    The BYOD policy template

    You need a written BYOD policy. Keep it short and enforceable. It should cover:

    • What devices are allowed (phones, tablets, laptops?)
    • What organisational data is allowed on BYOD (email, files, both?)
    • OS minimums (e.g. iOS 17+, Android 13+, macOS 14+, Windows 11)
    • Required settings (auto-lock, encryption, auto-update)
    • Required apps (only from official app store)
    • What happens when someone leaves (remote wipe of work data, account disable)
    • User attestation – they sign or accept the policy

    Conditional Access: the BYOD multiplier

    If you have Microsoft Entra ID P1, Conditional Access lets you enforce many of these controls automatically. You can require:

    • MFA on every BYOD sign-in
    • Compliant device or app protection policy
    • Block sign-in from unsupported OS versions
    • Restrict download to managed devices only

    For SaaS companies and tech teams this is the cleanest BYOD path – see our Microsoft 365 checklist.

    Common BYOD fails

    1. Saying "no BYOD" but actually allowing work email on personal phones
    2. BYOD policy on paper but no user attestation or enforcement
    3. One BYOD phone running an unsupported OS
    4. BYOD allowed but MFA not enforced on the cloud account from BYOD
    5. No process for revoking BYOD access when someone leaves

    The 30-minute BYOD audit

    1. List every cloud service that BYOD can access (start with email)
    2. Check MFA is enforced for every account on those services
    3. Confirm minimum OS versions in your BYOD policy
    4. Document the leavers process for BYOD (remote wipe / account disable)
    5. Have every BYOD user sign or accept the policy

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions