Cyber Essentials Malware Protection: What Counts in 2026
Published 9 June 2026
The three approved approaches
The IASME question set is unusually flexible here. You don't have to install anti-malware on everything. You have to use one of three approved methods per device class:
- Anti-malware software – signature- or behaviour-based AV.
- Application allowlisting – the device only runs approved software.
- Sandboxing – untrusted code runs in an isolated container.
What works for which device class
Windows laptops and desktops
Defender for Endpoint (built in) is acceptable when configured correctly: real-time protection on, cloud-delivered protection on, automatic sample submission on, definitions updating. Third-party AV (Sophos, SentinelOne, CrowdStrike) is also fine. The configuration evidence matters more than the brand.
Mac laptops and desktops
Either AV (Jamf Protect, Sophos, Defender for Mac), or an enforced "App Store and identified developers" policy with Gatekeeper on. Gatekeeper alone doesn't always satisfy assessors – pair it with a documented configuration baseline.
Linux desktops/servers
Real-world malware risk is lower, but the question still applies if the device is in scope. ClamAV plus a hardened configuration is the common answer; allowlisting via SELinux/AppArmor is acceptable evidence too.
iOS and Android mobiles
App-store-only installs (no sideloading), enforced through MDM (Intune, Jamf, Kandji) or a documented policy. This is treated as application control rather than AV. For Android, no installations from "unknown sources".
What the assessor checks
- The control is active across the fleet, not just on a sample of "good" devices.
- Definitions or app catalogues update automatically.
- Real-time protection is on (not just scheduled scans).
- Users can't disable the control without admin rights.
- Coverage extends to BYOD where BYOD is in scope.
Common slip-ups
- Defender showing as off on a developer's laptop because a previous AV uninstall left it disabled.
- Mac fleet relying on "Gatekeeper handles it" with no MDM enforcement.
- Server AV with definitions 30 days behind because automatic updates broke.
- BYOD phones with no MDM, sideloading allowed, and no documentation.
- Allowlisting documented as the approach, but the allowlist isn't actually enforced – just an aspirational list.
Evidence pack items
- Screenshot of the AV admin console (Defender, Jamf, Sophos) showing fleet-wide status.
- Configuration profile from MDM enforcing the relevant policy.
- For mobile: MDM or documented BYOD policy showing app-store-only installs.
- For allowlisting: the actual allowlist plus the change-control process.
The wider context lives in our five controls breakdown, with related guidance in secure configuration and the 14-day patching rule.
