Cyber Essentials Plus BYOD Testing: What the Assessor Will Sample
Published 7 July 2026
What counts as BYOD in scope
- Any personal phone that receives corporate email.
- Any personal tablet used to access shared drives, CRM or SaaS admin consoles.
- Any personal laptop used for work, including "occasional" home working.
- Contractor devices accessing your tenant, unless contractually excluded.
Devices that never touch organisational data are out of scope. "Reads their work calendar" counts as touching data.
How the assessor samples BYOD
Under the current IASME methodology, BYOD is sampled in line with its share of your user base. If half your staff read email on a personal phone, roughly half the mobile sample will be BYOD. Small numbers get rounded-sm up: the practical minimum is one BYOD device per OS family in scope.
Path 1: manage BYOD with MDM
- Intune, Jamf, Google Endpoint Management or a comparable MDM.
- Enforce screen lock, minimum OS version, disk encryption (default on modern iOS and Android).
- Compliance policy tied to Conditional Access so out-of-compliance devices lose access.
- User consent captured in the BYOD policy: staff know the corporate profile is manageable.
Path 2: app-level protection (MAM without enrolment)
Intune app protection policies (MAM-WE) let you apply controls to Outlook, Teams, OneDrive and Word on a personal device without full enrolment. You get PIN enforcement, copy-paste restrictions and selective wipe of corporate data, while the user's personal apps stay untouched. IASME accepts this route provided the app protection policies are enforced and evidenced.
Path 3: remove BYOD from scope
The strictest option: block personal devices from accessing corporate data at the identity provider. Conditional Access in Entra can require a compliant or hybrid-joined device before granting access to email or SharePoint. You must then live by it – no exceptions, no "just this once for the CEO's iPad".
What the sample day looks like
- The assessor connects to the sampled BYOD device (in person or via a remote tool).
- They verify the MDM or MAM profile is applied and reporting compliant.
- They verify screen lock, OS version and any allowlisted apps.
- If the device is managed by MAM only, they inspect one of the corporate apps and evidence the protection policy.
The common BYOD failure
The classic fail is telling the assessor "we do not have BYOD" while the sign-in logs show a dozen personal iPhones connecting to Outlook. Sign-in logs are the first thing an assessor pulls. Be honest about BYOD and manage it, or block it at the identity provider.
BYOD scope decisions overlap with your wider Microsoft 365 CE Plus setupand the MFA requirements for the 2026 Danzell question set.
