Cyber Essentials Plus for Remote and Distributed Teams
Published 7 July 2026
Home network: in scope or out?
A staff member's home router is not in your CE Plus scope. The device connected to it is. Enable the host firewall on every laptop, treat every network as untrusted, and route access through identity and device compliance rather than network location.
Identity is the new boundary
- MFA enforced on every account, no exceptions.
- Conditional Access blocks access from non-compliant devices, not just non-corporate networks.
- Session controls limit persistent sign-in on high-risk accounts.
- Legacy authentication protocols disabled tenant-wide.
Device controls that satisfy the assessor
- Full-disk encryption (BitLocker, FileVault) on every laptop.
- Host firewall enabled and evidenced in the MDM compliance policy.
- Anti-malware active with signatures under 24 hours old.
- Screen auto-lock at 15 minutes or less.
- Automatic security updates applied within 14 days of vendor release.
VPN or Zero Trust: does it matter?
Either passes. A VPN protecting a legacy on-prem app is fine. A Zero Trust model with device-aware access to cloud apps is fine. What matters to CE Plus is that unpatched, non-compliant devices cannot reach organisational data.
How the sample audit works with no office
- The assessor agrees a sample list with you, weighted across OS families and BYOD share.
- You install a temporary scanning agent on each sample device 48 hours before the audit window.
- On the day, the assessor connects remotely (screen share, remote scan agent) and runs the checks.
- Test user accounts you provision receive the email and web-download test payloads.
Shipping hardware for the audit
For genuinely dispersed teams, staff run the scanning agent themselves after a short walkthrough. Only shipping laptops for physical inspection is required in rare edge cases (usually air-gapped or compliance-restricted environments). The audit remains remote.
The remote-work common failures
- Staff on an older personal laptop as a backup device with no MDM.
- Home printers on the corporate SSO for scan-to-email – unpatched and forgotten.
- Local admin rights granted "just for the install" and never revoked.
- Split-tunnel VPN with the split routed round the security stack.
For the wider BYOD picture see CE Plus BYOD testing, and for the M365 configuration that makes remote work auditable see CE Plus for Microsoft 365.
