Skip to main content
    NixInfinity-AI
    Device Scope

    Cyber Essentials for Thin Clients, Zero Clients and Remote Desktop Users

    Published 14 August 2026

    What is a thin client vs a zero client

    A thin client runs a small operating system (often Linux-based, ThinOS, IGEL OS or a stripped-down Windows IoT) and a remote-display client. A zero client runs only firmware – typically a PCoIP or HDX chip – with no general-purpose OS. Both connect to a hosted desktop, VDI or RDS environment.

    Why both are in scope

    Either device sends credentials, displays in-scope data and acts as the access path to organisational systems. That makes them user devices under Cyber Essentials – see hosted desktops and end-user devices.

    Controls that apply to thin clients

    • Supported OS / firmware – manufacturer must still issue security updates
    • 14-day patching for high/critical vulnerabilities
    • Secure configuration – default admin password changed, unused services disabled, USB policy considered
    • Account separation – local admin (if any) separate from user account
    • Malware protection where the platform supports it; otherwise rely on the locked-down OS plus restricted-execution stance
    • MFA on the account used to launch the hosted session

    Controls that apply to zero clients

    • Supported firmware from the vendor
    • Firmware updates applied within the 14-day window for critical advisories
    • Documented hardening baseline – password change on management interface, restricted protocols
    • MFA at the broker / IdP level on the connection account

    Common failure modes

    • End-of-life thin client OS still in production
    • Default admin password on the thin client management console
    • No central management for firmware updates
    • USB ports unrestricted, allowing local exfiltration despite a hosted desktop
    • Thin client running an unsupported browser that bypasses the VDI session

    Asset management still applies

    Thin and zero clients must be inventoried in the same way as laptops. You should be able to tell the assessor how many you have, what model/firmware they run, who owns them and when they were last updated.

    Remote desktop users on full PCs

    If staff use a normal laptop (Windows, macOS, Linux) to RDP into a hosted desktop, the full CE controls apply to that laptop in addition to anything done inside the session. The hosted desktop does not replace endpoint controls – it adds to them.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions