Skip to main content
    NixInfinity-AI
    Remote Working

    Cyber Essentials for Remote & Home Workers

    Published 30 April 2026

    What is in scope for a remote worker

    • The corporate-issued device they use (laptop, phone, tablet)
    • The cloud accounts they sign into for work (Microsoft 365, etc.)
    • The software firewall on the device (Windows Defender Firewall, etc.)
    • Patch status and anti-malware on the device

    What is not in scope

    • The home router – Cyber Essentials does not require you to manage it, provided the device has its own software firewall enabled.
    • Personal devices the worker owns and uses only personally.
    • The home network in general.

    BYOD interplay

    If a remote worker uses a personal device for work, BYOD scope rules apply. The device itself does not need full MDM, but the cloud accounts they sign into are in scope and MFA, password policy and account hygiene all apply. See our BYOD guide.

    VPN and zero-trust

    A VPN is not required by Cyber Essentials. Modern zero-trust patterns (Conditional Access, device compliance) satisfy the assessor equally. The control objective is that the device and account are protected, not that traffic is tunnelled.

    Practical checklist for a remote-first team

    • Every device is corporate-issued or properly enrolled in MDM
    • Software firewall enabled on every device
    • Disk encryption enabled (BitLocker, FileVault)
    • Anti-malware running and reporting back centrally
    • MFA enforced on every cloud account
    • Conditional Access rules block legacy authentication
    • Patches applied within 14 days of vendor release
    • Admin accounts separate from day-to-day accounts

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions