Rule explainer
BYOD and thin clients: how personal devices get scoped under Cyber Essentials
The general principle is simple: any device that can access organisational data or your approved cloud services is potentially in scope, whether or not the business owns it. A personal phone used to check work email, or a personal laptop used to log into a shared drive, doesn't get a pass just because it's not company-issued.
A personal phone used to check work email, or a personal laptop used to log into a shared drive, doesn't get a pass just because it's not company-issued.
There are ways to take a device out of scope deliberately, most commonly a thin-client or VDI setup, where the personal device is only a window onto a remote environment and no organisational data actually lands on the device itself, or a mobile device management (MDM) setup that applies the required controls to a personal device directly. Without one of those in place, the device is in.
This is one of the areas businesses most often get wrong, in both directions. Some assume "it's not a company device, so it doesn't count," which is wrong and leaves a real gap. Others over-scope every personal device in the business out of caution, when a proper thin-client or MDM approach would have narrowed what actually needs to meet the standard.
Worth knowing
This is worth resolving early, before an assessment, not during one. Run the free 5-minute readiness check or book a free 30-minute call if your setup includes personal devices and you're not sure how they'd be scoped.