Cyber Essentials & Device Security: What UK Organizations Must Know in 2025
By Gijs Van Laer
October 17, 2025
Cyber Essentials is a UK government‑backed certification that sets baseline of cybersecurity strategy for organizations. It's designed to help companies demonstrate they are protected from the most common cyber threats.
Over time, it has evolved to address new workplace patterns, especially remote work and employee-owned devices.
In 2025, the requirements for devices have become more concrete. Many organizations that previously relied on broad policies will now have to show real technical enforcement, especially for home working and BYOD environments.
What's new in Cyber Essentials 2025 update
The 2025 update introduces several important refinements:
- The term "home working" is now "home and remote working", widening the scope of compliant devices.
- The description that used to be 'patches and updates' will be changed to 'vulnerability fixes', in order to include different methods, like configuration changes and scripts.
- Most importantly, BYOD now requires actual technical controls, not just a policy. This means every device used to access company systems (corporate, personal, or contractor-owned) must meet clear security standards.
"An organisation cannot use a written policy to substitute applying controls to a BYOD device; technical measures also need to be in place."
- Other controls (firewalls, secure configuration, malware protection, etc.) remain core, but with closer alignment with zero trust thinking.
Device security measures for compliance
Cyber Essentials focuses on five core control areas: firewalls, secure configuration, user access control, malware protection, and security update management. All five directly apply to devices.
The way people work has changed. With more employees working outside the office, Cyber Essentials now treats remote, home devices, and BYOD as fully in scope. These devices must meet the same control criteria as office devices.
Organizations must ensure that personal devices in use:
- Activate device firewalls and secure configuration
- Are kept up to date with OS and software patches
- Use strong screen locks and restrict login attempts
- Run anti‑malware or equivalent protection
- Avoid jailbreaking or root access, and more
Because employees' personal devices vary widely, simply telling them what to do is not enough. The organizations need to enforce device security measures and log compliance.
Why device-level enforcement matters
A few reasons why BYOD is no longer tolerated via written policies alone:
- Attackers often exploit weak endpoints (unpatched, misconfigured, outdated)
- Even if a policy exists, non-compliant devices may bypass protection gaps
- Auditors under Cyber Essentials v3.2 will expect active monitoring and evidence
- Unknown or ignored devices are a compliance risk when remote, hybrid, or contractor setups are common
How UK organizations should prepare
Here are action steps for organizations looking to align with Cyber Essentials v3.2's stricter device standards:
How XFA helps meet Cyber Essentials requirements
XFA gives UK organizations a modern, privacy-respecting way to enforce device security, even across BYOD, remote, or third-party devices, without requiring intrusive software or full MDM enrollment.
With XFA, you can:
- Enforce policy at login, based on live device posture (OS version, encryption, screen lock)
- Discover unmanaged and personal devices accessing cloud and internal systems
- Block risky devices before they reach your business apps
- Respect user privacy while generating audit-ready compliance evidence
- Automatically export data to UK-relevant compliance platforms (e.g. Drata, TrustCloud)
This approach helps organizations stay aligned with Cyber Essentials v3.2 while keeping employee trust and productivity high, even across remote teams.
Book a demo now to explore how XFA can help your organization or start with a free trial to see what's currently accessing your infrastructure.