The problem Cyber Essentials is designed to address
Cyber Essentials is a UK government-backed scheme covering five foundational technical controls: firewalls, secure configuration, user access control, malware protection and patch management. The scheme is straightforward in principle. In construction and infrastructure businesses, the scope question is the one that most often catches teams out.
Scope is not defined by what your organisation owns. It is defined by what can access your organisation's services.
What "in scope" means in practice
The Cyber Essentials guidance is clear: any device used to access your organisation's data or services — including web-based services like email, SharePoint and Teams — must meet the scheme's five controls if it is within the assessment boundary you declare.
For a construction business, that boundary may include:
- Company-issued phones and laptops
- Personal phones used by employees to check work email
- Tablets carried on site by supervisors
- Contractor laptops and phones given temporary access to project systems
- Subcontractor devices accessing shared document platforms such as Procore, Aconex or SharePoint
If you are declaring a scope that excludes some of these devices, you need a documented and technically enforced reason for the exclusion — not simply a policy that says people should only use company devices.
Why personal phones are the common gap
Most construction businesses use Microsoft 365. Email and Teams are available on personal phones via the standard mobile apps. Subcontractors, site supervisors and project managers frequently access project communications from personal devices because it is convenient and because no technical restriction prevents it.
When Cyber Essentials asks whether devices accessing your services are patched, configured securely and have malware protection, a personal phone that has not been enrolled in device management and has not had its configuration validated by your IT team is not a device you can confidently declare in scope.
The options are:
- Enrol the device in MDM (such as Microsoft Intune) — this brings the device under a level of control that allows you to enforce configurations and declare it in scope.
- Use managed application access — Microsoft Intune App Protection Policies can enforce minimum OS versions, encryption and PIN requirements on the work application container without full device enrolment. This can reduce the risk and, depending on assessor interpretation, may support a narrower scope definition. You should confirm with your certification body.
- Restrict access to managed devices only — Conditional Access policies in Entra ID (Azure AD) can require MDM compliance before allowing access to corporate services, which effectively prevents ungoverned devices from reaching the services in scope.
The worst position — common in construction — is none of the above: no MDM, no App Protection Policies, no Conditional Access, but an assumption that because people are using their own phones rather than company ones, the devices are "outside scope."
They are not. Access is the deciding factor.
Contractor devices
Subcontractors present a specific challenge. A main contractor running Cyber Essentials may give a subcontractor temporary access to a shared project folder or communications platform. If that access is via the subcontractor's own device, the scope question becomes: is that device in your assessment boundary?
Practically, you have three routes:
- Provide a company-owned device for the duration of the engagement (operationally expensive and rarely used for short-term work)
- Require the contractor to access project systems only through a browser-based interface that does not install data on the device, and enforce this technically using Conditional Access (the most manageable approach for most businesses)
- Accept the device into your MDM and remove it on offboarding (feasible for longer engagements with a clear process, but requires the contractor's consent and creates an offboarding dependency)
What is not acceptable — for Cyber Essentials purposes or for practical data governance — is allowing access to continue after the contractor has left the project. Account closure is not the same as access removal. Project file permissions, shared drives and application access can persist after an account is disabled if the offboarding process is not thorough.
What this means for Cyber Essentials Plus
Cyber Essentials Plus involves independent technical verification that the controls you declared in your basic submission are actually implemented. An assessor will test real devices. If personal or contractor phones are in scope, they will be tested. If they are out of scope, the assessor will want to understand the technical boundary that enforces the exclusion.
Businesses that have declared a clean scope at the basic level and then cannot demonstrate the enforcing controls during Plus verification often face delays and remediation costs they had not anticipated.
The practical starting point
Before beginning a Cyber Essentials application, the most useful exercise is an honest inventory of device access: which devices, owned by whom, are currently accessing your email, cloud storage, Teams and any other services you plan to include in scope.
If the answer includes personal phones and contractor devices — which it almost certainly does in construction — the follow-up question is what technical controls govern those devices today.
The interactive guide below walks through a specific scenario involving a subcontractor whose project has ended. It shows, step by step, what access remains when an account is simply closed, and what a controlled offboarding process looks like in practice.
If you want to talk through your Cyber Essentials readiness — including how to handle devices that are currently ungoverned — speak to us directly.



