Are personal phones and home laptops in scope?
Scope is the decision that determines how hard your certification will be — and it is the one most organisations make by accident, after they have started answering questions.
Almost every small organisation reaches the same moment. Someone realises that the director reads work email on their own phone, or the part-time bookkeeper works from a home laptop, and asks whether that counts. It does, and understanding why makes everything else about scope straightforward.
The principle
Scope follows the data, not the ownership. If a device is used to access organisational data or services, it is in scope — regardless of who bought it, where it lives, or whether it is also used for family photographs.
That single rule resolves most of the questions people ask.
Personal mobile phones
In scope if used for work. A personal phone that reads work email, opens shared files or logs into a work system must have a supported operating system, security updates applied, a screen lock, and apps installed only from an official app store. A personal phone used only for calls and texts is not in scope.
Home laptops
In scope if used for work. Working from home does not take a device out of scope. It needs a supported operating system, its own software firewall switched on, updates applied within the required window, malware protection, and a separate user account rather than a shared family login.
The domestic router is not in scope, which surprises people. That is precisely why the firewall requirement attaches to the device itself — the scheme assumes you cannot control someone's home broadband, so the protection has to travel with the laptop.
Cloud services
Always in scope. No exceptions. Cloud services are now formally defined and cannot be excluded. Email, file storage, the accounting package, the CRM, the website content management system, the payroll provider — all of them. And MFA is mandatory on every one that offers it, which is one of only two answers that fail an assessment outright.
Contractors and volunteers
The question is the same: does the person access organisational data, and on what device? A contractor using their own laptop to work in your systems is a device in your scope. This is one of the harder conversations, because you are asking someone outside the organisation to meet your standard — which is exactly why it should be settled before the assessment rather than during it.
The three legitimate ways to narrow scope
Reducing scope is entirely allowed. Pretending is not. There are three honest routes.
Organisation-owned equipment for the roles that handle data, with a clear rule that work happens on work devices. Costs money, removes the problem, and is often cheaper than certifying five people's personal phones.
Access restricted to browser-based services with nothing downloaded or stored locally. This narrows what is in scope considerably, but it has to be genuinely enforced — if people can and do save attachments, the device is back in scope.
Where a network is excluded, it must be genuinely separated from in-scope systems — not merely described as separate. Under the current requirements you also have to justify the exclusion to the assessor rather than simply leaving it off the form.
Declaring devices out of scope while people carry on using them. The assessor is entitled to test whether the scope you described matches how the organisation actually operates, and the declaration is signed by someone confirming it is accurate. A scope that is not true is not a narrow scope — it is a false statement on a certification application.
Why this decision comes first
Scope determines the answer to nearly every subsequent question. Change the scope halfway through and the device counts, operating system list, MFA list and firewall answers all have to be revisited. Worse, if the assessor identifies a scope problem, the rework lands after you have already spent the time.
Organisations that certify smoothly almost always did the same thing first: they wrote down every device used for work including personal ones, every cloud service, and every person with access — then decided the scope deliberately, before opening the question set.
Whole organisation is usually the right answer anyway
For a small organisation, whole-organisation certification is normally simpler than engineering a narrow scope, and it is what customers actually want to see. A certificate covering a carved-out fragment invites the question of what was left out — and since certificates now name the entities covered, that question is easier for a customer to ask.
Narrow scope earns its complexity when there is a genuine reason: a legacy system that cannot be updated, a separate operational network, a subsidiary with its own IT. If none of those apply, certify the lot.
Get the scope right before you start
The scoping call is where certification is won or lost, and it takes a conversation rather than a form. Tell us how your organisation actually works — who uses what, and where — and we will tell you what your scope should be and what it would take.
Take the free readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd
Scheme requirements are set by the NCSC and IASME and are reviewed periodically. This guide reflects the Danzell question set and version 3.3 of the Requirements for IT Infrastructure. Confirm the requirements applying to your own assessment before you begin.