Do I need MDM for SOC 2 or ISO 27001?
No framework requires MDM by name. What they require is that laptops and phones reaching your data are encrypted, locked, patched and protected from malware, and that you can prove it. Answer five questions to see whether MDM is the practical way for you to do that, or whether lighter evidence will do.
No. SOC 2 and ISO 27001 do not name MDM. They require controls on the devices that reach in-scope data, such as disk encryption, screen lock, patching and malware protection, and an auditor needs evidence that those controls operate. A small team can evidence them with an agent or periodic checks. Past about 25 people, or with BYOD or regulated data, MDM is usually the cheapest evidence.
Result
Between 25 and 150 people, manual evidence becomes the bottleneck of the audit. Most teams adopt MDM here, or a posture agent that reports the same checks. With a mix of macOS, Windows and Linux, check that the tool covers every OS in use: Linux laptops are where MDM coverage is weakest.
- Decide: MDM if you also need to enforce settings and wipe devices; an agent if reporting is enough.
- Policy: write the device standard first, so whichever tool you pick checks the same list.
What each framework actually says about devices
SOC 2. The Trust Services Criteria never mention MDM. Three common criteria touch endpoints: CC6.1 (logical access security over information assets, including encryption), CC6.7 (restricting the transmission, movement and removal of information; its points of focus name Protects Endpoint Devices (mobile devices, laptops, desktops and sensors) and encrypting removable media) and CC6.8 (preventing or detecting unauthorised or malicious software). The auditor tests the controls you describe against them.
ISO 27001:2022. Annex A control 8.1 User endpoint devices requires that information on, processed by or reachable from endpoints is protected. Related controls: 5.10 acceptable use, 6.7 remote working, 7.9 security of assets off-premises, 8.7 protection against malware, 8.8 technical vulnerabilities and 8.24 use of cryptography. None names a tool.
HIPAA. The Security Rule requires workstation security and device and media controls (164.310(b) to (d)), with disposal and media re-use marked Required. Automatic logoff, encryption (164.312(a)(2)(iii) and (iv)) and malware protection (164.308(a)(5)(ii)(B)) are Addressable: you implement them, or document why an alternative is reasonable and implement that. A January 2025 proposal would make them required; it is not final.
Cyber Essentials. Requirements v3.3 (April 2026) apply secure configuration, security updates and malware protection to every in-scope laptop, desktop, tablet and phone: an unlock credential, lockout after no more than 10 failed attempts, updates within 14 days for critical or high-risk fixes, and anti-malware or application allow-listing. It does not require disk encryption.
PCI DSS. Device requirements such as anti-malware, patching and session controls apply to system components in or connected to the cardholder data environment. Staff laptops that never reach card data are usually out of scope.
MDM or lighter evidence
MDM earns its cost when you need to enforce settings, not just report them, or to wipe or lock a device remotely. A reporting agent, or dated screenshots on a small team, can show the same settings are in place. Auditors accept either if the evidence covers every in-scope device across the audit period. The usual tipping points are headcount past about 25, personal devices, regulated data on endpoints, and a Type 2 period where devices change during the window.
BYOD
Personal devices that reach company data are in scope everywhere. You do not have to manage the whole phone: work profiles and user enrolment manage only company apps and data, and conditional access can keep non-compliant devices out of company apps altogether. Write down what you check and what you may wipe, and have staff accept it.
Sources
- AICPA: 2017 Trust Services Criteria (with revised points of focus, 2022)
- ISO: ISO/IEC 27001:2022
- eCFR: 45 CFR Part 164 Subpart C, the HIPAA Security Rule
- eCFR: 45 CFR 164.310 Physical safeguards
- eCFR: 45 CFR 164.312 Technical safeguards
- NCSC: Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026)
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Is MDM required for SOC 2?
No. The Trust Services Criteria do not name MDM. CC6.1, CC6.7 and CC6.8 set the expectations (CC6.7's points of focus name protecting endpoint devices), and auditors look for controls such as encryption, restricted data movement and malware protection, and the auditor needs evidence they operate on every in-scope device. MDM is a common way to produce that evidence.
Is MDM required for ISO 27001?
No. Annex A control 8.1 requires that information on user endpoint devices is protected, and your Statement of Applicability says how. MDM is one way; a documented device standard with evidence from an agent or checks is another.
Does SOC 2 require disk encryption on laptops?
Not by name, but if laptops hold or reach customer data, auditors expect encryption under CC6.1 and CC6.7. It is cheap to turn on and hard to justify leaving off.
Does Cyber Essentials require MDM?
No. It requires that in-scope devices meet the five technical controls, including BYOD that reaches organisational data. MDM makes that easier to enforce and prove, but the scheme does not name it.
Do I need MDM for BYOD?
Not full device management. You need a way to check that personal devices meet your policy and to remove company access when someone leaves. Work profiles, user enrolment or device checks at sign-in all do that without managing the whole device.
What device evidence do SOC 2 auditors ask for?
Usually a device inventory, the device policy, and per-device proof of encryption, screen lock, OS updates and anti-malware for a sample of devices. In a Type 2 audit, the proof must cover the whole period, not one day.
Does HIPAA require encryption on laptops?
Encryption is an addressable specification under 164.312(a)(2)(iv): you must implement it or document why it is not reasonable and use an equivalent. For laptops holding PHI, that case is hard to make. A 2025 proposal would make encryption required; it is not yet final.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.