Free tool · Devices and MDM

Do I need MDM for SOC 2 or ISO 27001?

No framework requires MDM by name. What they require is that laptops and phones reaching your data are encrypted, locked, patched and protected from malware, and that you can prove it. Answer five questions to see whether MDM is the practical way for you to do that, or whether lighter evidence will do.

Short answer

No. SOC 2 and ISO 27001 do not name MDM. They require controls on the devices that reach in-scope data, such as disk encryption, screen lock, patching and malware protection, and an auditor needs evidence that those controls operate. A small team can evidence them with an agent or periodic checks. Past about 25 people, or with BYOD or regulated data, MDM is usually the cheapest evidence.

Answer for your organisation

Production access includes admin consoles, databases and customer exports.
Worked example: a 40-person SaaS company preparing for SOC 2

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
It depends: an agent or MDM; manual checks stop scaling

Between 25 and 150 people, manual evidence becomes the bottleneck of the audit. Most teams adopt MDM here, or a posture agent that reports the same checks. With a mix of macOS, Windows and Linux, check that the tool covers every OS in use: Linux laptops are where MDM coverage is weakest.

Full-disk encryption on laptops that hold or reach customer dataSOC 2 CC6.1, CC6.7 · ISO A.8.1, A.8.24 · HIPAA 164.312(a)(2)(iv)
Screen lock and an unlock credentialISO A.8.1 · HIPAA 164.312(a)(2)(iii) · CE secure configuration
OS and app patching within a set windowISO A.8.8 · CE: 14 days for critical and high
Anti-malware or application allow-listingSOC 2 CC6.8 · ISO A.8.7 · HIPAA 164.308(a)(5)(ii)(B) · CE
A way to lock, wipe or cut off a lost or departing deviceISO A.8.1, A.7.9 · HIPAA 164.310(d)(1)
  • Decide: MDM if you also need to enforce settings and wipe devices; an agent if reporting is enough.
  • Policy: write the device standard first, so whichever tool you pick checks the same list.
01

What each framework actually says about devices

SOC 2. The Trust Services Criteria never mention MDM. Three common criteria touch endpoints: CC6.1 (logical access security over information assets, including encryption), CC6.7 (restricting the transmission, movement and removal of information; its points of focus name Protects Endpoint Devices (mobile devices, laptops, desktops and sensors) and encrypting removable media) and CC6.8 (preventing or detecting unauthorised or malicious software). The auditor tests the controls you describe against them.

ISO 27001:2022. Annex A control 8.1 User endpoint devices requires that information on, processed by or reachable from endpoints is protected. Related controls: 5.10 acceptable use, 6.7 remote working, 7.9 security of assets off-premises, 8.7 protection against malware, 8.8 technical vulnerabilities and 8.24 use of cryptography. None names a tool.

HIPAA. The Security Rule requires workstation security and device and media controls (164.310(b) to (d)), with disposal and media re-use marked Required. Automatic logoff, encryption (164.312(a)(2)(iii) and (iv)) and malware protection (164.308(a)(5)(ii)(B)) are Addressable: you implement them, or document why an alternative is reasonable and implement that. A January 2025 proposal would make them required; it is not final.

Cyber Essentials. Requirements v3.3 (April 2026) apply secure configuration, security updates and malware protection to every in-scope laptop, desktop, tablet and phone: an unlock credential, lockout after no more than 10 failed attempts, updates within 14 days for critical or high-risk fixes, and anti-malware or application allow-listing. It does not require disk encryption.

PCI DSS. Device requirements such as anti-malware, patching and session controls apply to system components in or connected to the cardholder data environment. Staff laptops that never reach card data are usually out of scope.

02

MDM or lighter evidence

MDM earns its cost when you need to enforce settings, not just report them, or to wipe or lock a device remotely. A reporting agent, or dated screenshots on a small team, can show the same settings are in place. Auditors accept either if the evidence covers every in-scope device across the audit period. The usual tipping points are headcount past about 25, personal devices, regulated data on endpoints, and a Type 2 period where devices change during the window.

03

BYOD

Personal devices that reach company data are in scope everywhere. You do not have to manage the whole phone: work profiles and user enrolment manage only company apps and data, and conditional access can keep non-compliant devices out of company apps altogether. Write down what you check and what you may wipe, and have staff accept it.

04

Sources

Questions

The things people ask us

Is MDM required for SOC 2?

No. The Trust Services Criteria do not name MDM. CC6.1, CC6.7 and CC6.8 set the expectations (CC6.7's points of focus name protecting endpoint devices), and auditors look for controls such as encryption, restricted data movement and malware protection, and the auditor needs evidence they operate on every in-scope device. MDM is a common way to produce that evidence.

Is MDM required for ISO 27001?

No. Annex A control 8.1 requires that information on user endpoint devices is protected, and your Statement of Applicability says how. MDM is one way; a documented device standard with evidence from an agent or checks is another.

Does SOC 2 require disk encryption on laptops?

Not by name, but if laptops hold or reach customer data, auditors expect encryption under CC6.1 and CC6.7. It is cheap to turn on and hard to justify leaving off.

Does Cyber Essentials require MDM?

No. It requires that in-scope devices meet the five technical controls, including BYOD that reaches organisational data. MDM makes that easier to enforce and prove, but the scheme does not name it.

Do I need MDM for BYOD?

Not full device management. You need a way to check that personal devices meet your policy and to remove company access when someone leaves. Work profiles, user enrolment or device checks at sign-in all do that without managing the whole device.

What device evidence do SOC 2 auditors ask for?

Usually a device inventory, the device policy, and per-device proof of encryption, screen lock, OS updates and anti-malware for a sample of devices. In a Type 2 audit, the proof must cover the whole period, not one day.

Does HIPAA require encryption on laptops?

Encryption is an addressable specification under 164.312(a)(2)(iv): you must implement it or document why it is not reasonable and use an equivalent. For laptops holding PHI, that case is hard to make. A 2025 proposal would make encryption required; it is not yet final.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.