NIS2 BYOD Policy: The Directive Never Says “BYOD” — Here Are the 3 Annex Points That Govern Personal Devices
Search the full text of Directive (EU) 2022/2555 for the word “BYOD”. You get zero hits. Search it for “teleworking”, “personal device” or “smartphone” — zero, zero, zero. Now search Commission Implementing Regulation (EU) 2024/2690, the 13-section technical annex that spells out what Article 21(2) actually means in practice. “BYOD”: zero. “MDM”: zero. “wipe”: zero. The word “mobile” appears exactly once, and not where you would expect it [1][3].
That absence is the whole story. Personal devices are not out of scope — they are governed by derived obligations, assembled from provisions written about assets, identities and employment. Derived obligations are precisely the ones a supervisory authority asks you to justify in writing, because there is no checklist item to point at.
Does this apply to you?
Plain-language summary: if your organisation is an essential or important entity under NIS2 and any employee reads corporate email on a phone you do not own, you are already inside Article 21(2). Whether the detailed Implementing Regulation annex binds you, or merely serves as the benchmark you will be measured against, depends on your sector.
| Your situation | What governs your personal devices |
|---|---|
| DNS provider, TLD registry, cloud provider, data centre, CDN, managed service or managed security provider, online marketplace, search engine, social platform, trust service provider | CIR 2024/2690 binds you directly. Its Annex is a legal requirement, not a suggestion [1]. |
| Any other essential or important entity (energy, health, transport, manufacturing, water, public administration, postal…) | Article 21(2) binds you directly. The CIR Annex does not formally apply, but it is the Commission’s own reading of the same obligations — the de facto audit benchmark [1][2]. |
| Out of NIS2 scope | Neither applies. GDPR Article 32 and national employment law still do. |
The decision logic is three questions. Is the entity in scope of NIS2? Does any personal device process, transfer or store entity data — including a single mailbox sync? Does that device hold, or can it obtain, credentials to a system in your asset inventory? Two yeses put personal devices inside your risk-management scope. There is no employee-count threshold, no “under five devices” carve-out, and no exemption for a device the employee bought themselves.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
The three Annex points ENISA ties to personal devices
Article 21(2), point (i) of NIS2 requires “human resources security, access control policies and asset management” [2]. For a personal device those three limbs are not separate topics — they are three views of one object. The phone is an asset you do not own, carrying an identity you issued, held by a person whose employment you control. CIR 2024/2690 splits point (i) across Annex sections 10 (human resources security), 11 (access control, which also implements point (j)) and 12 (asset management) [1].
ENISA’s Technical Implementation Guidance, published June 2025 as the official companion to the Implementing Regulation, names personal devices in exactly three places:
| Annex point | What ENISA says about personal devices | What it means for you |
|---|---|---|
| 12.2 — Handling of assets | “Consider mobile devices, such as smartphones and tablets, and determine a strategy for mobile device management, including Bring-Your-Own-Device (BYOD)” [4] | Your asset-handling policy is where a BYOD position belongs — not a separate document. |
| 12.3 — Removable media policy | Footnote 105 extends the removable-media policy to “‘bring your own device’, if personal devices are used to store corporate data” [4] | A personal phone holding corporate files is treated like removable media — including 12.3.2(a)’s default of technical prohibition absent an organisational reason [1]. |
| 12.5 — Deposit, return or deletion on termination | “In cases where employees (and other third parties) use their own personal equipment, follow procedures to ensure that all relevant information is traced and transferred to the entity and securely deleted from the equipment” [4] | Offboarding is where BYOD compliance is won or lost. |
Note what is not on that list. Access control — Annex section 11 — never mentions devices at all. It regulates identities, rights and authentication [1]. The common framing that BYOD is fundamentally an access-control problem points implementers at the wrong section. Access control governs what the credential can reach; asset management governs the device the credential lives on. A BYOD programme documented only against section 11 has no answer when an auditor turns to 12.5.
One more correction: the only operative mention of mobile devices anywhere in the Annex is point 8.2.3(a), which requires security training to cover “instructions regarding the secure configuration and operation of the network and information systems, including mobile devices” [1]. That sits under basic cyber hygiene and training — Article 21(2)(g) — not under access control. If you are building an evidence pack, your training records are part of your BYOD evidence.
One provision does come closer to a direct BYOD control, and it sits in neither of the sections people look in. Annex point 6.7.2(g), under network security rather than asset management, requires entities to “where appropriate, exclusively allow access to the relevant entities’ network and information systems by devices authorised by those entities” [1]. That is device authorisation — what you would recognise as conditional access or enrolment-before-connect. It is the cleanest textual hook for requiring a personal phone to be enrolled before it can reach anything. It is also qualified by “where appropriate”, which means that whichever way you decide, the decision has to be written down.
What CNIL says you cannot do
Plain-language summary: the security control every MDM vendor sells you — full remote wipe of the device — is not lawfully available to an employer over an employee’s own phone, at least in France. Design around that constraint from the start rather than discovering it during a dispute.
France’s data protection authority has published direct guidance on BYOD, and it is unusually specific. On erasure: “Si l’employeur peut prévoir un effacement à distance de la partie du terminal personnel spécifiquement dédiée à l’accès distant aux ressources de l’entreprise, il ne peut en revanche s’arroger le droit d’effacer à distance l’ensemble des données présentes sur le terminal de l’employé” — the employer may provide for remote erasure of the part of the device dedicated to corporate access, but may not claim the right to erase everything on the employee’s device [5].
CNIL goes further. Security measures may not have the object or effect of obstructing private use of the device, and it gives banned examples: prohibiting web browsing, prohibiting the download of mobile applications [5]. A hardened device profile that blocks app installation — a completely standard corporate baseline — becomes unlawful the moment the device belongs to the employee. CNIL’s recommended answer is compartmentalisation, creating what it calls a “bulle de sécurité”, a security bubble containing the professional applications and data [5]. It also settles a question people argue about: whether to permit BYOD at all “relève avant tout d’un choix de l’employeur qui peut tout aussi bien l’autoriser sous conditions, ou l’interdire” — it is the employer’s choice, who may equally authorise it under conditions or prohibit it [5].
NIS2 pushes toward control of everything that touches your systems; data protection law pushes back at the boundary of the private sphere. Both apply at once, and our NIS2 and GDPR comparison covers the wider overlap. Two caveats: CNIL’s guidance binds in France and is persuasive, not binding, elsewhere, and it interprets data protection law rather than NIS2. Not every national authority has published an equivalent BYOD position, so a pan-European programme should expect variation rather than a single rule.
Annex 12.5: the offboarding clause nobody cites
Point 12.5 of the CIR Annex requires that assets under the custody of personnel “are deposited, returned or deleted upon termination of employment”, with the deposit, return and deletion documented. Then comes the sentence that does the real work: “Where the deposit, return or deletion of assets is not possible, the relevant entities shall ensure that the assets can no longer access the relevant entities’ network and information systems in accordance with point 12.2.2” [1].
Read that against a personal phone. You cannot take deposit of it. You cannot require its return. Full deletion is the thing CNIL says you may not do [5]. Every primary option in 12.5 fails — which triggers the fallback, and the fallback is not optional. You must be able to demonstrate that a departed employee’s own device can no longer reach your systems.
This is the strongest legal anchor for selective wipe and de-enrolment in the whole framework, and it reframes what your BYOD tooling is for. The requirement is not “wipe the device”. It is “sever the access, and evidence that you did”. ENISA’s suggested evidence for 12.5 is a completed exit checklist including asset return and data deletion steps, signed by the departing employee and the relevant supervisors [4]. For a personal device, that signed line is an attestation that corporate data has been removed and access revoked — which is why BYOD offboarding is an HR process with a technical step, not a technical process with an HR footnote. Annex point 10.3.2 supports this: post-termination security duties must be written into “the individual’s terms and conditions of employment, contract or agreement” [1].
A minimum configuration baseline — and how certain each item is
Most BYOD guidance presents a flat list of controls and implies they are equally mandated. They are not. The table below separates what the regulation states, what official guidance recommends, and what is industry practice with no regulatory text behind it — the distinction an auditor is testing when they ask why you chose a control.
| Control | Anchor | How firm is it? |
|---|---|---|
| Corporate data separated from personal data | ENISA guidance to 12.2; CNIL “bulle de sécurité” [4][5] | Recommended by two regulators, named in neither the Directive nor the CIR. Strong practice, not a citable mandate. |
| Encryption of corporate data on the device | Art. 21(2)(h); CIR Annex 9 and 12.3.2(d) [1][2] | Directive-level obligation — but encryption is “where appropriate”, so the decision must be documented. |
| MFA for access from the device | Art. 21(2)(j); CIR 11.7.1 [1][2] | “Where appropriate, in accordance with the classification of the asset to be accessed.” Classification first, then the control. |
| Only entity-authorised devices may connect | CIR 6.7.2(g), under Art. 21(2)(e) [1] | “Where appropriate.” The closest thing to a direct BYOD control in the CIR — and still qualified. |
| One identity per person, no shared family logins | CIR 11.5.2(b): “link the identity of users to a single person” [1] | Unhedged “shall”. The firmest device-adjacent requirement in the Annex. |
| Session timeout on inactivity | CIR 11.6.2(e) [1] | Unhedged “shall”; the interval is yours to define and defend. |
| Revocation of access on termination | CIR 11.2.2(b) and 12.5 [1] | Unhedged “shall”, twice. The least negotiable item here. |
| Device in the asset inventory | CIR 12.4.1: “complete, accurate, up-to-date and consistent inventory” [1] | Unhedged — but the CIR never resolves whether a personal phone is an entity asset. Record your interpretation. |
| Minimum OS version, jailbreak detection, app allow-listing | No regulatory text | Industry practice. Defensible as risk-based measures under Art. 21(1), not citable as NIS2 requirements — and CNIL limits app restrictions on personal devices [5]. |
Germany’s competent authority publishes the concrete MDM configuration reference the EU text lacks: the BSI Mindeststandard für Mobile Device Management, version 2.0 of 5 September 2022, with requirements such as MDM.2.5.02 on separating the management server’s device-communication component, and MDM.2.6.05, under which the management system should be able to prevent a user removing the provisioned device from management [6]. Read its scope note before citing it, though. The document states that it “behandelt keine spezifischen Anforderungen für Bring Your Own Device (BYOD)” — it addresses no BYOD-specific requirements at all [6]. It also binds German federal administration bodies under §8(1) BSIG rather than NIS2 entities. Useful corporate-device baseline; poor BYOD authority — which is worth knowing, because ENISA’s BYOD footnote points readers toward the neighbouring BSI IT-Grundschutz material [4].
Notice the pattern. Four of the nine items carry an unhedged “shall” — single-person identities, session timeouts, revocation on termination and inventory — and not one of them is a device-configuration control. Everything about how the phone itself is configured is hedged, recommended, or absent from the text entirely. That is the opposite of how the MDM market frames NIS2, and it is the framing your evidence pack should follow.
Do you need a standalone BYOD policy?
Strictly, no. NIS2 Chapter IV and the Implementing Regulation together require roughly thirty documents, and practitioner analysis puts a BYOD policy and a mobile device policy in the “recommended, not required” column [7]. Nothing obliges you to produce a document with BYOD in the title, and ENISA places the BYOD strategy inside the asset-handling policy required by 12.2 [4].
The practical answer depends on how much you permit. If personal devices are limited to mailbox and calendar sync, a clearly-marked BYOD section inside your asset-handling and access-control policies is easier to keep consistent than a fourth standalone document. If they reach line-of-business systems, or your workforce spans member states with different employment-law constraints, a dedicated policy earns its place — the employee-facing consent and acceptable-use content has no natural home in an asset policy, and you need it signed.
Whichever you choose, there is one document you cannot skip. CIR Article 2(2) states that where the Annex applies a requirement “where appropriate”, “where applicable” or “to the extent feasible”, and the entity considers it not appropriate, applicable or feasible, “the relevant entity shall in a comprehensible manner document its reasoning to that effect” [1]. Most BYOD controls sit under exactly those qualifiers. Decide that MFA is not appropriate for calendar-only access, or that encryption of a synced mailbox is covered by the platform, and the reasoning is itself a mandatory artefact. That is the sentence to build your BYOD file around.
What different roles should actually do
The same provisions land very differently depending on your seat:
| Role | The specific action |
|---|---|
| CISO / IT security manager | Classify the assets personal devices can reach before choosing controls — CIR 11.7.1 and 11.6.2(a) both make authentication strength a function of classification [1]. |
| Compliance officer | Write the Article 2(2) reasoning for every hedged control you are not applying, and file it where an audit will find it. An undocumented “not appropriate” reads as an unmanaged gap [1]. |
| HR | Put post-termination duties into the employment contract per Annex 10.3.2, and add a personal-device line to the exit checklist covering data removal and access revocation [1][4]. |
| SME owner without a security team | Start with the four unhedged obligations: one identity per person, session timeouts, revocation on termination, device in the inventory. They are cheap, and they have no “where appropriate” escape hatch [1]. |
| Management body | Article 20(1) makes the management body responsible for approving these measures and liable for infringements — including the decision to permit BYOD at all. |
Frequently asked questions
Does NIS2 ban BYOD? No. Neither the Directive nor the Implementing Regulation mentions it, and CNIL treats permitting or prohibiting personal devices as the employer’s decision [3][5]. What NIS2 removes is the option of permitting it without documented, risk-proportionate controls.
Is MDM mandatory under NIS2? No — “MDM” appears nowhere in the Directive or the Annex [1][3]. ENISA recommends determining a mobile device management strategy under point 12.2, which is a strategy, not a product [4]. MDM or MAM is the usual way to satisfy the underlying obligations; it is not itself the obligation.
Can we remotely wipe an employee’s personal phone? Only the corporate compartment. CNIL states the employer may provide for remote erasure of the part of the device dedicated to corporate access but may not claim the right to erase the whole device [5]. Build the capability at the compartment level and say so in the policy the employee signs.
Does a personal phone belong in our asset inventory? The regulation does not say. Point 12.4.1 requires a complete and accurate inventory of “their assets”, and a device the entity does not own sits at the edge of that phrase [1]. The defensible approach is to record the corporate access — the enrolled work profile, the identity, the data reachable — rather than claiming the hardware, and to document that reasoning.
The short version
Personal devices are governed through three asset-management provisions and a set of identity obligations, not through a BYOD rule — because there is no BYOD rule. The four requirements with no escape clause — one identity per person, session timeouts, revocation on termination, inventory — are about identities, sessions and records, not about how the phone is configured. Everything about the device itself is qualified by “where appropriate”, which converts your reasoning into a mandatory document under CIR Article 2(2). And the control most people assume is the answer — wiping the device — is the one a data protection regulator has explicitly placed out of reach.
Start with the offboarding path. If you can demonstrate today that a person who left last month can no longer reach anything from their own phone, and show the record of it, you have the hardest part of Annex 12.5 already covered. Work backwards from there through classification, identity and the Implementing Regulation mapping, and the rest of the Article 21 picture follows.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Commission Implementing Regulation (EU) 2024/2690 — EUR-Lex (Article 1 scope; Article 2(2); Annex points 8.2.3, 10.3.2, 11.2.2, 11.5.2, 11.6.2, 11.7.1, 12.2, 12.3, 12.4.1, 12.5)
- NIS2 Directive, Article 21 — Cybersecurity risk-management measures (points (h), (i) and (j))
- Directive (EU) 2022/2555 (NIS2), full text — EUR-Lex (Article 21(1) proportionality; keyword verification)
- ENISA, Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0, June 2025 (non-binding guidance; points 12.2, 12.3 footnote 105, and 12.5)
- CNIL — BYOD : quelles sont les bonnes pratiques ?
- BSI — Mindeststandard des BSI für Mobile Device Management nach § 8 Absatz 1 Satz 1 BSIG, version 2.0 (5 September 2022), PDF
- Advisera — NIS 2 Documentation: What is Required?
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
