The main article attempts to find a way through the Cyber Essentials standard for the actual working model of volunteer-driven charities. But every route in it relies, somewhere, on assessor interpretation – because a literal reading of the requirements leads somewhere no one can follow. On that reading, the only way to keep a volunteer’s device out of scope is to communicate with them solely by phone call or text message.
The guidance explicitly says:
“User owned devices which access organisational data or services (as defined above) are in scope”
and uses the definition:
“Organisational data includes any electronic data belonging to your organisation, for example, emails, documents, database data, financial data”
An email sent to a volunteer – even a volunteer-only email newsletter – fits this definition. This is the stated position taken to its conclusion, and the conclusion is absurd: it makes Cyber Essentials compliance impossible with even one volunteer.
“However, all mobile or remote devices used only for the purpose of:
- native voice applications
- native text applications
- multi-factor authentication (MFA) applications
are out of scope.”
The existence of this exemption is itself the tell: NCSC wouldn’t need to exempt phone calls and text messages unless receiving communications scopes a device by default. But if this is not the line the guidance intends to draw, it should say so.
Because if email between staff and volunteers doesn’t bring a device into scope, does WhatsApp? Does Telegram? A voice call between two iPhone users on FaceTime Audio arguably falls under the native-voice carve-out; the same call on WhatsApp brings the device into scope under this reading.
Why charities alone take the hit
It’s worth asking why this absurdity surfaces for charities in particular. After all, every business emails people outside its walls – customers, suppliers, subscribers – and nobody has ever suggested that a marketing newsletter drags ten thousand phones into a company’s certification.
But look at how those phones escape: not because the data definition spares them, but because the scoping table does. Customers have an explicit out-of-scope row. So do students. The definitions overreach for everyone, and the role table quietly absorbs the overreach for everyone – except organisations built on volunteers, because volunteers are the one population of loosely-connected people using their own devices that the table places, deliberately and by name, on the in-scope side.
The Danzell question set doesn’t soften this – it hardens it, twice over. Question A1.3 defines the organisation’s employees as including “volunteers… and others who have access to your organisational data,” and the scope guidance states that devices used by employees cannot be excluded. The volunteer isn’t just on the wrong side of a scoping table any more; they’re inside the definition of the workforce.
And the question set also shows us, in one sentence, exactly what the absorption mechanism looks like when the scheme wants one. The guidance under A2.6 reads:
“Devices outside the declared scope are excluded, but user accounts accessing the cloud service must comply with Cyber Essentials controls, including mandatory MFA.”
That is account-level compliance without device-level scoping – secure the login, leave the phone alone. It’s how a university’s students, a SaaS company’s customers, and a charity’s beneficiaries all use organisational cloud services without dragging their devices into anyone’s certification. It is precisely the mechanism a volunteer model needs. And volunteers are the one population barred from it, because their devices cannot be outside the declared scope in the first place.
That’s the trap in full. The volunteer row exists for good reason – volunteers do the organisation’s work and often hold real access. But it means the charity sector alone takes the data definition at full, literal strength, with no shielding row, no account-level escape hatch, and only the narrow voice-and-text exemption standing between a volunteer newsletter and a failed scope declaration.
Exhibit two: the social media credential
Danzell then manufactures a second version of the same flaw – and this one isn’t charity-specific. Version 3.3 defines cloud services for the first time, states they can never be excluded from scope, and adds, in terms: “Social media accounts (e.g. Facebook, LinkedIn, X) are also considered to be cloud services” (A2.9). MFA must be enabled for all users of every cloud service that offers it, on pain of automatic failure (A7.17).
Now follow the credential. A Facebook Page – and the Business Manager behind it – cannot be administered by an organisational account. It is administered through the personal Facebook profile of whoever runs it, because that is how Meta’s platform works.
Creating a separate work profile isn’t a fix: Meta’s authentic-identity terms permit one account per person, which means the “dedicated business profile” workaround leaves your entire Page and advertising estate hanging off an account Meta can remove at will. (Meta has built the actual fix – Managed Meta Accounts, work-only logins with SSO and no personal profile – but organisations must be invited by Meta to use them. Your local befriending charity will not be receiving the invite.)
A shared dummy account fails twice over: it violates Meta’s terms and Cyber Essentials’ own requirement that “accounts must not be shared” (A7.2).
So the organisation’s social media presence – an in-scope, non-excludable cloud service – is accessed exclusively through personal accounts. The MFA attestation the scheme demands is an attestation about the personal Facebook security settings of an employee or volunteer. The scheme is already treating a personal login as an organisational credential; that much is now simply true, and at least it’s enforceable – Business Manager can require two-factor authentication for everyone with asset access.
But the device question is where the definitions collide. The question set says devices “that are connecting to cloud services must be included” in the assessment (A2.8). The social media manager’s personal phone connects to Facebook – a declared, in-scope cloud service – through a session that cannot be separated from the organisational role, because the personal account is the organisational credential, page switching lives in the same app, and Page notifications arrive on the personal device by default.
Read one way, only the devices actually used to administer the Page are in scope (bad enough – social media managers live on their phones). Read the way the words point, every device logged into that personal account is connecting to an in-scope cloud service. And read against the A2.6 sentence quoted above, perhaps the device escapes and only the account must comply.
Three readings, one question set, no resolution – and unlike the volunteer newsletter, this version applies to every certifying organisation with a Facebook Page, which is most of them.
The question set is quietly saving everyone
Here is the strange part: if the literal reading were the operative one, the scheme would have collapsed years ago. Under it, almost no organisation in the country has ever truthfully certified. That hasn’t happened – and the reason is visible when you put the requirements document and the question set side by side.
The requirements document defines organisational data so broadly that receiving one work email scopes a phone. The question set never asks the question that would cash that in. It asks for devices “used for accessing organisational data or services,” framed by worked examples of laptops and staff phones; it asks for summaries by make and operating system; it asks nothing about newsletter recipients, announcement groups, or passive receipt of anything.
An organisation answering every Danzell question truthfully, on the ordinary meaning of the words, can certify without ever confronting the literal reading. The declaration is signed on reasonable enquiry against the questions asked – not against a definition three documents away, taken to its logical end.
In other words: the compliance surface is the question set, and the question set operationalises the practical reading. That is why the scheme functions. The literal text stays on the books; the questions decline to enforce it; assessor common sense papers over the residue.
The problem is the direction of travel. Every revision since 2022 has moved the questions closer to the text – tighter scope rules, mandatory justifications, and now automatic failures that remove assessor tolerance question by question. Danzell deleted discretion in exactly the places where discretion was doing load-bearing work, and simultaneously imported fresh definitional overreach (the cloud service definition, the social media clause) faster than the old overreach has been repaired.
And look at where the auto-fail markings landed: on MFA and update cadence – controls an organisation can technically enforce – and not on the application allow-listing question, the one requirement no organisation can honestly operate across a fleet of personal devices.
The auto-fail placement is a map of which of its own promises the scheme’s authors believe are actually keepable. The gap between what the requirements say and what the questions ask is the scheme’s shock absorber, and it is being machined away from both sides.
The NCSC has explicitly drawn its lines. Either it has made the same drafting error repeatedly, across every version of the standard since 2022 – or it expects the question set to go on absorbing definitions it declines to amend, and assessors to go on ignoring the words when the words point somewhere unworkable.
Either the standard should exempt all channels used solely to receive organisational communications – which would make the WhatsApp question, the social media credential problem, and most of this article disappear – or it should state plainly that organisational data on any non-exempt channel scopes the device, and let every sector, not just charities, confront what that means.
The current position, where the requirements document and the question set give different answers and the true one depends on which assessor you ask, serves nobody: not the charities certifying in good faith, not the assessors marking in the gap, and not the scheme whose credibility depends on its promises meaning what they say.
