Choose Your Own Device is a corporate mobility model where employees select from a list of approved devices. It gives users some choice while preserving stronger enterprise control over configuration, monitoring, security settings, and application management than a fully open personal device policy.
How CYOD differs from BYOD and fully managed mobility
CYOD sits between employee choice and enterprise standardisation. The organisation narrows device variety to approved models, which reduces support complexity and makes it easier to enforce security baselines than a fully open BYOD program.
That middle position matters because the security posture comes less from ownership and more from what the enterprise can standardise: operating system versions, configuration profiles, encryption, screen-lock settings, and mobile device management enrollment. When the device catalogue is tightly curated, the business can apply CIS Benchmarks more consistently across the fleet.
Security controls CYOD can strengthen
A well-run CYOD model usually improves control over configuration drift, patch cadence, approved applications, and data separation between corporate and personal use. It also gives security teams a cleaner policy surface for conditional access, remote wipe, and compliance monitoring.
Because the devices are pre-approved, organisations can pair the mobility program with stronger baseline controls rather than negotiating exceptions for every endpoint. That makes CYOD a practical fit for environments that need predictable enforcement of encryption, audit logging, and device integrity checks, especially when the program is tied to broader NIST Cybersecurity Framework 2.0 governance.
Operational trade-offs and user experience
CYOD is attractive when employees want more flexibility than a corporate-issued single model, but the enterprise still needs a bounded support matrix. The trade-off is that user choice is real, yet not unlimited, so procurement, help desk support, and lifecycle planning remain easier than in a loose bring-your-own-device model.
The model can also reduce friction around onboarding and replacement devices because users choose from a known catalogue, but it only works well when the catalogue is refreshed often enough to remain usable. If approved devices lag behind market expectations, employees may bypass the intent of the policy through shadow IT, unmanaged apps, or informal workarounds.
Where CYOD fits in a modern endpoint strategy
CYOD is most effective as part of a larger endpoint governance program, not as a standalone security control. It should be aligned with mobile device management, acceptable use policy, data classification, and remote support procedures so the organisation can distinguish between personal preference and enterprise control.
For teams building device policy, the key question is whether the approved list is designed around risk reduction, supportability, or both. When that list is chosen deliberately, CYOD can preserve a better user experience without giving up the control needed for regulated data, managed apps, and secure access to corporate services.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 4 — Secure Configuration of Enterprise Assets and Software | CYOD depends on standard device baselines and controlled configuration. |
| CIS 6 — Access Control Management | CYOD is used to govern who can access corporate resources from approved devices. | |
| Recommendation — Enforce approved device baselines and lock mobile settings to the corporate standard. Restrict corporate access to enrolled, policy-compliant devices. | ||
| NIST CSF 2.0 | PR.AC — Identity Management, Authentication, and Access Control | CYOD affects access decisions tied to device compliance and trust. |
| Recommendation — Bind access to device posture checks and policy-compliant endpoints. | ||
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org