- Purple
- Enterprise WiFi security and authentication: a complete guide
- Cyber Essentials and Staff WiFi: Passing the Five Controls on Your Wireless Network
Cyber Essentials and Staff WiFi: Passing the Five Controls on Your Wireless Network
You will be able to map each of the five Cyber Essentials controls to your staff WiFi and close the gaps assessors find. You can then choose between 802.1X, iPSK and a segregated WPA2-PSK network for each device class. Finally, you will know how to prepare access points, controllers and BYOD for a Cyber Essentials Plus audit.
Video overview
Part of our core series: Enterprise WiFi Security Guide →
- What is Cyber Essentials asking of your staff WiFi?
- Why does staff WiFi decide so many audits?
- How do the five controls apply to your wireless network?
- Firewalls and boundary devices
- Secure configuration
- User access control
- Malware protection
- Security update management
- Which questionnaire items sink a poorly configured staff WiFi?
- Does WPA2-PSK pass user access control?
- How does Cyber Essentials Plus probe your staff WiFi?
- Where does Purple sit alongside your existing wireless network?
- Two worked scenarios
- A 200-room hotel with one shared staff key
- A 40-store retail chain preparing for Plus
- What are the limits you should know about?
- What should you do next?
- Frequently asked questions
- Does Purple Staff WiFi work with the access points we already own?
- Do we have to remove WPA2-PSK to pass Cyber Essentials?
- Is our guest WiFi in scope for Cyber Essentials?
- Are staff personal phones on the staff SSID in scope?
- Does Cyber Essentials Plus test our wireless network directly?
- How much work is it to move staff WiFi to 802.1X before our assessment?
- Is Purple secure and compliant?
To pass the five Cyber Essentials controls on your wireless network, you must secure staff WiFi using the 802.1X standard or iPSK. Integrating platforms like Cisco Meraki lets you enforce individual user access controls, patch firmware within 14 days, and apply MFA to protect your in-scope devices.
What is Cyber Essentials asking of your staff WiFi?
Cyber Essentials is the UK government-backed scheme that certifies five technical controls against common internet-borne attacks. The National Cyber Security Centre (NCSC) owns the technical requirements. IASME has delivered the scheme as the NCSC's partner since April 2020. Assessments from 28 April 2025 use the Willow question set, which aligns to version 3.2 of the NCSC requirements.
The questionnaire has no separate wireless chapter. Your staff WiFi appears inside every control instead. Access points, wireless controllers and the cloud dashboard that manages them are in-scope devices or services. Laptops and phones on your staff SSID (the network name your employees join) are in-scope end-user devices if they reach organisational data or services.
This guide sits under Purple's Staff WiFi pillar, which covers identity-based employee access on the hardware you already run. Here we narrow that to one practical question. Which wireless settings pass a Cyber Essentials or Cyber Essentials Plus assessment, and which ones sink it?
Why does staff WiFi decide so many audits?
Three features of the scheme pull your wireless network into the spotlight.
Scope. The NCSC requirements bring wireless devices, including access points, into scope when they can communicate with other devices over the internet. Every cloud-managed access point does this by design.
Bring your own device (BYOD). Since version 3.0 of the requirements took effect in January 2022, staff-owned devices that access organisational data or services are in scope. A staff SSID that welcomes personal phones can quietly add dozens of devices to your assessment. Devices used only for MFA apps, voice calls and text messages are excluded.
Verification. Cyber Essentials Plus checks your self-assessment answers against your live estate. A staff network configured years ago by a contractor rarely survives that comparison unchanged.
How do the five controls apply to your wireless network?
Firewalls and boundary devices
Every in-scope device must sit behind a correctly configured firewall or boundary device. For wireless, the requirements raise three specific points:
- Default passwords. The router or firewall that carries your staff WiFi traffic needs its default administrative password changed to a strong one.
- Admin interface exposure. The firewall's administrative interface must not be reachable from the internet. The exception is a documented business need, protected by MFA or an IP allow list.
- Inbound rules. Each inbound rule needs a documented business reason. Remove the rule when that need ends.
Wireless kit commonly fails on the second point. A port forward set up years ago for remote support can leave an access point's local web admin page reachable from the internet.
The control also covers devices on untrusted networks. Staff laptops used on public hotspots, including hotel guest networks, need their software firewall switched on.
Guest WiFi is not itself a boundary device. The requirements let you exclude a sub-set of your network from scope, provided a firewall or VLAN segregates it from in-scope systems. A VLAN (virtual LAN) is a logically separate network running over shared switches and access points. Put guest and staff traffic on separate VLANs, block routing between them, and describe that separation in your scope statement.
Secure configuration
This control asks you to remove what you do not need and change what ships insecure. On the wireless side, that means:
- Changing default administrator credentials on every access point, controller and management appliance.
- Removing or disabling unused local accounts, including vendor support accounts you never activated.
- Disabling management services you do not use, such as unencrypted HTTP or Telnet access to access points.
- Applying the requirement's password rules to every credential that unlocks network equipment.
The password rules are specific. Use MFA, or a minimum of 12 characters, or a minimum of eight characters with an automatic block on common passwords. Protect against brute-force guessing with throttling, or lock out after no more than 10 failed attempts.
If you keep a WPA2-PSK (pre-shared key) network for legacy devices, we recommend applying the same minimums to its passphrase. A shared passphrase is still a password, and it opens a route onto your network.
User access control
This control is where most staff WiFi designs struggle. It requires that:
- Every person has their own account, approved before it is issued.
- Accounts are removed or disabled when no longer needed, including when someone leaves.
- Administrative accounts are used only for administration, kept separate from day-to-day accounts, and never used for email or browsing.
- MFA is enforced on cloud services wherever the service offers it.
Your cloud wireless dashboard is a cloud service. If your access points are managed in the Cisco Meraki dashboard, Juniper Mist or a similar platform, every admin login needs MFA.
The staff SSID itself is the harder question, and we answer it in full in the WPA2-PSK section below.
Malware protection
Every in-scope desktop, laptop, tablet and phone needs anti-malware software or application allow-listing. The control has no direct wireless setting. It reaches your staff WiFi through the devices it admits.
If personal phones join your staff SSID and open company email, each phone must meet this control. You must be able to show that it does.
Security update management
Firmware counts as software. Access points, controllers and wireless-capable routers must run vendor-supported firmware. High and critical updates must be installed within 14 days of release. High and critical means a CVSS v3 score of 7 or above, or any fix where the vendor gives no severity.
Access points that have reached end of support fail this control outright. You must remove them or segregate them out of scope. Check the end-of-life notice for every model on your estate before you submit. A retail or hotel estate built up over years often hides one or two discontinued models.
Which questionnaire items sink a poorly configured staff WiFi?
The Willow questions are grouped by control rather than by technology. These are the wireless-relevant items we see catch IT teams, worded as topics rather than question numbers:
- Scope description. Does it name your wireless equipment and explain how guest traffic is segregated?
- Default credentials. Have you changed the defaults on every access point, controller and router?
- Admin interface exposure. Can anyone reach a wireless management page from the internet?
- MFA on management. Is MFA enforced on your cloud wireless dashboard for every admin account?
- Admin account separation. Do named admin accounts manage the WiFi, rather than a shared "admin" login?
- Leaver process. When someone leaves, does their WiFi access end, or does a shared key stay in their pocket?
- Password policy. Does your stated policy cover network equipment and any PSK passphrase?
- Firmware currency. Is every access point on supported firmware, patched within 14 days for high and critical fixes?
- BYOD inventory. Have you listed the personal devices on your staff SSID that reach organisational data?
- Untrusted networks. Do staff laptops keep their software firewall on when they join guest or public WiFi?
The table below maps each control to the wireless failure an assessor will find and the configuration that answers it.
| Control | Wireless question area | Fails the assessment | Passes the assessment |
|---|---|---|---|
| Firewalls | Admin interface exposure | Access point web admin reachable through a port forward | Management reachable only internally, or behind MFA or an IP allow list |
| Firewalls | Guest separation | Guest and staff on one flat network | Separate VLANs with no routing between guest and staff |
| Secure configuration | Default credentials | Factory admin password on controller or access points | Unique credentials meeting the 12-character rule, defaults removed |
| User access control | Individual accounts | One WPA2-PSK key shared by all staff and contractors | 802.1X or iPSK, one credential per person or device |
| User access control | Management plane | Cloud dashboard login without MFA | MFA enforced for every admin account |
| Malware protection | BYOD | Unmanaged personal phones reading company email on staff WiFi | Personal phones moved to guest WiFi, or listed and meeting the control |
| Security updates | Firmware | End-of-life access points still in service | Supported models, high and critical patches within 14 days |
Does WPA2-PSK pass user access control?
Not cleanly. The requirements do not ban WPA2-PSK by name. They do require individual accounts and the removal of access when someone leaves. A single shared key gives you neither. If a leaver knows the key, your only remedy is to change it on every device that uses it.
Two alternatives give you per-person control.
802.1X is the IEEE standard for port-based network access control. On WiFi, it runs as WPA2-Enterprise or WPA3-Enterprise. Each person or device authenticates to a RADIUS server, the service that checks credentials and grants network access. The exchange uses an EAP method such as EAP-TLS (certificate-based), EAP-TTLS or PEAP (both tunnel credentials inside TLS).
iPSK (identity pre-shared key, called PPSK or private PSK by some vendors) issues a unique key per person or device on a single SSID. Devices that only support a passphrase still connect, and you can revoke each key individually.
| Staff SSID method | Per-person revocation | Fit with user access control | Handles BYOD | Device support | Who it suits |
|---|---|---|---|---|---|
| WPA2-PSK, one shared key | No, rotate the key on every device | Weak, no individual accounts | Poorly, no way to tell personal from corporate devices | All WiFi devices | Legacy-only networks, segregated out of scope |
| iPSK or PPSK | Yes, per key | Good, one key per person or device | Yes, each personal device gets its own key | All devices that accept a passphrase | Mixed estates with scanners, tills and IoT that cannot run 802.1X |
| 802.1X with EAP-TTLS or PEAP | Yes, per account | Strong, tied to individual accounts | Yes, with identity on every session | Modern laptops, phones and tablets | Office and back-of-house staff with directory accounts |
| 802.1X with EAP-TLS certificates | Yes, per certificate | Strongest, no passwords to steal | Managed devices only, unless you issue BYOD certificates | Devices you can enrol with certificates | Managed corporate fleets |
If you must keep a PSK network, segregate it on its own VLAN. Restrict it to devices that cannot do better, document why it exists, and rotate the passphrase when anyone who knows it leaves.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.
How does Cyber Essentials Plus probe your staff WiFi?
Cyber Essentials Plus uses the same requirements as the basic certification. An assessor then verifies them with hands-on tests. The Plus audit must be completed within three months of your basic certificate.
The test specification covers:
- An external vulnerability scan of your internet-facing IP addresses.
- An internal vulnerability scan of a sample of end-user devices.
- Checks that sampled devices are patched and run malware protection, using test files delivered by email and browser.
- A check that MFA is enforced on in-scope cloud services.
- A check that admin accounts are separate from day-to-day accounts.
The specification contains no dedicated over-the-air wireless attack test. Your WiFi surfaces in four other ways.
- The external scan finds any access point, controller or router management page exposed to the internet. Unpatched firmware with a known vulnerability shows up as a high or critical finding.
- The device sample includes laptops and phones that connect over your staff SSID, BYOD among them if they are in scope.
- The MFA check can include your cloud wireless dashboard if you listed it as an in-scope service.
- The account check can expose shared admin logins on wireless management.
Fix exposure before the assessor arrives. A management page that a port scan can find will become a finding.
Where does Purple sit alongside your existing wireless network?
Purple is a hardware-agnostic cloud overlay. Purple Staff WiFi runs on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet, with no rip and replace required.
On your existing controller, the staff network becomes a WPA2-Enterprise (802.1X) SSID with no captive portal. A captive portal is the web login page guests normally see. Authentication goes to Purple's cloud RADIUS over RadSec, which wraps RADIUS traffic in TLS. A certificate you install in your controller secures that link. Two Purple RADIUS servers are configured for redundancy. Passpoint (Hotspot 2.0, the standard that lets devices join automatically using stored credentials) runs with EAP-TTLS, so enrolled devices connect without a prompt.
Our support articles hold the exact settings for each platform:
For the wider vendor picture, read How to Configure WPA2-Enterprise on Common Access Point Platforms (Cisco, Aruba, Ubiquiti).
Here is how this maps to the questionnaire:
- User access control. Every session carries an individual identity, not a shared key.
- Leavers. Joiners, movers, leavers (JML) processes in Microsoft Entra ID, Okta or Google Workspace drive WiFi access, so disabling an account ends that person's access.
- Secure configuration. RADIUS credentials travel inside TLS rather than across the internet in the clear.
- Supplier assurance. Purple holds ISO 27001 certification and is GDPR compliant, which helps when your assessor asks about third-party services.
Purple handled 440 million logins in 2024 across 80,000+ live venues, according to Purple's own platform data.
Two worked scenarios
A 200-room hotel with one shared staff key
Situation. A 200-room hotel ran its 85 staff on a single WPA2-PSK network. The key had not changed since opening four years earlier. Contractors and agency housekeeping staff knew it. A port forward from the original installer left the controller's web admin reachable from the internet, still on its factory password.
What was done. The IT manager closed the port forward and changed every default credential. They enforced MFA on the cloud dashboard and gave each administrator a named account. Staff moved to an 802.1X SSID through Purple, with access tied to the hotel's directory. Housekeeping tablets that could not run 802.1X moved to a segregated VLAN with their own passphrase. Guest WiFi stayed on a separate VLAN with no route to staff systems.
Outcome. Shared keys on the staff network fell from one to zero. Removing a leaver went from re-keying more than 120 devices to disabling one directory account. The questionnaire went in with no non-compliant wireless answers. Hotels with high staff turnover feel this change most, because every leaver used to mean a re-key.
A 40-store retail chain preparing for Plus
Situation. A 40-store Retail chain held basic Cyber Essentials and booked its Plus assessment. Around 300 personal phones used the staff SSID, mostly for browsing on breaks. A pre-assessment external scan found remote management enabled on store routers, with a firmware version carrying a high-severity advisory.
What was done. The team disabled remote management and applied the patched firmware within the 14-day window. They then moved personal phones to the guest network, which was segregated and outside scope. Only store managers' phones, which read company email, stayed on staff access, each with its own iPSK key and device management enrolment. Handheld scanners received per-device iPSK keys.
Outcome. In-scope BYOD devices fell from about 300 to 45. The re-run external scan returned zero high or critical findings on wireless or router equipment. The Plus audit closed inside the three-month window.
What are the limits you should know about?
Cyber Essentials is not a wireless security standard. It sets a baseline against internet-borne attacks. It does not test rogue access points, radio-frequency attacks or wireless intrusion detection. Passing does not mean your WiFi is fully hardened.
Shared-tenant offices need more than one staff SSID. Where several organisations share a building, a single staff network cannot keep each tenant's devices separate. iPSK places each tenant's devices on their own segment over one SSID, which is how Purple Multi-Tenant WiFi approaches shared buildings. Public-sector hubs, council offices and coworking floors often fall into this category.
Legacy devices limit your options. Tills, scanners and some medical or building-management kit cannot run 802.1X. Plan for iPSK or a segregated PSK network rather than forcing them onto Enterprise authentication. The same pattern applies in Healthcare settings, where clinical devices often share the radio estate with staff.
Guest networks can still matter. Segregation keeps guest WiFi out of your Cyber Essentials scope. It does not remove your GDPR obligations for any guest data you collect. If you run Purple Guest WiFi, the SecurePass add-on is our guest-side answer when your boundary discussion extends to guest traffic.
What should you do next?
- Pull your scope statement and list every access point, controller and router model, with firmware version and support status.
- Run an external port scan of your own public IPs before an assessor does.
- Enforce MFA and named accounts on your wireless management dashboard.
- Decide which staff SSID method in the comparison table fits each device class.
- Move personal devices that do not need organisational data to your guest network.
See also: Purple Staff WiFi, for identity-based employee access on your existing hardware. Purple SecurePass, for the guest-side answer to the boundary-device question. Purple Multi-Tenant WiFi, for iPSK in shared-tenant offices where one staff SSID will not work.
Frequently asked questions
Does Purple Staff WiFi work with the access points we already own?
Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You configure a WPA2-Enterprise SSID on your existing controller and point authentication at Purple's cloud RADIUS over RadSec. Our support articles give the exact settings per platform, so you change configuration rather than replace hardware before your assessment.
Do we have to remove WPA2-PSK to pass Cyber Essentials?
No, the requirements do not ban WPA2-PSK by name. A single shared key does make your user access control answers hard to defend, because it cannot be removed for one person when they leave. Move staff to 802.1X or iPSK. Keep any remaining PSK network segregated on its own VLAN, restricted to legacy devices and documented, with a passphrase that meets the 12-character rule.
Is our guest WiFi in scope for Cyber Essentials?
Not if you segregate it properly. The NCSC requirements let you exclude a sub-set of your network from scope when a firewall or VLAN separates it from in-scope systems. Put guest traffic on its own VLAN, block routing to staff networks and corporate systems, and describe that separation in your scope statement. Staff laptops that join the guest network still need their software firewall enabled.
Are staff personal phones on the staff SSID in scope?
Yes, if they access organisational data or services such as company email. Since version 3.0 of the requirements, BYOD devices that reach organisational data are in scope and must meet all five controls. Phones used only for MFA apps, calls and texts are excluded. Moving personal devices that only need internet access onto your segregated guest network is the quickest way to reduce scope.
Does Cyber Essentials Plus test our wireless network directly?
No, the Plus test specification has no dedicated over-the-air wireless test. Your WiFi is still examined indirectly. The external scan finds exposed access point or controller management pages and vulnerable firmware. The device sample includes laptops and phones on your staff SSID. The MFA check can cover your cloud wireless dashboard. Fix management exposure and firmware before booking the assessor.
How much work is it to move staff WiFi to 802.1X before our assessment?
The controller side is one SSID change on your existing hardware. You add Enterprise security, Purple's RADIUS servers and a RadSec certificate, as set out in our per-vendor support articles. Most of the effort sits in device onboarding: enrolling laptops and phones and deciding which legacy devices need iPSK instead. Plan that inventory first, because it also answers the BYOD questions.
Is Purple secure and compliant?
Yes. Purple holds ISO 27001 certification and is GDPR compliant. The platform was founded in 2012 and maintains a 99.999% uptime. When your assessor asks how third-party cloud services handle staff authentication, you can point to these credentials. Purple's platform recorded 440 million logins in 2024 across 80,000+ live venues, serving 350 million users.
Key Definitions
Cyber Essentials
The UK government-backed certification scheme covering five technical controls: firewalls, secure configuration, user access control, malware protection and security update management. The NCSC owns the technical requirements, IASME has delivered the scheme since April 2020, and assessments from 28 April 2025 use the Willow question set aligned to version 3.2 of the requirements.
Your access points, controllers and cloud wireless dashboard are in-scope devices and services, so staff WiFi settings appear inside every control rather than in a separate wireless chapter.
Cyber Essentials Plus
The verified tier of the scheme, using the same NCSC requirements as the basic certificate but tested hands-on by an assessor. The test specification covers an external vulnerability scan, an internal scan of sampled end-user devices, patch and malware checks, MFA checks on cloud services and admin account separation. It must be completed within three months of the basic certificate.
There is no over-the-air wireless test, but the external scan finds exposed wireless management pages and vulnerable firmware, and the device sample includes laptops and phones on your staff SSID.
IEEE 802.1X
The IEEE standard for port-based network access control. On WiFi it runs as WPA2-Enterprise or WPA3-Enterprise, with each person or device authenticating to a RADIUS server through an EAP method such as EAP-TLS, EAP-TTLS or PEAP.
802.1X gives every staff session an individual identity, which answers the individual account and leaver requirements in user access control.
iPSK (identity pre-shared key)
A vendor implementation, also called PPSK or private PSK, that issues a unique passphrase per person or device on a single SSID. The device still uses standard WPA2 personal authentication, while the network maps each key to an identity and can revoke it individually.
Use iPSK for tills, handheld scanners and IoT that cannot run 802.1X, and for shared-tenant buildings where each tenant's devices need their own segment.
WPA2-PSK
WPA2 Personal mode, in which every device on the SSID authenticates with the same pre-shared passphrase. It offers no per-user identity, so revoking one person means changing the key on every device that uses it.
The NCSC requirements do not ban it by name, but a single shared key makes user access control answers hard to defend. Keep any remaining PSK network segregated, documented and rotated when anyone who knows the key leaves.
RADIUS
Remote Authentication Dial-In User Service, defined in RFC 2865, the protocol a WiFi controller uses to send 802.1X credentials to an authentication server, which checks them and grants or refuses network access.
With Purple, your existing controller points staff SSID authentication at Purple's cloud RADIUS, with two servers configured for redundancy.
RadSec
RADIUS over TLS, specified in RFC 6614. It wraps RADIUS traffic in a TLS tunnel authenticated with certificates, so credentials do not cross the internet in the clear.
You install a certificate in your controller to secure the RadSec link to Purple's cloud RADIUS, which supports the secure configuration control.
EAP-TLS
The Extensible Authentication Protocol method defined in RFC 5216, in which client and server authenticate each other with X.509 certificates inside a TLS handshake, with no password exchanged.
EAP-TLS is the strongest staff SSID option for managed corporate fleets, but personal devices need certificates issued before they can use it.
EAP-TTLS and PEAP
Tunnelled EAP methods: EAP-TTLS is specified in RFC 5281, and PEAP is a Microsoft-originated method. Both build a TLS tunnel to the RADIUS server and carry user credentials inside it.
Both suit office and back-of-house staff with directory accounts on modern laptops, phones and tablets. Purple runs Passpoint with EAP-TTLS.
VLAN
A virtual LAN as defined by IEEE 802.1Q: a logically separate network sharing the same switches and access points, with traffic tagged so it can be isolated and routed under firewall policy.
The NCSC requirements let you exclude a sub-set of your network from scope when a firewall or VLAN segregates it, which is how guest WiFi and legacy PSK networks stay out of your assessment.
CVSS v3
The Common Vulnerability Scoring System version 3, maintained by FIRST, which rates vulnerability severity from 0 to 10. Cyber Essentials treats a score of 7 or above as high or critical.
High and critical firmware fixes for access points, controllers and wireless-capable routers must be installed within 14 days, as must any fix where the vendor gives no severity.
Passpoint (Hotspot 2.0)
The WiFi Alliance certification built on IEEE 802.11u that lets devices discover and join a network automatically using stored credentials, with authentication over an EAP method.
Purple runs Passpoint with EAP-TTLS on the staff network, so enrolled devices connect without a prompt or captive portal.
Worked Examples
A 200-room hotel ran its 85 staff on one WPA2-PSK key unchanged for four years and known to contractors and agency housekeeping. An old installer port forward left the controller's web admin reachable from the internet on its factory password. How do you make it pass Cyber Essentials?
The IT manager closed the port forward and changed every default credential, fixing the firewall and secure configuration failures. MFA went onto the cloud dashboard, with a named account for each administrator to meet user access control. Staff moved to an 802.1X SSID through Purple, tied to the hotel's directory, so each session carries an individual identity. Housekeeping tablets that could not run 802.1X moved to a segregated VLAN with their own passphrase. Guest WiFi stayed on a separate VLAN with no route to staff systems. Shared keys fell from one to zero, and removing a leaver went from re-keying more than 120 devices to disabling one directory account. The questionnaire went in with no non-compliant wireless answers.
A 40-store retail chain with basic Cyber Essentials booked its Plus assessment. Around 300 personal phones used the staff SSID, mostly for browsing on breaks. A pre-assessment external scan found remote management enabled on store routers, running firmware with a high-severity advisory. What should the team do before the assessor arrives?
The team disabled remote management and applied the patched firmware inside the 14-day window, removing the external scan findings. Personal phones moved to the guest network, which was segregated and outside scope, because they did not need organisational data. Only store managers' phones, which read company email, stayed on staff access, each with its own iPSK key and device management enrolment. Handheld scanners received per-device iPSK keys, giving individual revocation without 802.1X. In-scope BYOD fell from about 300 devices to 45. The re-run external scan returned zero high or critical findings on wireless or router equipment, and the Plus audit closed inside the three-month window.
Frequently asked questions
Does Purple Staff WiFi work with the access points we already own?
Yes. Purple is hardware-agnostic and runs as a cloud overlay on Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. You configure a WPA2-Enterprise SSID on your existing controller and point authentication at Purple's cloud RADIUS over RadSec. Our support articles give the exact settings per platform, so you change configuration rather than replace hardware before your assessment.
Do we have to remove WPA2-PSK to pass Cyber Essentials?
No, the requirements do not ban WPA2-PSK by name. A single shared key does make your user access control answers hard to defend, because it cannot be removed for one person when they leave. Move staff to 802.1X or iPSK. Keep any remaining PSK network segregated on its own VLAN, restricted to legacy devices and documented, with a passphrase that meets the 12-character rule.
Is our guest WiFi in scope for Cyber Essentials?
Not if you segregate it properly. The NCSC requirements let you exclude a sub-set of your network from scope when a firewall or VLAN separates it from in-scope systems. Put guest traffic on its own VLAN, block routing to staff networks and corporate systems, and describe that separation in your scope statement. Staff laptops that join the guest network still need their software firewall enabled.
Are staff personal phones on the staff SSID in scope?
Yes, if they access organisational data or services such as company email. Since version 3.0 of the requirements, BYOD devices that reach organisational data are in scope and must meet all five controls. Phones used only for MFA apps, calls and texts are excluded. Moving personal devices that only need internet access onto your segregated guest network is the quickest way to reduce scope.
Does Cyber Essentials Plus test our wireless network directly?
No, the Plus test specification has no dedicated over-the-air wireless test. Your WiFi is still examined indirectly. The external scan finds exposed access point or controller management pages and vulnerable firmware. The device sample includes laptops and phones on your staff SSID. The MFA check can cover your cloud wireless dashboard. Fix management exposure and firmware before booking the assessor.
How much work is it to move staff WiFi to 802.1X before our assessment?
The controller side is one SSID change on your existing hardware. You add Enterprise security, Purple's RADIUS servers and a RadSec certificate, as set out in our per-vendor support articles. Most of the effort sits in device onboarding: enrolling laptops and phones and deciding which legacy devices need iPSK instead. Plan that inventory first, because it also answers the BYOD questions.
Is Purple itself Cyber Essentials certified?
Yes. Purple holds Cyber Essentials and ISO 27001 certification, is a certified B Corp, and operates in line with GDPR and CCPA. When your assessor asks how third-party cloud services handle staff authentication, you can point to these certifications. Purple's platform recorded 440 million logins in 2024 across 80,000+ live venues, according to our own data.
Sources
- NCSC Cyber Essentials overview
- IASME Cyber Essentials
- FIRST Common Vulnerability Scoring System (CVSS)
- RFC 2865: Remote Authentication Dial In User Service (RADIUS)
- RFC 6614: Transport Layer Security (TLS) Encryption for RADIUS
- RFC 5216: The EAP-TLS Authentication Protocol
- Purple support: Staff WiFi on Cisco Meraki
Continue reading in this series
Portnox Alternatives: Cloud RADIUS Without the Full NAC
You will be able to decide whether your estate needs full NAC or only cloud RADIUS for WiFi, using a three-question test. You can then compare Portnox, Purple, SecureW2 and JumpCloud on wired enforcement, posture checks, certificates, guest access and three-year running cost, and plan a site-by-site pilot.
HPE Aruba Central presence analytics: setup, exports and limits
You will be able to enable Aruba Central presence analytics per site, calibrate the RSSI threshold and dwell boundaries against a ground-truth count, and export site-level aggregates through the Central REST API. You will also know where native presence analytics stops and when a hardware-agnostic platform layer such as Purple earns its place on your existing Aruba access points.
CIPA compliance: compliance checklist for venue operators
You will be able to decide whether CIPA binds your WiFi, then segment networks, route DNS through Purple Shield and close bypass routes. You will also know what evidence to keep for Form 486 or Form 479 certification. The checklist assigns every requirement an owner, so your next funding year certification has nothing missing.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.