Skip to main content

Best MDM for NIS2 and BYOD in Europe (2026)

Which MDM actually proves NIS2 article 21 controls on personal phones? We compare 8 platforms on BYOD modes, EU hosting, audit exports and price.

13 min read
Personal smartphone used for work under a NIS2 compliant MDM

If you're in scope for NIS2 and much of your staff reads work mail on a phone they bought themselves, you have an evidence problem before a security problem. No MDM makes you compliant, but the right one turns "we believe devices are encrypted" into a report an auditor accepts. Below: what the directive expects on mobile, why personal devices are the hard part, and how eight platforms handle that combination in Europe in 2026.

What NIS2 actually asks about phones and tablets

Directive (EU) 2022/2555 never uses the word MDM. Not once. It asks for outcomes, and article 21 is where the outcomes live: risk analysis, incident handling, business continuity, supply chain security, vulnerability handling and disclosure, policies on cryptography and encryption, asset management and access control, and multi-factor authentication or continuous authentication. Nothing in that list carves out the devices that happen to fit in a pocket.

Article 23 is the part teams underestimate. A significant incident means an early warning to your national authority within 24 hours, a fuller notification within 72 hours, a final report within a month. A phone vanishes on a Friday night and by Saturday morning you need to say whether it held regulated data, whether storage was encrypted, and whether the wipe landed. Answer that from a spreadsheet and you'll miss the clock.

Penalties run to 10 million euros or 2 % of worldwide turnover for essential entities, and 7 million euros or 1.4 % for important entities. Article 20 makes management bodies personally accountable for approving the measures, which is why these projects suddenly get budget.

Now the part vendors tend to skip. NIS2 is a directive, so what binds you is your country's transposition, not the Brussels text. And those texts landed at very different times. Germany's NIS2 implementation act came into force on 6 December 2025, the BSI registration portal opened on 6 January 2026, and roughly 29,500 German entities fell into scope with no transitional period. France is still finishing the job: the loi résilience was working its way through Parliament through 2026, and in the meantime ANSSI published the Référentiel Cyber France on 17 March 2026 so that the estimated 15,000 French entities could start somewhere. Spain approved its draft cybersecurity governance law in Council of Ministers on 14 January 2025 and still hadn't published it in the BOE when the European Commission referred the country to the Court of Justice on 8 July 2026.

So check your national text and your national authority first. This is an engineering article, not legal advice, and the national rule wins. If scope itself is still fuzzy, our NIS2 glossary entry covers sectors and thresholds.

BYOD under NIS2: proving things about a device you don't own

Here's the bind. Article 21 wants asset management, enforced cryptography and patch management. The GDPR, article 32 in particular, wants security appropriate to the risk without turning the employer into a surveillance operation, and the CNIL's guidance on personal devices is blunt that employer control has to stop at professional data. You can't satisfy one by breaking the other.

The technical answer is separation, and it's been standard for years. Android's work profile arrived with Android 5.0 in 2014: a second Android user on the same hardware, its own storage, its own encryption key, its own copies of apps. Apple's User Enrollment shipped with iOS 13 in 2019 and puts managed accounts and apps on a separate APFS volume, with its own keys.

One 2026 detail that catches teams out: Apple deprecated profile-based User Enrollment and removed it in iOS 18, so account-driven enrollment is the only way to start a new BYOD iPhone. That means Apple Business Manager and a Managed Apple Account per user, ideally federated to Entra ID or Google Workspace. If your MDM can't do account-driven User Enrollment, your iOS BYOD programme is already stuck.

What separation buys you, in audit terms, is a short honest list. You can show the work container was encrypted, a passcode enforced on it, which OS version the device ran, when it last checked in, and that a selective wipe was issued and confirmed. You cannot show an inventory of personal apps, you get no serial number under User Enrollment, and you have no location. Write that list down before the works council asks: it answers most employee objections and it's the evidence an auditor wants. Our BYOD definition covers the trade-offs.

The mechanism producing that evidence is the compliance policy: conditions checked at every device check-in, with consequences when a device drifts. "All devices must be encrypted" is an intention. "412 of 420 encrypted, here are the eight that aren't" is proof.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

What we compared on

Six things, chosen because they're what comes up in a NIS2 readiness review rather than in a feature matrix:

  • BYOD modes. Android work profile and account-driven Apple User Enrollment, both, properly.
  • Compliance and conditional access. Can the platform block access to company resources when a device falls out of policy, or does it only send a notification?
  • Encryption posture. Enforced and, more to the point, reported per device.
  • Audit trail and export. Admin actions logged, device state exportable. Without export you'll be taking screenshots at 2 a.m. mid-incident.
  • EU hosting. Where console data lives, under which law, and whether that's a named option or a sales promise.
  • Published pricing. Not a quality signal, but it tells you how fast you can budget.

The comparison at a glance

PlatformAndroid work profileApple account-driven User EnrollmentEU hostingPublished price
Microsoft IntuneYesYesEU Data Boundary, Microsoft-operatedBundled in Microsoft 365 E3 at 39 USD per user per month; Plan 2 add-on 4 USD
JamfYes (Jamf for Mobile)Yes, strongest implementationGermany region available for Jamf ProQuote only
Ivanti Neurons for MDMYesYesSovereign Edition EU, operated in Germany by a third partyQuote only
SOTI MobiControlYesYesEU cloud regions, confirm in contractQuote only
ScalefusionYesYesNot documented publicly, askFrom 2 USD per device per month, annual, 10 device minimum
HexnodeYesYesNot documented publicly, askFrom 2.2 USD per device per month, 15 device minimum
Samsung Knox ManageYesPartial, check current supportRegional, varies by offerBase Knox Suite plan free for Galaxy customers
AppaloosaYesYesFrance, SecNumCloud-qualified infrastructure3.49 EUR per device per month, 50 device minimum

The eight platforms, one by one

Microsoft Intune

If your identity already lives in Entra ID, Intune is hard to argue against on a NIS2 project. Conditional Access is the reason: device compliance state feeds straight into whether a token gets issued for Exchange, SharePoint or any app behind Entra. That's the cleanest "non-compliant device loses access" story on this list, and it's the one auditors understand fastest because it covers laptops and phones with one policy language.

The catch is licensing and size. Intune Plan 1 sits inside Microsoft 365 E3 at 39 USD per user per month, so most buyers never see a separate line; buy it standalone and the economics change. Data residency runs through the EU Data Boundary, which keeps processing in Europe without making Microsoft a European provider, and for some public buyers that distinction is the whole conversation. Expect real effort on policy design, not an afternoon.

Jamf

Best Apple implementation in the business, and it isn't close. Jamf tracks Apple's management surface release by release, which matters because Apple keeps moving the BYOD goalposts, as the iOS 18 removal of profile-based enrollment showed. Jamf Cloud offers a Germany region for Jamf Pro, so EU residency is a real option, not a roadmap item.

Android is the weak spot. Jamf added Android to Jamf for Mobile, but nobody buys Jamf for a rugged Zebra fleet, and pricing is quote-only so comparison takes a sales cycle.

Ivanti Neurons for MDM

The interesting move here is the Sovereign Edition EU, a cloud instance run in Germany by an independent operator rather than by Ivanti itself, pitched at exactly the buyer who can't accept US-owned control. If you're in an in-scope sector and procurement is asking about extraterritorial law, this is a credible answer that still comes with a mature multi-OS product.

Two caveats. Ivanti's own vulnerability record over recent years will come up in your risk committee, so be ready to discuss it rather than surprised by it. And the product carries enterprise weight: plenty of capability, plenty of configuration.

SOTI MobiControl

SOTI owns the rugged and frontline segment. If you manage handheld scanners, in-vehicle terminals or Android point of sale, its scripting, staging and remote control features are in a different class, and MobiControl supports hardware the cloud-native vendors have never heard of.

But rugged logistics and BYOD knowledge work are different problems, and SOTI is built for the first. If your mobile exposure is 600 employees reading mail on their own iPhones, you'd be paying for depth you won't use. Pricing is quote-only, and confirm your EU hosting region in the contract rather than on a web page.

Scalefusion

Good value and a genuinely pleasant console. Published pricing starts at 2 USD per device per month on annual billing with a 10 device minimum, the easiest platform here to pilot without a procurement cycle. Work profile and User Enrollment are both supported.

For NIS2 specifically, check two things early: where your tenant data sits, because EU hosting isn't documented on the public site, and how far the audit log export goes. An Indian-headquartered vendor can absolutely host in Europe, but you want it written down, not assumed.

Hexnode

Similar position to Scalefusion, slightly more Windows-oriented. Plans start at 2.2 USD per device per month with a 15 device minimum, and the feature-to-price ratio at the Enterprise tier is strong. Support gets consistently good reviews, which counts for more than a feature you'd use twice a year.

Same two questions as above on hosting and audit export. Hexnode's BYOD story also leans on the standard platform primitives rather than adding much of its own, so there's little separating it from Scalefusion on a pure BYOD shortlist.

Samsung Knox Manage

Free is a strong price. The base Knox Suite plan comes at no cost to Galaxy customers, and on a Samsung fleet the platform extras are things no third party can replicate: Knox Platform for Enterprise, E-FOTA for firmware version control, hardware-backed attestation from the chip up.

The limits aren't hidden. Everything interesting is Samsung-only, iOS management is functional rather than leading, and a fleet mixing iPhones, Pixels and Galaxies ends up using Knox Manage as the lowest common denominator. Useful as a second console for a Samsung subfleet, uncomfortable as the single source of NIS2 evidence for a mixed estate.

Appaloosa

We build Appaloosa, so read this with that in mind. The design bet is narrow: manage work apps and work data on iOS, iPadOS, Android, Windows and macOS, and stay out of everything personal. Our personal device management page spells out what IT can and cannot see. There's no location feature on BYOD devices at all, which kills the most common employee objection by removing the capability.

The NIS2-relevant piece is hosting. Appaloosa runs on infrastructure in France that holds the ANSSI SecNumCloud qualification at version 3.2, the version that added immunity criteria to non-European law, and customer data stays in the EU. To be precise about it: the hosting is qualified, Appaloosa itself holds no security certification, and no platform makes your organization NIS2 compliant. What you get is the controls and the export. Pricing is public at 3.49 EUR per device per month on the Business plan.

Where we're thinner than the big four: no Mobile Threat Defense engine of our own, no conditional access layer with Entra's reach, and a 50 device minimum that rules out small pilots. If your requirement list includes deep Windows patch orchestration or rugged device staging, Ivanti and SOTI will serve you better. Full feature detail sits on the mobile device management page, with platform specifics for iOS and iPadOS and Android.

Which one fits your situation

Already deep in Microsoft 365. Intune, almost certainly. You're paying for it, and Conditional Access gives you the access-revocation evidence article 21 pushes you toward. Budget the configuration time honestly.

Apple-only organization. Jamf, hosted in Germany. The Apple BYOD surface changes every September and Jamf keeps up with it better than anyone.

Mixed fleet with rugged or frontline devices. SOTI if the rugged side dominates, Ivanti if you need one console across mobile and desktop with an EU sovereign option. Scalefusion or Hexnode if the budget is tight and the use case is ordinary.

Sovereignty is an explicit requirement. Shortlist Ivanti Sovereign Edition EU and Appaloosa, then ask both the same question: which named offering is qualified or certified, at which version, and until when. Hosting claims without a named offering and a date aren't worth much.

Whichever way you go, what satisfies an auditor isn't the logo on the console. It's a device record you can export on demand: encryption state, OS version, last check-in, wipe confirmation, for every device touching company data. Pick the platform that makes that export boring. Earlier in the process? Our primer on MDM solutions covers the basics.

FAQ

Does NIS2 require an MDM?

No. The directive specifies outcomes, not products, and it never mentions MDM. But article 21 expects access control, cryptography and patch management on the systems your staff actually use, and on a fleet of phones and tablets an MDM is the only practical way to apply those measures and produce evidence that they were applied.

Can I use NIS2 as a reason to manage employees' personal phones?

You can require a managed work container as a condition of accessing company data, which is not the same as managing their phone. Under a work profile or User Enrollment your control stops at the work space, and that boundary keeps the arrangement defensible under the GDPR. Put it in a written BYOD policy, name what IT can and cannot see, and offer a company device to anyone who declines.

Is EU hosting mandatory for NIS2 compliance?

No, and anyone saying otherwise is selling something. NIS2 asks for supply chain risk management, not a data location. EU hosting shortens that conversation, and for French public bodies a SecNumCloud-qualified host may be expected by procurement rules sitting outside NIS2 entirely. Check your sector's requirements, then your national transposition.

See Appaloosa run on your fleet Book a demo

Ready to deploy MDM?

Get started today with unrestricted access to our platform and help from our product experts.

Get Started

Alternatively, contact sales.

Free 14-day trial
Cancel anytime, no questions asked.
Expert Support
Get customized and expert onboarding to get started.