Danzell Scoping Rule Changes: What Is Now In-Scope
Published 30 June 2026
The default: whole organisation
IASME and the NCSC continue to prefer whole-organisation scope. A whole-organisation certificate is what unlocks the free £25,000 cyber insuranceand the strongest tender position.
Sub-set scope under Danzell
You can still certify a sub-set – for example a single product team or a regulated division. Danzell requires:
- A clear network or identity boundary, not just an org-chart line.
- No shared user accounts spanning the boundary.
- No shared infrastructure that exposes the in-scope set to the excluded one.
- The certificate explicitly states the sub-set scope.
Home workers
Home worker devices that access organisational data are in scope. Routers supplied by the ISP are out of scope for the boundary firewall control as long as the device's host firewall is enabled and configured. Danzell makes the wording on this clearer – do not assume "home router exclusion" means home workers are exempt.
BYOD
BYOD is in scope when the device accesses email, files or business apps. Mobile devices used only for MFA prompts remain out of scope. See our BYOD guide for the practical options.
Cloud services
Every cloud service that holds organisational data or authenticates users is in scope. Danzell sharpens the responsibility split between IaaS, PaaS and SaaS – see our Danzell cloud rules guide.
How to evidence scope correctly
- A short scope statement naming the legal entity, sites, networks and cloud tenants.
- A device inventory aligned to the scope.
- A list of in-scope cloud services with their service model.
