Skip to main content
    NixInfinity-AI
    Danzell 2026

    Danzell Scoping Rule Changes: What Is Now In-Scope

    Published 30 June 2026

    The default: whole organisation

    IASME and the NCSC continue to prefer whole-organisation scope. A whole-organisation certificate is what unlocks the free £25,000 cyber insuranceand the strongest tender position.

    Sub-set scope under Danzell

    You can still certify a sub-set – for example a single product team or a regulated division. Danzell requires:

    • A clear network or identity boundary, not just an org-chart line.
    • No shared user accounts spanning the boundary.
    • No shared infrastructure that exposes the in-scope set to the excluded one.
    • The certificate explicitly states the sub-set scope.

    Home workers

    Home worker devices that access organisational data are in scope. Routers supplied by the ISP are out of scope for the boundary firewall control as long as the device's host firewall is enabled and configured. Danzell makes the wording on this clearer – do not assume "home router exclusion" means home workers are exempt.

    BYOD

    BYOD is in scope when the device accesses email, files or business apps. Mobile devices used only for MFA prompts remain out of scope. See our BYOD guide for the practical options.

    Cloud services

    Every cloud service that holds organisational data or authenticates users is in scope. Danzell sharpens the responsibility split between IaaS, PaaS and SaaS – see our Danzell cloud rules guide.

    How to evidence scope correctly

    • A short scope statement naming the legal entity, sites, networks and cloud tenants.
    • A device inventory aligned to the scope.
    • A list of in-scope cloud services with their service model.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions