Cyber Essentials for SaaS Companies
Published 15 June 2026
Why SaaS scoping is different
A typical SaaS company runs two distinct environments:
- Corporate: staff laptops, identity provider, email, CRM, code repos, internal tools
- Production: the AWS / GCP / Azure infrastructure that runs the product, holds customer data and is exposed to customers
These environments have different security models, different audit regimes and different risks. Cyber Essentials is best suited to the corporate environment. Production usually sits under SOC 2, ISO 27001 or specific contractual commitments to your customers.
The recommended scope for most SaaS companies
Scope CE around:
- All staff laptops (founders, engineers, sales, support, ops)
- The identity provider for staff (Google Workspace / Microsoft 365 / Okta)
- Internal SaaS tools (Slack, Notion, Linear, Github, Figma, etc.)
- Mobile devices used for work email or Slack
- Office network if you have one
Exclude from CE scope:
- Production AWS/GCP/Azure accounts (covered by SOC 2/ISO 27001)
- Customer data within your product
- Customer-facing infrastructure
- Build pipelines that only deploy to production (caveat below)
The boundary problem: engineer laptops
The trickiest piece is engineer laptops. They sit in the corporate environment but they hold the keys to production. Most assessors are pragmatic: the laptop is in scope (so it must meet CE controls – MFA, supported OS, AV, patching), and you also document that the laptop's privileged access to production is governed separately.
What you must NOT do is claim engineer laptops are out of scope because "they only access production". Engineer laptops are clearly in-scope corporate devices.
How to describe the scope on your submission
Use a clear scope statement on the IASME questionnaire, something like:
"All staff laptops, mobile devices used for corporate communications, the corporate identity provider (Google Workspace), and internal SaaS tools used by [Company]. The customer-facing production environment hosted on AWS is excluded and covered separately under our SOC 2 Type II programme."
This is honest, defensible and accepted by IASME assessors.
What if you don't have SOC 2 yet?
Plenty of early-stage SaaS companies don't yet have SOC 2 or ISO 27001. That's fine – you can still scope CE around the corporate environment and clearly state that production is excluded from this assessment. Your customers will likely ask for a separate statement about production security; CE doesn't have to cover it.
The CE controls applied to a SaaS corporate environment
Firewalls
Software firewalls on every laptop. If you have an office, the office router/firewall too.
Secure configuration
No default admin passwords. Auto-lock on devices. Disk encryption (FileVault / BitLocker).
User access control
SSO via Google Workspace or M365. MFA enforced. Documented leavers process. Admin accounts separate from day-to-day accounts.
Malware protection
macOS built-in protections + Gatekeeper, or Defender on Windows. EDR like SentinelOne / CrowdStrike if you have it (not required, but a strong signal).
Security update management
Auto-update enabled on macOS, Windows Update for Business on Windows. Browser auto-update on. App store apps update automatically.
Common SaaS scoping mistakes
- Trying to bring production into CE scope. CE isn't designed for it – use SOC 2 or ISO 27001.
- Excluding engineer laptops. Engineer laptops are corporate devices and must be in scope.
- Forgetting BYOD. Founders and salespeople often check work Slack on personal phones.
- Forgetting GitHub/GitLab. Source control is a corporate SaaS tool and must be in scope.
Why SaaS companies bother with CE
CE is increasingly required by enterprise customers, UK public sector tenders and cyber insurers. It's a fast, cheap, well-recognised baseline – often the first security cert a SaaS company achieves. See Cyber Essentials for government contracts for procurement detail.
