Cyber Essentials Plus for SaaS Companies: Scoping Product vs Corporate IT
Published 7 July 2026
What CE Plus certifies for a SaaS company
The default and correct scope for a SaaS company is corporate IT: staff laptops, mobiles, corporate M365 or Google Workspace, corporate SaaS (HubSpot, Xero, Slack, GitHub used for internal work). This is what the five CE controls fit and what CE Plus can meaningfully audit.
Why the production platform is usually excluded
- Production runs on cloud infrastructure (AWS, Azure, GCP) that is not "end-user devices".
- Customer data is segregated from corporate data by design.
- Production access is controlled by a separate identity path (SSO with just-in-time roles, SRE tooling).
- Production is normally covered by SOC 2, ISO 27001 or a customer-facing security programme, not CE Plus.
What a good SaaS scope statement looks like
"In-scope: NixInfinity-AI Ltd corporate IT, comprising all staff endpoints, corporate Microsoft 365 tenant, and corporate SaaS applications used by staff for internal operations. Out-of-scope: NixInfinity-AI Ltd production infrastructure hosted on AWS, including customer data planes, deployment pipelines and production identity services, which are governed under a separate security programme." That kind of statement holds up because it is honest about what is being certified.
The evidence pack for the corporate side
- MFA enforced across every corporate SaaS, including GitHub for admin operations that are not production deploys.
- Intune or equivalent MDM on staff laptops.
- Corporate M365 Conditional Access blocking legacy auth.
- Admin separation for corporate M365 global admins.
- Joiners/leavers process across corporate identity and every SaaS.
Where SaaS companies trip up
- Staff laptops used for both corporate work and production deploys – the laptop is now touching production and pulls it into scope.
- GitHub organisation used for both marketing site and product source – MFA and access are audited across the whole org.
- Personal AWS accounts left in the corporate identity provider "just in case".
- The engineering team's local dev environments running unpatched OS versions.
When customers ask for CE Plus on production
Sometimes a large customer asks for CE Plus covering the production platform. You can do it, but it is rarely the right fit – SOC 2 Type II or ISO 27001 will serve them better. If you must, the scope becomes the corporate estate plus the operational endpoints (SRE laptops, jump boxes, admin bastions). It does not become the AWS control plane.
For wider scope guidance see Cyber Essentials for SaaS companies(CE version) and CE Plus for Microsoft 365for the corporate M365 evidence pack.
