Cyber Essentials Plus for Cloud and Virtualised Environments: What Assessors Need to See
Published 13 August 2026
Product vs platform vs organisation
A frequent misconception is that CE Plus can "certify" a SaaS product or a VDI platform. It does not. It certifies an organisation against a defined scope. The product is incidental – what is tested is the organisation's operation of it. See can a VDI service be certified for the broader point.
What CE Plus tests in cloud / virtual estates
- Cloud management consoles – AWS, Azure, GCP, M365 admin, Google Workspace admin
- Tenant control planes for VDI – Azure Virtual Desktop, Citrix Cloud, Omnissa Horizon Cloud, AWS WorkSpaces
- Virtual machines – server OS gold images and live instances
- Host pools – each distinct build/image sampled
- Administrator endpoints used to reach the above
- Sampled user devices – including thin clients, managed laptops and BYOD
Evidence assessors want to see
- Architecture diagram showing data and admin paths
- Inventory of management planes, host pools and gold images
- List of administrator accounts with MFA evidence
- Patch reports for hypervisors, server OS and VDI agent software
- Hardened build documents for both server OS and VDI desktop builds
- Anti-malware coverage report across in-scope systems
- Sampling plan agreed before testing begins
Where cloud-native estates differ
In cloud-native deployments, the hypervisor and physical hardware are out of scope (cloud provider responsibility), but the management plane and tenant configuration are very much in scope. Misconfigured IAM, weak admin MFA and open management endpoints are common failure modes.
Where virtualised on-prem estates differ
On-prem virtualisation puts the hypervisor and its management plane into your scope. CE Plus expects to see evidence of patching, MFA on the management plane, segmented management network and a documented hardening baseline. See are hypervisors in scope.
Common failure modes in virtual/cloud CE Plus
- Cloud admin accounts without MFA (especially break-glass accounts that were "temporary")
- Server OS images patched, but live instances drifted past 14 days
- Gold image hardened, but live sessions allow user installs
- One host pool sampled when three exist
- Provider certificate referenced as covering customer-side controls
For the sampling errors specifically, see CE Plus VDI sampling mistakes.
