Skip to main content
    NixInfinity-AI
    Scope Wording

    Bad vs Good Cyber Essentials Scope Statements: VDI, SaaS and Hosted Services

    Published 6 August 2026

    Why scope wording matters as much as the controls

    Cyber Essentials is a scoped certificate. The text on the certificate is the binding description of what the assessor reviewed. Buyers, insurers and tender evaluators read that wording literally. Ambiguous scope creates false confidence, and in regulated sectors it can amount to misrepresentation.

    Three failure patterns to avoid

    1. Product-as-certified wording

    Bad: "Our VDI service is Cyber Essentials approved."

    The scheme does not approve products. Only organisations are certified, against a defined scope. See can a VDI service be Cyber Essentials certified.

    2. Universal-coverage wording

    Bad: "All users and customers of our platform are covered."

    A provider cannot certify other organisations' devices, identities or data. Universal claims are unenforceable and unverifiable.

    3. Ambiguous boundary wording

    Bad: "Our IT environment is certified."

    Which IT environment? Production? Corporate? Customer-side? Buyers cannot tell what assurance they are receiving.

    Good scope statement examples

    VDI provider

    "In scope: the VDI infrastructure, hypervisors, hosted network, administrator endpoints and administrator accounts operated by Provider Ltd. Out of scope: customer-owned end-user devices, customer identity providers and customer administrator accounts."

    SaaS company

    "In scope: the production SaaS platform hosted in AWS eu-west-2 (compute, storage, network), the build and deployment pipeline, the administrator endpoints managed by SaaSCo Ltd and all SaaSCo Ltd staff laptops with access to corporate or production systems."

    MSP offering hosted desktops

    "In scope: the hosted desktop infrastructure operated by MSP Ltd, the supporting management plane, administrator endpoints and administrator accounts used by MSP engineers. Customer-side endpoints, customer accounts and customer data remain the customer's responsibility."

    What good wording always contains

    • The systems in scope (named, not implied)
    • The hosting environment or network they run on
    • Who administers them
    • The admin endpoints used to manage them
    • Explicit exclusions – what the certificate does not cover

    If you want the formula, see how to write a scope statement for hosted services.

    The procurement test

    Read your scope back as if you were the buyer. Can a procurement team tell, from that sentence alone, exactly which systems are certified? If they would have to ask follow-up questions, the wording is too vague – and the assessor should push back before issuing the certificate.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions