Bad vs Good Cyber Essentials Scope Statements: VDI, SaaS and Hosted Services
Published 6 August 2026
Why scope wording matters as much as the controls
Cyber Essentials is a scoped certificate. The text on the certificate is the binding description of what the assessor reviewed. Buyers, insurers and tender evaluators read that wording literally. Ambiguous scope creates false confidence, and in regulated sectors it can amount to misrepresentation.
Three failure patterns to avoid
1. Product-as-certified wording
Bad: "Our VDI service is Cyber Essentials approved."
The scheme does not approve products. Only organisations are certified, against a defined scope. See can a VDI service be Cyber Essentials certified.
2. Universal-coverage wording
Bad: "All users and customers of our platform are covered."
A provider cannot certify other organisations' devices, identities or data. Universal claims are unenforceable and unverifiable.
3. Ambiguous boundary wording
Bad: "Our IT environment is certified."
Which IT environment? Production? Corporate? Customer-side? Buyers cannot tell what assurance they are receiving.
Good scope statement examples
VDI provider
"In scope: the VDI infrastructure, hypervisors, hosted network, administrator endpoints and administrator accounts operated by Provider Ltd. Out of scope: customer-owned end-user devices, customer identity providers and customer administrator accounts."
SaaS company
"In scope: the production SaaS platform hosted in AWS eu-west-2 (compute, storage, network), the build and deployment pipeline, the administrator endpoints managed by SaaSCo Ltd and all SaaSCo Ltd staff laptops with access to corporate or production systems."
MSP offering hosted desktops
"In scope: the hosted desktop infrastructure operated by MSP Ltd, the supporting management plane, administrator endpoints and administrator accounts used by MSP engineers. Customer-side endpoints, customer accounts and customer data remain the customer's responsibility."
What good wording always contains
- The systems in scope (named, not implied)
- The hosting environment or network they run on
- Who administers them
- The admin endpoints used to manage them
- Explicit exclusions – what the certificate does not cover
If you want the formula, see how to write a scope statement for hosted services.
The procurement test
Read your scope back as if you were the buyer. Can a procurement team tell, from that sentence alone, exactly which systems are certified? If they would have to ask follow-up questions, the wording is too vague – and the assessor should push back before issuing the certificate.
