Hosted Desktops and Cyber Essentials: Are End-User Devices In Scope?
Published 7 August 2026
The common misconception
Many teams adopt hosted desktops or VDI specifically to "thin down" the endpoint, then assume the laptop or thin client no longer matters for Cyber Essentials. The scheme's user-device definition does not work that way. If a device is used to access organisational data – including via a hosted desktop session – that device is an in-scope user device.
Device-by-device guide
Thin clients
In scope. They must run a supported OS, receive patches, have host firewalls (where applicable) and be configured securely. See thin clients and zero clients for Cyber Essentials.
Managed company laptops
In scope. Standard CE controls apply – MFA on the connection, patched OS, malware protection, secure config, account separation.
Personal laptops used as BYOD to access hosted desktops
In scope. BYOD does not become out of scope just because the work happens inside a hosted session. See BYOD rules.
Contractor / third-party devices
In scope if they access your hosted desktop using your accounts. You either (a) lend them a managed device, (b) require them to evidence their own CE-equivalent controls, or (c) ringfence their access so they cannot reach in-scope data.
Zero clients
Treated as user devices but with very narrow firmware/config surface. Still need supported firmware and a documented hardening baseline.
The "what the device touches" test
Ask: does this device send or receive organisational data – credentials, screen pixels of in-scope systems, copy-paste content, file uploads? If yes, it is a user device. The hosted-desktop architecture is irrelevant to that test.
What you can legitimately exclude
- Personal devices that do not access work systems at all
- Devices in a clean room with no network path to the hosted desktop environment
- Devices owned by the hosted desktop provider, used only by their engineers – they sit in the provider's scope, not yours
For the provider/customer split, see customer devices vs provider infrastructure.
Practical implications
- You still need an asset list of every device that connects to the hosted desktop
- BYOD still needs a written policy and MFA on the access account
- You cannot rely on the provider's certificate to cover your endpoints
- CE Plus testing will sample these endpoints, not just the hosted environment
