How to Write a Clear Cyber Essentials Scope Statement for Hosted Services
Published 20 August 2026
The five-part formula
- Systems – name them, do not gesture at them
- Hosting environment / network – where they run
- Administrators – who operates them
- Admin endpoints – how they are managed
- Explicit exclusions – what the certificate does not cover
VDI provider example
"In scope: the VDI infrastructure (broker, gateway, image management, profile services) and hypervisors hosted in our London data centre, administered by the Provider Ltd platform engineering team, accessed through managed admin endpoints. Excluded: customer-owned end-user devices, customer identity providers and customer administrator accounts."
SaaS example
"In scope: the production SaaS application and its build/deployment pipeline hosted in AWS eu-west-2 (compute, storage, network), administered by the SaaSCo platform team, accessed through managed engineer laptops, plus all SaaSCo Ltd staff laptops with access to corporate or production systems. Excluded: customer-side configuration and customer data residing in customer-administered systems."
Cloud hosting example
"In scope: the Azure tenant management plane and production subscriptions operated by HostCo Ltd, administered by the HostCo cloud platform team, accessed through managed admin endpoints. Excluded: customer-owned subscriptions, customer identities federated into the tenant, and customer-managed workloads."
MSP example
"In scope: the hosted desktop infrastructure and supporting RMM/PSA platforms operated by MSP Ltd, administered by MSP Ltd engineers, accessed through managed admin endpoints and jump servers. Excluded: customer-owned endpoints, customer-side accounts and customer data."
What good scope statements never do
- Use the word "approved" – the scheme certifies organisations, not products
- Imply coverage of "all customers" or "all users"
- Describe the scope as "our IT environment" without naming it
- Leave out the exclusions
Five questions to ask before submitting
- Could a procurement team work out exactly what is certified from this sentence?
- Could a customer realistically infer that their own environment is covered? (If yes, rewrite.)
- Is every named system actually in scope, with evidence?
- Are the exclusions complete and specific?
- Does the wording match your marketing copy?
Where scope statements appear
- On the certificate itself (the binding text)
- In tender responses, alongside the certificate PDF
- In contract schedules
- On the trust / security page of your website (matching the certificate exactly)
For the kinds of wording to avoid, see bad vs good scope statements.
