Skip to main content
    NixInfinity-AI
    VDI Scope

    Can a VDI Service Be Cyber Essentials Certified? Scope Explained

    Published 4 August 2026

    The "product is certified" myth

    Cyber Essentials is awarded to a legal entity for a defined scope of IT. The scheme has no concept of a "Cyber Essentials approved product". When a VDI vendor says "our VDI is Cyber Essentials certified", what they actually mean (or should mean) is that the company running the VDI platform is certified for the infrastructure that delivers it.

    The distinction matters because buyers reading "VDI service is certified" assume their own use of it is also certified. It is not. See our companion piece on why a supplier certificate does not cover customers.

    What can legitimately be in scope for a VDI provider

    • VDI infrastructure (broker, gateway, session hosts, image pipeline)
    • Hypervisors and management consoles hosting the VDI estate
    • Server operating systems running the VDI workloads
    • Hosted network and segmentation between tenants
    • Administrator endpoints used to manage the platform
    • Administrator and privileged accounts (with MFA)
    • Patching, secure configuration, malware protection for all of the above

    Bad scope vs good scope examples

    Bad scope: "Our VDI service and all users are Cyber Essentials certified."

    This is meaningless – it implies every customer tenant and every end-user device is in scope, which the provider cannot evidence.

    Good scope: "In scope: the VDI infrastructure, hypervisors, server operating systems, hosted network, administrator endpoints and administrator accounts operated by [Provider Ltd]. Out of scope: customer-owned end-user devices and customer-owned administrator accounts."

    That tells a procurement team exactly what assurance they can rely on – and what they still need to certify themselves. For the formula behind writing scope statements like this, see How to write a Cyber Essentials scope statement for hosted services.

    Where buyer responsibility starts

    The provider's certificate does not cover:

    • The thin client, laptop or BYOD device the end user logs in from
    • The customer's identity provider (unless explicitly in scope)
    • Customer-side data, files and applications
    • The customer's own administrator accounts

    Anyone using a hosted VDI to access company data still needs to scope and certify their own endpoints. See our hosted desktops and end-user devices guide.

    A short readiness checklist for VDI providers

    1. Write a precise scope statement – what is in, what is out
    2. Inventory every hypervisor, broker, gateway and management server
    3. Confirm every administrator account uses MFA
    4. Confirm patch cadence meets the 14-day rule for high/critical CVEs
    5. Document hardened build images for both servers and VDI desktops
    6. Make sure marketing language matches what the certificate actually covers

    If you offer VDI commercially, the longer-term move is full MSP/VDI provider readiness – and ultimately Cyber Assurance or ISO 27001 to evidence operational maturity.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions