Can a VDI Service Be Cyber Essentials Certified? Scope Explained
Published 4 August 2026
The "product is certified" myth
Cyber Essentials is awarded to a legal entity for a defined scope of IT. The scheme has no concept of a "Cyber Essentials approved product". When a VDI vendor says "our VDI is Cyber Essentials certified", what they actually mean (or should mean) is that the company running the VDI platform is certified for the infrastructure that delivers it.
The distinction matters because buyers reading "VDI service is certified" assume their own use of it is also certified. It is not. See our companion piece on why a supplier certificate does not cover customers.
What can legitimately be in scope for a VDI provider
- VDI infrastructure (broker, gateway, session hosts, image pipeline)
- Hypervisors and management consoles hosting the VDI estate
- Server operating systems running the VDI workloads
- Hosted network and segmentation between tenants
- Administrator endpoints used to manage the platform
- Administrator and privileged accounts (with MFA)
- Patching, secure configuration, malware protection for all of the above
Bad scope vs good scope examples
Bad scope: "Our VDI service and all users are Cyber Essentials certified."
This is meaningless – it implies every customer tenant and every end-user device is in scope, which the provider cannot evidence.
Good scope: "In scope: the VDI infrastructure, hypervisors, server operating systems, hosted network, administrator endpoints and administrator accounts operated by [Provider Ltd]. Out of scope: customer-owned end-user devices and customer-owned administrator accounts."
That tells a procurement team exactly what assurance they can rely on – and what they still need to certify themselves. For the formula behind writing scope statements like this, see How to write a Cyber Essentials scope statement for hosted services.
Where buyer responsibility starts
The provider's certificate does not cover:
- The thin client, laptop or BYOD device the end user logs in from
- The customer's identity provider (unless explicitly in scope)
- Customer-side data, files and applications
- The customer's own administrator accounts
Anyone using a hosted VDI to access company data still needs to scope and certify their own endpoints. See our hosted desktops and end-user devices guide.
A short readiness checklist for VDI providers
- Write a precise scope statement – what is in, what is out
- Inventory every hypervisor, broker, gateway and management server
- Confirm every administrator account uses MFA
- Confirm patch cadence meets the 14-day rule for high/critical CVEs
- Document hardened build images for both servers and VDI desktops
- Make sure marketing language matches what the certificate actually covers
If you offer VDI commercially, the longer-term move is full MSP/VDI provider readiness – and ultimately Cyber Assurance or ISO 27001 to evidence operational maturity.
