Skip to main content
    NixInfinity-AI
    VDI Scope

    VDI and Cyber Essentials: What Is Actually In Scope?

    Published 5 August 2026

    VDI splits scope between two organisations

    VDI almost always involves at least two parties: the provider who runs the platform, and the customer whose users log in from their own devices. Cyber Essentials scope follows ownership and operational control, so the same VDI deployment produces two separate scope statements – one for each party.

    What is in scope for the provider

    • VDI infrastructure – connection broker, gateway, image management, profile services
    • Hypervisors hosting the VDI workloads, plus their management plane
    • Server operating systems running the session hosts and management roles
    • Hosted network – internal segmentation, tenant isolation, ingress filtering
    • Administrator endpoints – the laptops/jump boxes used to manage all of the above
    • Privileged accounts used by provider engineers

    What is normally out of scope for the provider

    • Customer-owned end-user devices (laptops, thin clients, BYOD)
    • Customer identity providers (unless the provider operates them)
    • Customer-owned admin accounts or self-service consoles
    • Customer data residing inside the VDI sessions

    Customers should not assume the provider has them covered. Their own CE submission must still describe how they manage the device they use to launch the VDI session – see hosted desktops and end-user devices.

    When end-user devices ARE in the provider's scope

    If the provider also owns or manages the endpoint (e.g. supplies a managed thin client, or runs MDM on the customer's behalf), that device joins the provider's scope. The test is operational control: who patches it, who configures it, who controls the admin account on it.

    The CE controls applied to VDI infrastructure

    1. Firewalls – hosted network boundary plus host firewalls on management servers
    2. Secure configuration – hardened gold images for both server OS and VDI desktops, no default credentials
    3. Access control – MFA on all admin accounts, separation between admin and standard accounts, leavers process for engineers
    4. Malware protection – on session hosts and management servers
    5. Patch management – 14 days for high/critical CVEs across hypervisors, server OS and VDI agent software

    Where providers commonly get scope wrong

    • Excluding hypervisors because "they're underneath the VDI" – they are not; they are in scope
    • Forgetting the management plane (vCenter, AVD control plane, Citrix Cloud admin portal)
    • Implying customer endpoints are covered, when they are not
    • Leaving the build pipeline for gold images out of scope when it touches production

    For the wording side of this problem, read bad vs good scope statements.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions