Skip to main content
    NixInfinity-AI
    Infrastructure Scope

    If Your VDI Runs on Hypervisors, Are the Hypervisors In Scope?

    Published 10 August 2026

    Why the layer underneath matters

    A compromised hypervisor compromises every VDI workload above it. CE treats hypervisors as in-scope infrastructure for any organisation that operates them. Excluding them on the basis that they are "underneath" the user-facing service is a common scope error and one that assessors are increasingly explicit about under Danzell scoping rules.

    What is in scope at the hypervisor layer

    • The hypervisor itself (ESXi, Hyper-V, KVM, AHV, Nutanix, Proxmox)
    • The management plane – vCenter, SCVMM, Prism, Proxmox PVE UI
    • Administrator accounts with access to the management plane
    • Administrator endpoints used to reach those consoles
    • Out-of-band management (iLO, iDRAC, BMC) where accessible

    The CE controls applied to hypervisors

    1. Patching: high/critical CVEs within 14 days. Hypervisor patches often require rolling maintenance windows – plan accordingly.
    2. Secure configuration: no default credentials, lockdown mode where supported, hardened build standard documented.
    3. Access control: MFA on the management plane, separation between hypervisor admin accounts and day-to-day accounts, leavers process for engineers.
    4. Malware protection: for management servers running standard operating systems (vCenter on Windows/Linux, SCVMM hosts, etc.).
    5. Firewalls: network segmentation around the management plane; ideally a separate management VLAN.

    Cloud hypervisors and managed control planes

    If your VDI runs on AWS, Azure or GCP, the cloud provider owns the underlying hypervisor – it is out of your scope under shared responsibility. But the tenant control plane you use to manage your VMs (Azure portal, AWS console) is in scope: MFA, admin accounts and audit logging all apply.

    Shared responsibility – who does what

    LayerSelf-hosted VDICloud-hosted VDI
    HardwareYouCloud provider
    HypervisorYou (in scope)Cloud provider
    Management planeYou (in scope)You (in scope)
    Server OSYouYou
    VDI softwareYouYou

    Common scoping mistakes at this layer

    • Forgetting iLO/iDRAC – they are admin endpoints
    • Excluding "infrastructure" hosts that run management services
    • Treating hyperconverged storage controllers as out of scope
    • Not having MFA on the vCenter / Prism / Azure Stack HCI portal
    • Patch cadence on hypervisors slipping past the 14-day rule

    If you provide VDI commercially, this layer is a CE Plus testing focus – see CE Plus in virtualised and cloud environments.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions