If Your VDI Runs on Hypervisors, Are the Hypervisors In Scope?
Published 10 August 2026
Why the layer underneath matters
A compromised hypervisor compromises every VDI workload above it. CE treats hypervisors as in-scope infrastructure for any organisation that operates them. Excluding them on the basis that they are "underneath" the user-facing service is a common scope error and one that assessors are increasingly explicit about under Danzell scoping rules.
What is in scope at the hypervisor layer
- The hypervisor itself (ESXi, Hyper-V, KVM, AHV, Nutanix, Proxmox)
- The management plane – vCenter, SCVMM, Prism, Proxmox PVE UI
- Administrator accounts with access to the management plane
- Administrator endpoints used to reach those consoles
- Out-of-band management (iLO, iDRAC, BMC) where accessible
The CE controls applied to hypervisors
- Patching: high/critical CVEs within 14 days. Hypervisor patches often require rolling maintenance windows – plan accordingly.
- Secure configuration: no default credentials, lockdown mode where supported, hardened build standard documented.
- Access control: MFA on the management plane, separation between hypervisor admin accounts and day-to-day accounts, leavers process for engineers.
- Malware protection: for management servers running standard operating systems (vCenter on Windows/Linux, SCVMM hosts, etc.).
- Firewalls: network segmentation around the management plane; ideally a separate management VLAN.
Cloud hypervisors and managed control planes
If your VDI runs on AWS, Azure or GCP, the cloud provider owns the underlying hypervisor – it is out of your scope under shared responsibility. But the tenant control plane you use to manage your VMs (Azure portal, AWS console) is in scope: MFA, admin accounts and audit logging all apply.
Shared responsibility – who does what
| Layer | Self-hosted VDI | Cloud-hosted VDI |
|---|---|---|
| Hardware | You | Cloud provider |
| Hypervisor | You (in scope) | Cloud provider |
| Management plane | You (in scope) | You (in scope) |
| Server OS | You | You |
| VDI software | You | You |
Common scoping mistakes at this layer
- Forgetting iLO/iDRAC – they are admin endpoints
- Excluding "infrastructure" hosts that run management services
- Treating hyperconverged storage controllers as out of scope
- Not having MFA on the vCenter / Prism / Azure Stack HCI portal
- Patch cadence on hypervisors slipping past the 14-day rule
If you provide VDI commercially, this layer is a CE Plus testing focus – see CE Plus in virtualised and cloud environments.
