Cyber Essentials Cloud Services Scope Guide
Published 30 April 2026
What counts as an in-scope cloud service
Any cloud service that stores or processes data on behalf of your organisation. Personal accounts (a director's personal Gmail) are out of scope. Anything used for organisational work is in scope.
The IaaS / PaaS / SaaS responsibility split
SaaS (Microsoft 365, Google Workspace, Salesforce, Xero)
You are responsible for: account management, MFA, password policy, role-based access, data sharing settings. The provider handles infrastructure security and patching.
PaaS (Azure App Service, AWS Elastic Beanstalk, Heroku)
You are responsible for: account management, MFA, application configuration, data, and any libraries or runtime versions you control.
IaaS (AWS EC2, Azure VMs, GCP Compute Engine)
You are responsible for everything from the operating system upwards: OS patching, hardening, firewalls, account management, MFA, anti-malware, monitoring.
Common in-scope SaaS apps that get missed
- Xero, QuickBooks, Sage
- HubSpot, Salesforce, Pipedrive
- Slack, Teams, Zoom
- Dropbox, OneDrive, Google Drive, Box
- Jira, Confluence, Asana, Monday
- GitHub, GitLab, Bitbucket (for organisational repos)
Cloud accounts and MFA
Under the 2026 Danzell standard, MFA must be enforced on every user account on every in-scope cloud service – not just admins. See MFA requirements.
Microsoft 365 and Google Workspace specifics
- Microsoft 365 checklist – Conditional Access, Defender, Intune.
- Google Workspace checklist – 2SV, context-aware access.
