Skip to main content
    NixInfinity-AI
    Cloud Scope

    Cyber Essentials Cloud Services Scope Guide

    Published 30 April 2026

    What counts as an in-scope cloud service

    Any cloud service that stores or processes data on behalf of your organisation. Personal accounts (a director's personal Gmail) are out of scope. Anything used for organisational work is in scope.

    The IaaS / PaaS / SaaS responsibility split

    SaaS (Microsoft 365, Google Workspace, Salesforce, Xero)

    You are responsible for: account management, MFA, password policy, role-based access, data sharing settings. The provider handles infrastructure security and patching.

    PaaS (Azure App Service, AWS Elastic Beanstalk, Heroku)

    You are responsible for: account management, MFA, application configuration, data, and any libraries or runtime versions you control.

    IaaS (AWS EC2, Azure VMs, GCP Compute Engine)

    You are responsible for everything from the operating system upwards: OS patching, hardening, firewalls, account management, MFA, anti-malware, monitoring.

    Common in-scope SaaS apps that get missed

    • Xero, QuickBooks, Sage
    • HubSpot, Salesforce, Pipedrive
    • Slack, Teams, Zoom
    • Dropbox, OneDrive, Google Drive, Box
    • Jira, Confluence, Asana, Monday
    • GitHub, GitLab, Bitbucket (for organisational repos)

    Cloud accounts and MFA

    Under the 2026 Danzell standard, MFA must be enforced on every user account on every in-scope cloud service – not just admins. See MFA requirements.

    Microsoft 365 and Google Workspace specifics

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions