Skip to main content
    NixInfinity-AI
    Scoping Guide

    Cyber Essentials Scope: Devices and Cloud Services

    Published 1 June 2026

    The scoping principle: "all or a defined sub-set"

    Cyber Essentials must cover either the whole organisation or a defined sub-set that is logically and physically separated from the rest. The sub-set option is useful for large groups, multi-brand organisations and acquisitions, but it has strict requirements.

    If you scope a sub-set, the certificate states that sub-set explicitly. You cannot certify "the head office" if head office staff log into the same Microsoft 365 tenant as the rest of the group.

    Devices in scope

    Any device that meets any of these criteria is in scope:

    • Connects to your organisation's data
    • Connects to cloud services in scope
    • Can access organisational email or business apps
    • Stores organisational data, even temporarily

    That includes:

    • Laptops and desktops (Windows, macOS, Linux, ChromeOS)
    • Mobile phones and tablets used for work email
    • Servers in offices (on-premise) and shared NAS devices
    • BYOD devices used for any of the above
    • Meeting-room PCs, kiosks, warehouse handhelds

    What's NOT in scope

    • Devices used purely for personal browsing with no access to org data
    • IoT devices that don't process organisational data (smart printers, building sensors)
    • Test/development environments physically and logically segregated from production data

    Cloud services in scope

    Every cloud service that holds organisational data or hosts business operations is in scope. Common examples:

    • Microsoft 365, Google Workspace
    • AWS, Azure, GCP (production environments)
    • Salesforce, HubSpot, Pipedrive
    • Xero, QuickBooks, Sage
    • Slack, Microsoft Teams, Zoom (where business data is shared)
    • GitHub, GitLab, Bitbucket
    • Dropbox, Box, OneDrive, Google Drive

    For each in-scope cloud service you must demonstrate MFA, account inventory, admin controls and a leavers process.

    BYOD: the messy bit

    Personal devices used to access work email or business apps are in scope. You don't need to install MDM, but you must apply the relevant CE controls – chiefly MFA on the cloud account, supported OS, and a documented BYOD policy. See our BYOD article (live from 22 June 2026).

    Home workers and home routers

    A home worker's home router counts as a "boundary firewall" for the work device. The rules are simple: default admin password changed, no unrequested inbound services. Software firewalls on the device itself cover the rest.

    The sub-set scoping rules

    If you scope a defined sub-set rather than the whole organisation, you must demonstrate:

    • Logical segregation: the sub-set has its own user directory or tenant, separate from out-of-scope users
    • Network segregation: in-scope devices cannot freely access out-of-scope networks
    • Data segregation: in-scope data is held only on in-scope systems
    • Clear naming: the certificate names the sub-set precisely (e.g. "ACME UK Consumer Division")

    Most SMEs scope the whole organisation. Sub-setting is most useful for groups acquiring smaller companies that need certification fast.

    Common scoping mistakes

    1. Forgetting BYOD. "We don't have BYOD" but staff check work email on their phones – that's BYOD.
    2. Forgetting shadow-sm SaaS. The marketing team's Mailchimp account is in scope.
    3. Excluding "test" environments that hold real data. If it has a copy of production data, it's in scope.
    4. Sub-setting that doesn't actually segregate. Putting "head office only" on the cert when head office staff use the same M365 tenant as everyone else.
    5. Forgetting on-premise servers. The office NAS, the file server, the print server – all in scope if they hold business data.

    How to scope cleanly in 30 minutes

    1. List every cloud service the organisation pays for or relies on
    2. List every device type (laptops, mobiles, BYOD, servers)
    3. Mark anything that touches organisational data – that's in scope
    4. For sub-set: prove segregation in writing before you submit
    5. Get the assessor to confirm scope in pre-check before you commit

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions