Monitor

Blog › Article

27 August 2026 · Article

Cyber Essentials scope: getting a client estate right

Every requirement in Cyber Essentials applies to everything in scope. Get the scope wrong and every other answer is wrong with it — which is why scope, not patching or passwords, is where so many first attempts come unstuck.

The default: the whole organisation

Cyber Essentials assumes the whole organisation is in scope unless you define a smaller part of it. That's usually the simplest and safest choice, because a whole-organisation certificate is the one customers and contracts expect, and it leaves nothing to argue about.

Within that, the scope covers:

Home workers

Devices used by home workers that access organisational data or services are in scope, whether the organisation or the person owns them. The home router supplied by an internet provider generally isn't: for a device working from home, its own software firewall is what's expected to protect it. That makes the laptop's firewall settings matter more than the office's.

Personally owned devices

A personal phone or laptop that reads work email or opens work files is in scope, and has to meet the same controls as a company device: supported software, updates within fourteen days, a locked screen, malware protection. This is the part of scoping most organisations underestimate, because nobody has a list of which personal devices have work email on them.

There are narrow exceptions, such as a phone used only to receive MFA codes or only for calls and texts. A phone with the work mail app on it is not one of them.

Excluding part of the estate

You can certify a subset of the organisation, but only if it's genuinely separated from everything else — typically by a firewall or network segmentation that stops traffic between the part in scope and the part outside it. Leaving machines off the list isn't exclusion. If an excluded machine can reach the in-scope network, it isn't excluded.

Subset scoping has a cost too: the certificate says what it covers, and a customer reading it may notice that it doesn't cover them.

The scoping mistakes that cause failures

The machines nobody mentioned

The laptop in the drawer, the PC in the warehouse office, the machine a contractor brought in and never took away. If it accesses organisational data, it's in scope, and it is usually the one furthest behind on updates.

The cloud services nobody listed

A department signs up for a new tool and starts putting organisational data in it. It's in scope from that moment, and if it offers MFA and it isn't turned on, that's an automatic fail.

Unsupported software treated as a detail

An old operating system or application in scope can't meet the fourteen-day rule, because there are no more updates to apply. It has to be upgraded, replaced or removed, or moved into a separate subset with no internet access at all.

A scope written once and never revisited

The scope on last year's certificate describes last year's estate. New starters, new sites and new services change it constantly.

For MSPs, scope is a client conversation, not a form field. The client knows which devices touch their data; you know which ones you manage. The gap between those two lists is where assessments fail, and closing it is worth doing before the questionnaire, not after.

A scoping checklist

Quick answers

Are personal devices in scope for Cyber Essentials?

If they access organisational data or services, yes, with narrow exceptions such as phones used only for MFA codes or only for calls and texts.

Are cloud services in scope?

Yes. Cloud services that hold or process organisational data are in scope and can't be excluded.

Can I exclude part of my network?

Yes, if it's genuinely separated from the in-scope part, for example by a firewall that blocks traffic between them.