Blog › Article
Cyber Essentials scope: getting a client estate right
Every requirement in Cyber Essentials applies to everything in scope. Get the scope wrong and every other answer is wrong with it — which is why scope, not patching or passwords, is where so many first attempts come unstuck.
The default: the whole organisation
Cyber Essentials assumes the whole organisation is in scope unless you define a smaller part of it. That's usually the simplest and safest choice, because a whole-organisation certificate is the one customers and contracts expect, and it leaves nothing to argue about.
Within that, the scope covers:
- End-user devices — desktops, laptops, tablets and phones — that access organisational data or services;
- Servers, on premises or virtual, including servers you run on a cloud provider's infrastructure, where you manage the operating system;
- Network devices between in-scope devices and the internet, such as firewalls and routers;
- Cloud services that hold or process organisational data, which can't be excluded;
- Accounts — including accounts used by third parties such as an IT provider.
Home workers
Devices used by home workers that access organisational data or services are in scope, whether the organisation or the person owns them. The home router supplied by an internet provider generally isn't: for a device working from home, its own software firewall is what's expected to protect it. That makes the laptop's firewall settings matter more than the office's.
Personally owned devices
A personal phone or laptop that reads work email or opens work files is in scope, and has to meet the same controls as a company device: supported software, updates within fourteen days, a locked screen, malware protection. This is the part of scoping most organisations underestimate, because nobody has a list of which personal devices have work email on them.
There are narrow exceptions, such as a phone used only to receive MFA codes or only for calls and texts. A phone with the work mail app on it is not one of them.
Excluding part of the estate
You can certify a subset of the organisation, but only if it's genuinely separated from everything else — typically by a firewall or network segmentation that stops traffic between the part in scope and the part outside it. Leaving machines off the list isn't exclusion. If an excluded machine can reach the in-scope network, it isn't excluded.
Subset scoping has a cost too: the certificate says what it covers, and a customer reading it may notice that it doesn't cover them.
The scoping mistakes that cause failures
The machines nobody mentioned
The laptop in the drawer, the PC in the warehouse office, the machine a contractor brought in and never took away. If it accesses organisational data, it's in scope, and it is usually the one furthest behind on updates.
The cloud services nobody listed
A department signs up for a new tool and starts putting organisational data in it. It's in scope from that moment, and if it offers MFA and it isn't turned on, that's an automatic fail.
Unsupported software treated as a detail
An old operating system or application in scope can't meet the fourteen-day rule, because there are no more updates to apply. It has to be upgraded, replaced or removed, or moved into a separate subset with no internet access at all.
A scope written once and never revisited
The scope on last year's certificate describes last year's estate. New starters, new sites and new services change it constantly.
For MSPs, scope is a client conversation, not a form field. The client knows which devices touch their data; you know which ones you manage. The gap between those two lists is where assessments fail, and closing it is worth doing before the questionnaire, not after.
A scoping checklist
- List every device that accesses organisational data, including home and personal devices, not just the ones you manage.
- List every cloud service in use, and who owns each account.
- Note every operating system and application version, and flag anything unsupported.
- Decide whole organisation or subset; if subset, document the separation.
- List every legal entity covered, and describe any exclusion specifically.
- Include third-party and IT-provider accounts.
- Keep the list current, because the scope at renewal must match the estate at renewal.
Quick answers
Are personal devices in scope for Cyber Essentials?
If they access organisational data or services, yes, with narrow exceptions such as phones used only for MFA codes or only for calls and texts.
Are cloud services in scope?
Yes. Cloud services that hold or process organisational data are in scope and can't be excluded.
Can I exclude part of my network?
Yes, if it's genuinely separated from the in-scope part, for example by a firewall that blocks traffic between them.