top of page

How to Scope Cyber Essentials

Updated: Jun 4



✅ Updated June 2025 — This blog has been revised to align with the Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026), published by the NCSC.


You can download the latest version of the document here: Cyber Essentials Requirements for IT Infrastructure v3.3


What's in Scope for Cyber Essentials?

When planning for Cyber Essentials certification, one of the first and most important decisions your organisation must make is establishing the scope of the assessment. Scoping defines what part of your IT systems and services your certification will cover. It influences everything from technical control implementation through to evidence collection during your assessment.


This blog explains how to think about scoping, what must be included, and how to approach more complex or cloud-heavy environments — including areas we commonly see misunderstood in submissions.


Why Scoping Matters

Scope determines the boundary of what will be assessed against the five Cyber Essentials technical controls. It tells your Certification Body exactly what they are evaluating and gives your organisation clear confidence about where risk has been addressed. Poorly defined scope can lead to unexpected gaps in coverage, additional work during assessment, or even a failed certification attempt.


Clear scoping also helps you:

  • Identify all systems and services that need controls applied

  • Plan remediation or configuration work ahead of assessment

  • Allocate responsibility for cloud services and external infrastructure

  • Manage risk by understanding where unsupported or legacy technology lives


What Must Be Included in Scope

The guiding principle is straightforward: include anything that could introduce risk into your business operations, particularly anything that is internet-connected or that stores or processes organisational data.


The v3.3 Requirements document is explicit on this. The requirements apply to all devices and software in scope which meet any of these conditions:

  • Can accept incoming network connections from internet-connected devices

  • Can establish outbound connections to devices via the internet

  • Control the flow of data between any of the above devices and the internet


A scope that does not include end-user devices is not acceptable.


End-User Devices

All devices that your staff, volunteers, trustees, or contractors use to access organisational systems and data for business purposes are in scope. This includes:

  • Corporate laptops and desktops

  • Mobile phones or tablets used to access organisational email, data, or cloud services

  • Devices used for hybrid or home working


Bring Your Own Device (BYOD) is also in scope if it accesses corporate data or services — with a specific exception for devices used only for native voice calls, native SMS, or MFA applications, which may be excluded.


For schools and educational settings, student-owned devices and those belonging to third-party contractors or MSPs are generally out of scope, but please refer to Table 2 in the v3.3 document or contact us if you are unsure.


Servers, Virtual Machines and Network Infrastructure

Physical and virtual servers hosting business services — whether on-premise or in hosted environments — are in scope. Network devices such as firewalls, routers, switches, Wi-Fi controllers, and VPN concentrators are also included where they govern the flow of traffic to and from your IT infrastructure.


If your organisation provides a router to a home or remote worker, that router is in scope too. ISP-provided routers at home locations are generally out of scope, but the device connecting through them must still have appropriate software firewall controls applied.


Cloud Services — A Critical Area Often Misunderstood

This is one of the areas we most frequently see incomplete in submissions, so we want to be very clear about this.


The v3.3 Requirements document states definitively: "Cloud services cannot be excluded from scope."


If your organisation's data or services are hosted on a cloud service, those services must be included. You remain responsible for ensuring that Cyber Essentials controls are implemented — even if a third party manages or provides the service.


What is a Cloud Service?

The v3.3 document provides a formal definition for the first time:

"A cloud service means an on-demand, scalable service, hosted on shared infrastructure, and accessible via the internet. For the purposes of Cyber Essentials, a cloud service will be accessed via an account (which may be credentials issued by your organisation, or an email address used for business purposes), and will store or process data for your organisation."

This is broader than many applicants realise. It is not limited to Microsoft 365 or Google Workspace.


Cloud Services You Must Include — and Often Don't

We regularly receive submissions listing only Microsoft 365 as a cloud service. In reality, the cloud services in scope will depend on your organisation but are likely to include many of the following:


Productivity & Collaboration

  • Microsoft 365 (including Exchange Online, SharePoint, Teams, OneDrive)

  • Google Workspace (Gmail, Drive, Meet, Docs)


Communication & Messaging

  • WhatsApp Business or WhatsApp used for work communications

  • Slack, Teams (standalone), or other messaging platforms used for business purposes


Finance & Accounting

  • Xero, QuickBooks, Sage, FreeAgent, or similar cloud accounting platforms

  • Payroll platforms such as BrightPay Online or Moorepay


Customer & Sales Management

  • CRM platforms such as Salesforce, HubSpot, Zoho CRM, or similar


Social Media & Marketing

  • LinkedIn company pages and LinkedIn Ads accounts

  • Facebook / Meta Business accounts

  • Instagram Business

  • X (formerly Twitter) business accounts

  • Mailchimp, Klaviyo, or other email marketing platforms


Domain Names, Web Hosting & DNS Management

  • This is an area that is almost always overlooked. If your organisation has a registered domain name or a website, you will have a management portal with your domain registrar (for example GoDaddy, 123-reg, Namecheap, or similar) and potentially a separate hosting control panel. These portals store organisational data — your domain registration details, billing information, and DNS configuration — and if compromised, an attacker could redirect your email or website. They are in scope.

  • Website CMS platforms such as WordPress (hosted), Wix, Squarespace, or Shopify

  • Hosting control panels (cPanel, Plesk, or similar)


File Storage & Sharing

  • Dropbox, Box, or other cloud file storage services


IT Management & Security Tools

  • Cloud-based MDM solutions, antivirus portals, or remote monitoring tools


Other Business Applications

  • Legal practice management software hosted in the cloud

  • Project management tools such as Monday.com, Asana, Trello (where business data is stored)

  • HR platforms such as BambooHR, Breathe, or similar


The test to apply is simple: does this service store or process data for your organisation, and is it accessed via an account? If yes, it is a cloud service and it must be in scope.


What Can Be Excluded from Scope?

Exclusions are permitted, but only where they are:

  1. Clearly defined

  2. Technically segregated from the in-scope estate (via a firewall or VLAN)

  3. Justified to your Certification Body with a valid business reason


Examples of items that may be justifiably excluded include:

  • A guest Wi-Fi network that is fully isolated and has no access to organisational data

  • A development subnet that cannot affect or communicate with the production environment

  • Legacy systems that cannot be secured but are fully isolated

  • A subsidiary of a large multi company organisation may wish to exclude the larger organisation whilst still benefiting from head office support etc. We have scoped this for applicants however this involves additional work not included under the supported service. Please enquire about our consultancy services for more information.


If you use exclusions, you must be able to explain and demonstrate the segregation and justification. Simply saying a system is "out of scope" without technical segregation is not acceptable.


Multi-Site and Complex Environments

For organisations with multiple locations, subsidiaries, or complex network architectures, the same core principle applies — define your scope clearly and consistently. For each part of the estate you must identify:

  • The network boundary

  • The physical location(s)

  • The business unit responsible for managing it


Each part of your infrastructure must map back to the agreed scope. If parts cannot meet Cyber Essentials controls, you must demonstrate isolation and mitigation to justify any exclusion. Our consultancy service has helped many larger organisations benefit from group resources whilst excluding the larger organisation from scope.


Scope and Educational Settings

For schools, colleges, and academy trusts, we may be able to descope student and guest systems but only under very specific conditions. Please contact us for more information. Another common misconception for cloud services is that MFA does not need to be applied for primary or SEN students. MFA must be applied to all user and administrator accounts if its supported. No exceptions however there are ways to apply this. Again, please contact us for more information.


Common Scoping Misunderstandings

Some of the most frequently encountered misconceptions:


"Only devices that store organisational data are in scope." Incorrect. Devices that access organisational data or services are also in scope, even if they do not store it locally.


"We only use Microsoft 365 as a cloud service." Unlikely to be accurate. Review the examples above carefully. Most organisations use many more cloud services than they initially realise.


"Cloud services can be excluded because they're managed by a third party." Not possible under the v3.3 requirements. Cloud services must always be included.


"Personal devices used occasionally aren't in scope." If they access organisational services or data — including cloud services accessed via a personal device — they are in scope unless appropriate access controls and segregation can be demonstrated.


Best Practices for Defining Scope

To ensure scoping goes smoothly:

  1. Start early — before assembling evidence or filling in assessment questions

  2. Document your scope boundary clearly — what is included, what is excluded, and why

  3. Discuss scope with your Certification Body at the outset; we are here to help

  4. Audit your cloud services properly — ask your finance team, operations team, and management what accounts and platforms are used for business purposes

  5. Use the official Requirements for IT Infrastructure v3.3 document as your reference — you can download it here

  6. Maintain an asset inventory — including devices, cloud services, and applications in scope


Final Thoughts

Well-defined scope is the foundation of a successful Cyber Essentials assessment. It ensures you are protecting what matters most in your organisation and helps avoid costly rework or assessment delays. By carefully thinking through your assets, cloud services, networks, and endpoints — and by aligning with the April 2026 v3.3 standard — you can plan for certification with confidence.


My name is Mark Kindred and I'm the Senior Assessor at Get Cyber Certified, an authorised and accredited IASME Certification Body. If you need support defining your scope or preparing for assessment, we can provide guidance tailored to your organisation's size and complexity. Scoping guidance is included as part of our supported services. Feel free to contact us with any questions.


Download the Cyber Essentials Requirements for IT Infrastructure v3.3: https://www.ncsc.gov.uk/files/cyber-essentials-requirements-for-it-infrastructure-v3-3.pdf

Comments


Get Cyber Certified Logo

0333 339 0383

bottom of page