Cyber Essentials scope — what’s in, what’s out
Every device and account that can reach your data or your network is in. Here is the full picture: the home-working laptop, the personal phone, the serviced-office router, the cloud services, and why certifying a sub-set is rarely the shortcut it looks like.
The short answer
Cyber Essentials scope is every device and account that can reach your business data or your business network: laptops, desktops, servers, phones and tablets — company-owned or personal — plus your firewalls, routers and cloud services. The default is "whole organisation", and that is what buyers, insurers and the free insurance all expect. You can certify a smaller scope, but it must be a separately networked sub-set, it must be declared on the certificate, and it usually causes more trouble than it saves.
What is always in scope
- Every user device that accesses organisational data or services — including home-working laptops and any personal phone with work email on it. Personal devices are the usual surprise.
- Every server — on premises or hosted — that you administer.
- Boundary devices — the firewalls and routers between your network and the internet. In a home or serviced office that includes kit you don’t own; here’s how that’s handled.
- Cloud services — Microsoft 365, Google Workspace, Xero, your CRM, anything with a login that holds business data. You don’t patch the provider’s servers, but the MFA and account controls are yours to answer for.
- Accounts — every user and admin account on the above.
What is out of scope
- Devices that cannot reach business data or the business network at all — a till on its own isolated network, a machine-tool controller with no internet access.
- Services where you are purely a consumer with no admin rights and no business data — but be honest: a shared spreadsheet in a personal Dropbox is business data.
- Anything you have deliberately walled off into a separate network with its own boundary, and excluded on the application. Rare in a small business, and it must be real segmentation, not a line on a form.
The home-working question
A home router is not in scope if the laptop uses its own software firewall and the business runs no services on the home network. The laptop, however, is fully in scope — supported operating system, patched within 14 days, MFA on the cloud services it reaches. The same goes for the director’s personal machine used "just for email" at weekends. This is where most scope arguments end: if it touches the data, it’s in.
Whole organisation or a sub-set?
Certify the whole organisation unless you have a specific, defensible reason not to. Three things push you that way:
- Buyers assume it. A certificate scoped to "head office only" invites the question "what about the rest?" on every tender.
- The free insurance requires it. The £25,000 cyber liability cover is only available for whole-organisation certification.
- Sub-sets are hard to prove. You must show the excluded part is on a separately controlled network with its own firewall. If a laptop can wander between the two, it isn’t separate.
The legitimate case for a sub-set is a large organisation with a genuinely separate division, or an old estate you’re decommissioning that you can isolate until it’s gone. For a business under fifty people it almost never applies — and the certification fee is banded by the size of the organisation, not the scope, so a narrow scope doesn’t make it cheaper.
How to write the scope on the application
Name the organisation, state "whole organisation", and list the counts the questionnaire asks for: user devices by operating system and version, servers and what they run, mobile devices, cloud services, and the location(s) they operate from. If you have excluded anything, say exactly what and describe the network boundary that separates it. Vague scopes get sent back with questions, which costs you days; a scope that reads like an inventory sails through. The checklist lists everything you need to have counted before you start.
Scope drift is what fails renewals
New starter, new laptop, new cloud tool, tablet bought for the workshop: all in scope from the day they arrive, all invisible to last year’s answers. Keep a one-page asset list and update it as things change, and renewal becomes a re-check rather than a rediscovery.
Before anything else, run our free readiness check against the current rules — it flags the MFA and 14-day traps specifically, so you know in two minutes whether this year's renewal is a formality or a project.
Not sure what’s in scope? Ask before you apply.
Fixed price, current-rules review before submission, fixes included, resubmission covered. We’ll agree the scope with you first, so the application doesn’t come back with questions.
hello@passcyber.co.uk · Take the readiness check
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd