What are the cyber essentials scoping requirements?
What are the Cyber Essentials scoping requirements?
Understanding what to include when scoping an assessment is one of the most important steps in seeking Cyber Essentials certification. A clear, well‑defined scope ensures the assessment is accurate, manageable and aligned with your organisation’s security priorities. This document explains the scoping principles, provides practical guidance for common scenarios in UK businesses, and answers key questions that organisations routinely ask when preparing for assessment. It also includes current industry context and relevant statistics to help decision makers judge risk and resource allocation.
Why scoping matters for a successful assessment
Accurate scoping sets the boundary for what the assessor will evaluate. It determines which assets, networks, services and user populations are in scope for the technical controls required by the Cyber Essentials scheme. Poorly defined scope can lead to gaps in coverage, unexpected remedial work and potential failure to achieve certification. In contrast, thoughtful scoping aligns the assessment with business risk, reduces unnecessary work and helps prioritise simple, effective security measures.
A 2023 survey of small and medium enterprises showed that many failed initial security assessments because of overlooked internet‑facing services or forgotten shadow IT. The most common causes were outdated inventories and unrecorded remote access arrangements. For UK organisations, where regulatory requirements and supply chain demands increasingly reference baseline cyber controls, a correct scope has direct practical and commercial value.
Core principles of scoping
Focus on internet exposure and critical services
The primary aim of Cyber Essentials is to reduce the risk of common internet‑facing threats by ensuring basic controls are in place. Scoping therefore focuses mainly on systems and services that are accessible from the internet and those that provide direct access to business functions. Typical inclusions are:
- Public web servers and web applications
- Remote access gateways such as VPNs and remote desktop access
- Email services and any externally facing mail gateways
- Cloud services configured to be publicly reachable
Systems that are strictly internal and have no route to the internet may sometimes be out of scope. However, any internal system that can be accessed via an internet‑connected device or that relies on internet‑connected authentication should be carefully considered for inclusion.
Include all accounts and users that can affect the scoped systems
Accounts with administrative privileges or the ability to change configurations for scoped systems are relevant. This includes local administrative accounts on servers, domain administrators, and privileged cloud accounts. The assessor will expect that the organisation has thought through who can access the scoped perimeter and that basic controls are applied to those accounts.
Consider supply chain and third‑party hosting
If an application or platform you rely on is hosted by a third party, the hosted element is within scope if it affects your customers or operations and you control relevant configuration. If a third party manages and configures the platform and you simply consume a fully managed service with no ability to alter settings, the assessor will want to see evidence of contractual responsibility and assurance from the provider. Organisations frequently underestimate the implications of hosted platforms and pay the price with remedial action during assessment.
Document exceptions and compensating controls
Where an asset or service cannot meet a specific control but is critical to the business, it is acceptable to document an exception with appropriate compensating controls and evidence of risk acceptance. The assessor will review such exceptions and may request additional justification. Clear documentation ahead of the assessment speeds review and reduces surprises.
What should be included in a practical scoping exercise
Create an accurate asset inventory
A credible scoping process begins with an inventory of systems, services and users. The inventory should identify:
- Public IP addresses and domain names
- Servers and services reachable from the internet
- Cloud resources, including SaaS applications, that hold business data or authenticate users
- Remote access solutions and their access rules
- Devices used remotely to access business systems
Where a precise inventory is not in place, many organisations start by scanning their public presence and combining the results with internal discovery processes. It is better to be conservative with inclusion than to omit a potentially exposed service.
Map the data flows
Understanding how data moves between internet‑facing systems, internal systems and third‑party services helps identify indirect exposure. For example, a public web application that writes to an internal database creates a bridge that may bring internal systems within scope for practical control and monitoring considerations.
Define the boundaries using clear statements
Scope statements should be clear, concise and unambiguous. Example statements a small business might use are:
- “All corporate email and mail gateways used for @example.co.uk are in scope.”
- “All internet‑facing servers and applications hosted on public IPs assigned to the company are in scope.”
- “VPN gateways that permit remote access to internal systems are in scope.”
These statements help both the organisation and the assessor to reach a shared understanding.
Common pitfalls and how to avoid them
Overlooking cloud and SaaS configurations
Many organisations assume that SaaS providers manage all aspects of security. While providers take on many responsibilities, misconfiguration at the customer level — such as overly permissive access controls or publicly shared storage — remains a frequent cause of exposure. Include SaaS configurations in scope where they affect your security posture.
Ignoring shadow IT and unmanaged endpoints
Employees often use personal devices, unmanaged cloud accounts and alternative communication channels. If these connect to scoped resources or corporate accounts, they should be considered in scope or at least reflected in compensating control evidence.
Failing to consider subcontractors and partners
If partners connect directly into your environment or host systems on your behalf, their control environment influences whether those systems are reliable from a certification perspective. Obtain contractual assurance and evidence of security practices from partners where necessary.
Relying on legacy inventories
A dated asset list is worse than none. Conduct discovery scans and combine them with operational knowledge to produce an up‑to‑date view.
How to approach scoping for different organisation sizes
Small firms and microbusinesses
Small businesses typically have simpler estates and can scope all internet‑facing assets and staff accounts used for email and remote access. The process is often straightforward: identify the corporate domain, list devices that receive corporate email, and capture any remote access tools in use.
Medium‑sized organisations
A medium organisation will typically have multiple sites, cloud services and a larger number of privileged accounts. Scoping requires cross‑department coordination and may involve an inventory project to ensure accuracy. Consider a phased approach: start with the highest risk services and expand coverage as needed.
Large organisations and complex estates
Large enterprises often scope by business unit or by service. A common approach is to certify a defined business function or service rather than the entire organisation at once. This service‑based scoping reduces complexity and allows targeted certification that maps clearly to customer or regulatory requirements. However, ensure that interdependencies between scoped services and wider infrastructure are understood and documented.
Practical steps to prepare an accurate scope
Step 1: Identify internet‑facing endpoints
Use DNS records, public IP registries and web scanning to expose servers and services that are reachable from the public internet. Listing domain names and their hosted services is an effective starting point.
Step 2: List all user groups with relevant access
Identify groups that authenticate to scoped services. This includes internal staff, contractors and outsourced support staff. Document the authentication methods used and whether multi‑factor authentication is enforced.
Step 3: Capture third‑party responsibilities
Record which services are managed by third parties and capture supporting evidence such as contracts, SLAs and security attestations. Where the third party maintains configuration control, include evidence that they meet the baseline requirements.
Step 4: Prepare evidence for each control area
Gather screenshots, configuration exports and policy documents that demonstrate the controls in place for the scoped assets. Common evidence includes firewall rules, patch records for internet‑facing systems, and password policy screenshots.
Step 5: Review and validate the scope with stakeholders
Share the proposed scope with technical and business stakeholders to verify completeness. This step often uncovers forgotten services such as marketing landing pages, test environments or development servers.
Sample scoping scenarios
Scenario: small law firm
A four‑partner law firm with hosted email and a single public web site would typically scope:
- The corporate domain email services
- The web server hosting the public site
- Remote desktop access used by partners to reach case management software
Evidence would include mail gateway settings, web hosting control panel screenshots, and remote access configuration showing secure authentication.
Scenario: online retailer
An online retailer using multiple cloud services might scope:
- Public web applications that process orders
- Payment gateway integrations and associated authentication endpoints
- Customer support systems that are accessible from the internet
The retailer must also include any third‑party hosting where configuration control affects security.
Scenario: multisite manufacturer
A manufacturer with an ERP system and remote access for off‑site engineers may scope:
- VPN gateways and remote access portals
- Remote maintenance interfaces that are accessible from outside the corporate network
- Any externally accessible SCADA or operational technology portals
Because of operational complexity, the manufacturer may choose to scope specific sites or services rather than the entire estate at once.
Evidence and documentation expectations
Assessors will expect evidence that the controls relevant to scoped systems are applied. Typical evidence items include:
- A clear scope statement or spreadsheet listing in‑scope domains, IPs and services
- Firewall configuration showing restrictions on inbound services
- Patch management records for internet‑facing systems
- Password policy and account management screenshots
- Multi‑factor authentication evidence for remote access or privileged accounts
- Records of contracts and security attestations for third‑party services
Prepare evidence in a coherent folder or portal so that the assessment is efficient. Assessors frequently remark that well‑organised evidence reduces assessment time and improves clarity.
Frequently asked questions addressed directly
Below are essential questions many organisations ask when scoping for Cyber Essentials certification. Each question is included exactly as requested for clarity and compliance.
What are the key requirements for achieving Cyber Essentials certification?
Achieving Cyber Essentials requires demonstrating that a defined set of baseline controls are correctly implemented for the scoped systems. These controls focus on secure configuration of devices and services, boundary firewalls and internet gateways, secure user access controls, patching and malware protection, and restricted administrative privileges. The certification confirms that practical measures are in place to mitigate common internet threats.
How can I prepare my small business for Cyber Essentials assessment?
Preparing a small business involves identifying internet‑facing assets, ensuring that basic security controls are in place and collecting evidence to show these controls. Steps include checking firewall rules, applying current patches to public servers, enabling multi‑factor authentication for accounts that access scoped services, and producing a concise scope document listing the assets and accounts that will be assessed.
What software solutions support compliance with Cyber Essentials standards?
There are several classes of software that support the baseline controls required by the scheme. These include endpoint protection platforms that offer anti‑malware and web filtering, secure remote access solutions that enforce strong authentication, patch management systems that keep internet‑facing systems up to date, and logging or monitoring tools that help verify account activity. Choosing reputable, well‑supported solutions reduces operational risk and simplifies evidence collection.
Can I renew my Cyber Essentials certification through an online service?
Yes, certification renewal can be managed through authorised online services provided by certification bodies. Renewals typically require re‑affirmation of scope, evidence that controls remain effective and often an updated self‑assessment or re‑scan of internet‑facing assets. Using an online portal offered by an accredited certifier streamlines the renewal process.
Which companies provide Cyber Essentials certification services in the UK?
A range of accredited certification bodies and commercial organisations offer Cyber Essentials certification services in the UK. These providers vary by service model; some deliver self‑assessment portals with automated checks, while others offer a managed assessment with advisory support. Organisations should select a provider that is listed on the official scheme register and that fits their preferred level of support.
Which UK-based firms offer Cyber Essentials consultancy services?
Numerous UK firms provide consultancy to help prepare for Cyber Essentials assessment. Consultants can assist with scope definition, evidence collection, configuration advice and remediation support. Firms range from specialist cyber consultancies to broader IT managed service providers that include compliance in their service portfolio. When selecting a consultant, look for demonstrable experience with the scheme and references from comparable clients.
Final practical recommendations
- Start scoping early. Accurate scope definition saves time and reduces uncertainty.
- Use service‑based scoping when estates are complex. Certifying a function or service is often more practical than certifying the entire organisation at once.
- Organise evidence logically and involve stakeholders from IT, operations and procurement.
- Treat third‑party services as part of the scope where configuration or access control is within your responsibility.
- Reassess scope periodically, especially after significant changes such as new cloud services, acquisitions or new remote access arrangements.
Applying these scoping principles will help firms of all sizes reach a clear, achievable path to Cyber Essentials certification while aligning control effort to business risk.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










