Skip to content
Industry

Cyber Essentials for SaaS companies: the scoping question nobody gets right

How SaaS companies can document corporate devices and production cloud responsibilities correctly in a Cyber Essentials scope.

group of people using laptop computer

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

12 min read

Share

Section 01

Cyber Essentials for SaaS companies: the scoping question nobody gets right

A SaaS company can misunderstand scoping by treating production cloud infrastructure as automatically excluded. This guide addresses that practical mistake; it does not claim a measured sector failure ranking.

This guide separates corporate and product responsibilities without excluding cloud services that host organisational data or services.

Section 02

The mistake most SaaS companies make

A SaaS company has two distinct environments:

1. Corporate estate: laptops, email, Slack, HR systems, finance systems. The stuff your team uses to run the business.

2. Product infrastructure: the AWS/GCP/Azure accounts that run your SaaS product for your customers.

The mistake is assuming that the second environment is exempt. NCSC v3.3 requirements requires cloud services hosting organisational data or services to be in scope. SOC 2, ISO 27001 and ISO 27017 can provide broader assurance but do not replace this scope obligation.

Section 03

What Cyber Essentials is designed for

Cyber Essentials covers five control categories: firewalls, secure configuration, user access control, malware protection, and security update management. The scope includes end-user devices, servers and cloud services; responsibilities vary between IaaS, PaaS and SaaS.

Map container hosts, serverless services, managed Kubernetes and databases to the provider/customer responsibility boundary. Self-developed application code has specific scheme treatment; that does not exclude hosting accounts, services or commercial components.

Section 04

The correct SaaS scope

Build the scope from actual organisational use, including:

  • All staff laptops, desktops, and phones.
  • Corporate M365/Google Workspace tenancy.
  • Corporate network (office only). Note: under v3.3, normal home routers used by remote workers are explicitly excluded from scope; the laptop's software firewall handles the home-network boundary.
  • Corporate SaaS: email, Slack, HRIS, finance, CRM.
  • Anything else employees directly use.

Production responsibilities to include and map:

  • Production AWS/GCP/Azure accounts used to run the product.
  • Container registries, CI/CD pipelines that deploy to production, production Kubernetes clusters.
  • Product databases, production data stores.

Section 05

How to document the separation

The CE questionnaire asks for a scope description. For a SaaS company, this looks like:

> "Scope includes employee devices, corporate M365 and SaaS, office network and the production cloud services hosting our product. We document customer-managed configuration and provider-delivered controls for each service. Privately owned home routers are excluded; organisation-supplied routers are included. Remote endpoints meet the firewall controls, or use the managed corporate VPN boundary."

This is illustrative wording. Agree the actual scope and responsibility mapping with the assessor; naming a production account does not make its exclusion permissible.

Section 06

What about staff access to the product?

If engineers bastion into production AWS from their corporate laptops, the corporate laptop is in CE scope (it is the engineer's primary device). The production AWS service and bastion access also need the applicable responsibility and authentication controls; a bastion does not create an automatic exclusion.

The assessor's concern is that the corporate laptop itself meets the five controls: MFA on the corporate identity provider, up-to-date patches on the laptop OS, malware protection, secure configuration, firewall. They also review the applicable controls for your in-scope cloud services, including the settings and responsibilities you manage.

Section 07

What about customer data?

Cloud services hosting your organisation's production data or services must be in scope. Cyber Essentials assesses its defined technical baseline, not every aspect of application security, privacy or customer assurance. SOC 2, ISO 27001 and ISO 27017 may complement it.

Explain the certificate's actual scope and technical baseline to customers. It is not a blanket assurance of secure custom code or every production security practice.

Section 08

Cyber Essentials Plus for SaaS

CE Plus adds external vulnerability scanning and device configuration verification. For SaaS companies, CE Plus is particularly useful because the external scan targets your corporate network perimeter, which is a real attack surface.

Agree the Plus test scope with the assessor from the actual in-scope infrastructure and applicable test requirements; do not categorically exclude production. Penetration testing can provide separate deeper testing. CSA CAIQ is a questionnaire and SOC 2 Type II is an assurance report, neither a vulnerability scan.

At Fig Group, Plus scheduling and completion depend on agreed scope, availability, access and remediation. The external scan, authentication checks and sampled-device tests must pass before certification; 2-3 working days is not a universal completion promise.

Section 09

The pattern that works

1. Map corporate and production scope, provider responsibilities and customer-managed controls.

2. Submit a complete compliant assessment. Fig Group's 6-working-hour CE service applies to complete compliant submissions received before midday on a UK business day; Plus needs agreed scheduling and successful testing.

3. If the customer is asking about production data handling, respond with SOC 2 or ISO 27001 evidence separately.

4. If you need both tiers, start ISO 27001 with CE Plus as foundation evidence.

This sequence keeps the corporate and product responsibilities clear while preserving the required cloud-service scope.

Section 10

Bottom line

Include corporate devices and relevant production cloud services, document shared responsibilities, and use complementary assurance where customers need broader evidence.

Get Cyber Essentials in 6 hours | See Cyber Essentials Plus pricing | Read the scoping guide

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.