Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.

Section 01
Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service obligations explicit. The requirements distinguish IaaS, PaaS and SaaS and clarify that applicable cloud services cannot be excluded. v3.3 now requires organisations to describe each cloud service they use, categorise it, and document how its security is configured.
This article walks through the three cloud categories and what the assessor wants to see for each.
Section 02
Why v3.3 changed this
Too many organisations were declaring "we use AWS" or "we use Office 365" without explaining what that means for CE scope. v3.3 forces a clearer answer: which services, with which configuration, holding what data.
Section 03
The three cloud categories
SaaS - Software as a Service
Examples: Microsoft 365, Google Workspace, Salesforce, HubSpot, Xero, Slack, Notion, Jira.
In scope: always, if it holds organisational data.
What the assessor wants:
- Every SaaS listed in the scope description
- MFA enforced on every user account (usually via SSO)
- Role-based access - not everyone is an admin
- Leaver process - accounts removed or disabled when no longer required; a 24-hour operational SLA is a local choice, not a scheme deadline
- Individual SaaS administrator credentials and separate admin use; stronger phishing-resistant methods are recommended hardening
Common failure: "We have SSO for most SaaS but three tools are standalone with email/password login." Either integrate those tools with SSO or enforce MFA per-tool.
IaaS - Infrastructure as a Service
Examples: AWS EC2, Azure VMs, Google Compute Engine, DigitalOcean Droplets, Linode, Hetzner.
In scope: if you run servers that hold organisational data for the certified organisation. Production infrastructure is not exempt merely because it hosts your product. Cloud services storing or processing organisational data cannot be excluded.
What the assessor wants (when in scope):
- Asset register of all VMs
- Each VM has CE-compliant firewall, secure config, patches, malware protection, user access control
- Cloud-native firewall rules (Security Groups, NSGs) deny inbound except specifically-required ports
- Management-plane access (AWS console, Azure portal) via MFA with separation from normal user accounts
Common failure: "We have 3 EC2 instances but forgot to include them in scope." Anything running organisational data is in scope.
PaaS - Platform as a Service
Examples: AWS Lambda, Azure App Service, Heroku, Vercel, Netlify, Google Cloud Run.
In scope: when the platform runs code on your behalf that processes organisational data.
What the assessor wants:
- List of PaaS services and what they do
- Human management access uses MFA; unattended deploy keys and machine identities are documented and controlled separately
- Dedicated secret stores such as AWS Secrets Manager or Azure Key Vault are useful security advice, not a mandated Cyber Essentials product
- Interactive human cloud sign-in uses MFA; machine tokens and certificates do not perform interactive human MFA
Lower risk than IaaS because the provider handles OS patching. Assessors typically treat PaaS as a simpler scope line than a full VM.
Section 04
Shared responsibility model
v3.3 assumes you understand the cloud shared responsibility model:
- Cloud provider handles: physical security, host OS, hypervisor, network fabric.
- You handle: application, data, access management, guest OS (for IaaS), identity configuration.
The NCSC responsibility table, pages 10-11, identifies the controls you manage or must ensure the provider implements. Self-developed code has a specific treatment; that does not exempt the hosting cloud service. The CE controls apply according to that responsibility boundary. The assessor is not testing AWS's data-centre security; they are testing your configuration of AWS.
Section 05
Documenting cloud scope
A clean v3.3 scope description includes:
- SaaS inventory: every SaaS app, with MFA status and admin count.
- IaaS inventory: every VM or cloud host in scope, with OS, patch cadence, and access control.
- PaaS inventory: every PaaS service, with deploy-access controls.
- Responsibility boundary: state which controls you and the provider manage. A separate SOC 2 report does not exempt a production AWS account storing or processing organisational data.
Section 06
Backup and disaster recovery
The NCSC requirements, page 5, explicitly say backups are recommended rather than a technical Cyber Essentials requirement. For resilience beyond the baseline, record:
- Where backups live (different cloud provider, different region, or offline).
- Backup frequency.
- Restoration test cadence.
- Who has access to the backup system.
Section 07
What this means for a typical 30-person organisation
A 30-person UK SMB probably uses:
- M365 or Google Workspace (SaaS).
- Xero, HubSpot, Slack, and 5-10 line-of-business SaaS apps.
- Possibly one or two IaaS VMs (a VPN gateway, a file server).
- Maybe a Vercel/Netlify landing page (PaaS).
Scope description:
> "In scope: Microsoft 365 corporate tenant, 8 line-of-business SaaS apps (HubSpot, Xero, Slack, Notion, Jira, ClickUp, Zoom, LastPass), all via Entra ID SSO with MFA enforced. Two Azure VMs hosting a VPN gateway and a file server (Windows Server 2022, patched monthly, 14-day SLA for vendor high/critical, CVSS v3 7+ and unspecified-severity vulnerability fixes). One Vercel site hosting the marketing website. Excluded: nothing."
This is an illustration, not an automatic passing answer. Verify the actual estate, authentication and responsibility boundary against the requirements before submitting.
Start Cyber Essentials | CE for SaaS companies | See pricing
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Cyber Essentials Scoping: What Is In, What Is Out, and How to Not Get It Wrong
Scoping is the single most misunderstood part of the Cyber Essentials submission. Get it wrong and your whole assessment is compromised. This guide covers remote workers, BYOD, cloud services, legacy systems, sub-set scoping, and the five scoping traps that most often fail assessments.
Read articleTechnical Guides
User Access Control for Cyber Essentials v3.3: the complete pillar guide
User Access Control is the pillar of Cyber Essentials that catches the most UK organisations out at assessment. This guide walks through every v3.3 requirement - individual accounts, MFA, admin separation, joiner-mover-leaver, third-party access - and the exact evidence assessors now expect.
Read articleGuides
Does Cyber Essentials cover cloud services?
Yes - Cyber Essentials explicitly covers cloud services under v3.3. Microsoft 365, Google Workspace, AWS, Azure, and any SaaS application holding organisational data are all in scope, with specific configuration expectations around MFA, tenant settings, and managed updates.
Read article

