Skip to content
Technical Guides

Cyber Essentials v3.3 sub-set scoping: when and how to exclude

Cyber Essentials subset scope must be well-defined, separately managed and agreed with the certification body. Learn the firewall/VLAN boundary and stricter unsupported-software rule.

a group of cubes that are on a black surface

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials v3.3 sub-set scoping: when and how to exclude

Subset scoping defines the agreed part of the organisation being assessed. It needs a real management and network boundary, while end-user device and cloud-service rules still apply.

This article walks through what now qualifies.

Section 02

The rule

Start with the whole business IT estate or a well-defined and separately managed subset. The NCSC requirements, pages 5-12, require a clear business unit, network boundary and physical location, agreed with the certification body before assessment. Subsets are segregated by firewall or VLAN.

IASME guidance allows controlled communication across an ordinary subset boundary. Separate identity tenants, physical locks or different internet egress are not universal prerequisites. A policy is useful supporting evidence but does not prove the technical controls or actual use.

Unsupported software is a distinct case: remove it from in-scope devices or use a defined excluded subset preventing all traffic to or from the internet. Applicable cloud services cannot simply be excluded.

Section 03

Common sub-set patterns that pass

Virtual desktops. A thin client or personal laptop accessing Citrix, AWS WorkSpaces or another virtual desktop still accesses an organisational service. Both the relevant end-user device and virtual environment need assessment; no local storage is not an exemption.

Blocked personal devices. A personal device that genuinely does not access organisational data or services may be outside the applicable device scope. Conditional Access can help enforce that restriction. Check actual use rather than assuming a written ban is effective.

Guest networks. A firewall or VLAN can segregate a guest network from the assessed network. Describe the boundary and controlled traffic; different internet egress or physically separate equipment is not always necessary.

BYOD work containers. Work profiles help manage data and applications but do not erase applicable host operating-system, locking or update controls. A work device accessing organisational services remains relevant to scope.

Production and corporate estates. A separate AWS account or SOC 2 report does not exclude production cloud services storing or processing organisational data. Map the actual cloud responsibilities and scope instead.

Section 04

Common sub-set patterns that no longer pass under v3.3

Avoid scope statements based only on intended use. A BYOD ban does not prove that personal phones never access work email, and a guest Wi-Fi label does not establish effective VLAN/firewall segregation.

Conversely, do not invent a universal rule that policy alone makes every personal device in scope. Determine actual access, implement the necessary controls and agree the applicable boundary. A shared identity service or ordinary controlled network route is not by itself proof that a subset is invalid.

Section 05

How to declare sub-set in the self-assessment

Name the business unit, physical location, network boundary and management responsibility. Explain what is excluded, why a partial scope is appropriate and how firewall/VLAN segregation works.

An illustrative description might identify an assessed office business unit, its endpoint estate and VLAN, the firewall rules governing communication with another business unit, and all applicable cloud services. Include organisation-owned thin clients loaned to contractors and employee BYOD accessing virtual desktops. Under the NCSC role/ownership table a third-party contractor's own or personally owned endpoint is outside the assessment scope, while organisation-owned accounts remain in scope and the applicant retains responsibility for interacting-device configuration. VDI or blocked local storage is not the reason for that ownership-based exclusion.

Replace the illustration with your actual estate and agree it before assessment. No sample scope sentence guarantees a pass.

Section 06

What the assessor verifies

  • The technical control is configured.
  • The technical control is enforced (sign-in logs show the block).
  • The exclusion in the scope description matches what the control does.

Section 07

Edge cases

Home routers for remote workers. Under v3.3 (Danzell A2.5), normal home routers used by remote workers are out of scope - no sub-set declaration needed. The boundary follows the device that touches organisational data; the device's software firewall handles enforcement against the home network. Note this in A2.5 of the questionnaire ("Home and remote workers rely on the device's software firewall as the boundary; no home routers in scope"). Where the firm supplies a corporate router as managed kit, that IS in scope as corporate equipment.

Senior executives' personal iPads for reading board papers. If they access board papers directly on the iPad, the iPad is in scope. A managed board-paper app or virtual desktop does not make the host iPad exempt from relevant device controls.

Cleaning staff and facilities. These roles typically do not access organisational data and are out of scope without needing a formal sub-set.

Section 08

Bottom line

Agree a well-defined, separately managed boundary and show that its firewall/VLAN controls match reality. Include end-user devices and applicable cloud services, and distinguish ordinary subsets from unsupported-software internet disconnection.

Start Cyber Essentials | BYOD rules for 2026 | Cloud scope guide

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group