Does Cyber Essentials cover cloud services?
Yes - Cyber Essentials explicitly covers cloud services under v3.3. Microsoft 365, Google Workspace, AWS, Azure, and any SaaS application holding organisational data are all in scope, with specific configuration expectations around MFA, tenant settings, and managed updates.

Section 01
Does Cyber Essentials cover cloud services?
Yes - Cyber Essentials explicitly covers cloud services under v3.3. Microsoft 365, Google Workspace, AWS, Azure, GCP, Salesforce, and any SaaS application holding organisational data are all in scope, with specific configuration expectations around MFA, tenant settings, and managed updates.
Section 02
What v3.3 treats as in-scope cloud
- Identity providers (Microsoft Entra ID, Google Workspace, Okta)
- Productivity suites (Microsoft 365, Google Workspace)
- Cloud infrastructure you operate (AWS, Azure, GCP accounts / subscriptions)
- SaaS platforms that store or process organisational data (Salesforce, HubSpot, Xero, QuickBooks, Slack, Notion, Jira, and similar)
- File-sharing services used for corporate data (SharePoint, OneDrive, Google Drive, Dropbox Business, Box)
See the detailed guide: Cyber Essentials v3.3: cloud services scope changes explained.
Section 03
What assessors check on cloud services
Identity and access
- MFA enforced for every user on every cloud app in scope, without exceptions.
- Disable basic authentication where the exact service still supports it; POP, IMAP and SMTP are protocols and can have different authentication options. Check current vendor documentation before changing a tenant.
- Conditional Access / equivalent policy exports available.
- Consider phishing-resistant MFA for admin roles as stronger protection; apply the scheme's actual MFA criteria.
Configuration
- Default tenant settings reviewed and hardened.
- Use provider configuration guidance where helpful. Microsoft Secure Score is a posture measure, not a universal Cyber Essentials pass score.
- External sharing rules documented and appropriate.
Updates and maintenance
- For SaaS, confirm what the provider updates and what your organisation still configures. Review any customer-managed components or unsupported clients separately.
- For IaaS, the applicant commonly maintains guest operating systems and deployed applications; for PaaS and SaaS, responsibility varies by service. Map high-risk or critical updates to the component you actually control.
User access
- Joiner / mover / leaver process covers all cloud services, not just the identity provider.
- Guest and contractor access is named, time-bound, and reviewed.
Section 04
What is the organisation's responsibility vs the cloud provider's?
Responsibility differs by service and contract. For IaaS, PaaS and SaaS, identify which party maintains each layer. Applicant responsibilities may include:
- Anything you deploy on top (VMs, containers, application code, infrastructure as code)
- Tenant configuration
- User access
- Data classification and sharing settings
- Logging and monitoring setup
This is the shared-responsibility model - and the CE assessment focuses on your side of it.
Section 05
Common cloud-scoping failures
- Forgotten SaaS applications. Marketing tools, HR systems, procurement platforms that process organisational data but aren't on the IT inventory.
- MFA gaps on a secondary SaaS. The identity provider has MFA, but a standalone tool (a travel-booking platform, a legacy billing system) doesn't.
- Legacy authentication re-enabled. Microsoft 365 basic-auth accidentally left on for a specific mailbox.
- Free-tier cloud accounts used for work, outside IT governance.
Section 06
Does Cyber Essentials cover AWS / Azure / GCP infrastructure?
Yes. Any cloud infrastructure your organisation operates is in scope. Assessors want to see that:
- MFA is enforced on the cloud-provider console
- Root and emergency accounts are tightly controlled; sealed break-glass and monitoring arrangements are additional good practice
- Resource-level security groups / firewall rules are configured to least privilege
- Patching applies to any compute you operate (VMs, containers, self-managed databases)
- Any CSPM findings you choose to collect are reviewed and acted on; CSPM is an optional tool, not a scheme prerequisite
Section 07
Bottom line
Cyber Essentials includes cloud services used for organisational data or services. Inventory the actual accounts and map applicant and provider controls per service. The assessor checks the applicable scheme criteria, not every optional hardening measure above.
Start Cyber Essentials from £299.99 + VAT | Cyber Essentials v3.3 cloud scope | Free readiness check
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Technical Guides
Multi-factor authentication for Cyber Essentials v3.3: the complete pillar guide
MFA is the single most common reason Cyber Essentials v3.3 submissions fail. This pillar explains which accounts need MFA, which methods are acceptable, and how to implement it across Microsoft 365, Google Workspace, and line-of-business SaaS.
Read articleTechnical Guides
Cyber Essentials v3.3: cloud services scope changes explained
v3.3 made cloud-service scoping explicit. IaaS, PaaS, and SaaS all need specific treatment in the self-assessment. This guide walks through how to describe each type and what the assessor expects.
Read articleTechnical Guides
Malware Protection for Cyber Essentials: What Qualifies and What Does Not
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
Read article

