Skip to content

Scoping and devices

Are contractors in scope?

Assess accounts and endpoints separately. An organisation-owned device loaned to a contractor is in scope; a device owned by that third party is outside your device assessment, while the account accessing your service remains under your access controls. Employee BYOD and VDI follow their own scope rules. List device owner, user relationship and authentication path for each arrangement.

Short answer

Assess accounts and endpoints separately. An organisation-owned device loaned to a contractor is in scope; a device owned by that third party is outside your device assessment, while the account accessing your service remains under your access controls. Employee BYOD and VDI follow their own scope rules. List device owner, user relationship and authentication path for each arrangement.

Why this matters

Scoping is where many Cyber Essentials submissions fail. The assessor needs to understand which users, devices, networks, and cloud services can access organisational data. A policy statement alone is not enough if the technical environment still allows access.

Agree the organisation, network boundary and locations with the assessor. A separately managed subset needs the required network segregation and a justified boundary. MDM, Conditional Access or a virtual desktop can help manage access, but none automatically excludes an endpoint or cloud service from assessment.

What to check next

  • List all devices and cloud services that access organisational data.
  • Document any exclusions and the technical enforcement behind them.
  • Check BYOD, home working, and production cloud environments before submitting.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.