The Scope page defines the boundary of your Cyber Essentials assessment. Getting this right is critical — everything within scope must meet the CE requirements.

Key fields

FieldDescription
Scope DescriptionA narrative description of what's in scope — offices, departments, systems.
Organisation SizeSME, Large Enterprise, or Public Sector — affects some CE requirements.
Certification LevelBasic or Plus — determines assessment approach.
In-Scope SystemsAll devices, servers, and infrastructure that handle business data.
Cloud ServicesSaaS/IaaS/PaaS services used by the organisation (e.g., Microsoft 365, AWS).
Remote WorkersWhether remote/home workers are in scope — if yes, their devices must comply.
Board SponsorSenior leader accountable for the CE programme.
Target Cert DateWhen you plan to achieve certification.
💡
If you choose CE Plus, you'll also need to plan for external vulnerability scanning and internal testing. Use the CE Plus page to track scan results.