Govern & Assure
Cyber Essentials Scoping
Cyber Essentials scoping to define what your certification will cover and establish a clear boundary for the assessment.
- Clear certification scope
- Scope boundary
- Technology coverage
- Clear next step
Cyber Essentials scope is usually straightforward, but it still needs to be clear before the assessment starts. We help you define which parts of the organisation, systems, users, and services are included, whether certification will cover the whole organisation or an appropriately defined scope, and how areas such as cloud services and remote working fit into that boundary.
The outcome is a clear scope that gives you a firm starting point for readiness and assessment, without doing more work than is necessary.
Get a quote for Cyber Essentials Scoping
Tell us your scope and objectives, and we’ll come back with a clear, fixed proposal, usually the same working day.
Get a Quoteor call +44 (0) 203 393 7795- CREST-accredited
- UK-based specialists
- Crown Commercial Service supplier
How it works
- 01
Understand the certification objective
We establish why you need Cyber Essentials and what part of the organisation needs to be covered.
- 02
Review the environment
We look at the organisational and technical environment relevant to the proposed scope.
- 03
Identify boundaries
We establish which users, devices, services, and locations fall within the certification boundary.
- 04
Confirm the scope
We agree a clear scope that can be used for the next stage of the Cyber Essentials process.
- 05
Move into readiness or assessment
Once the scope is clear, you can move into gap and readiness work or directly into assessment where appropriate.
Whole organisation or limited scope?
Cyber Essentials can sometimes apply across the whole organisation, while in other cases a defined scope may be more appropriate. The important point is that the boundary is clear and makes sense in practice. We help you understand what needs to be included and how the scope affects the assessment that follows. Scoping does not assess whether you meet the Cyber Essentials requirements. That comes next through readiness and assessment.
What you get
Clear certification scope
A defined view of the organisation, systems, and users covered by the certification.
Scope boundary
Clarity over what sits inside and outside the assessment boundary.
Technology coverage
A clear view of the devices, networks, cloud services, and working arrangements relevant to the scope.
Clear next step
A confirmed basis for moving into readiness or assessment.
Frequently asked questions
Straight answers to what prospective clients ask us most.
Do we need a separate scoping exercise?
Not always. If the certification boundary is already clear, scoping may simply form the first part of the wider Cyber Essentials engagement. A separate scoping exercise is more useful where the organisation, technology estate, or intended certification boundary is less straightforward.
Does Cyber Essentials have to cover the whole organisation?
Not necessarily. Depending on your environment and certification objective, an appropriately defined scope may be possible. We help you understand what the proposed boundary means before the assessment begins.
Is scoping the same as a readiness assessment?
No. Scoping defines what is included. Gap analysis and readiness work looks at whether the in-scope environment meets the Cyber Essentials requirements.
What happens after scoping?
If you are unsure whether the controls are ready, the next step is usually gap analysis and readiness. If you are already confident in your position, you can move directly into the Cyber Essentials assessment.
Related services
Ready to talk about cyber essentials scoping?
Get a fixed-scope quote, usually the same working day.