Cyber Essentials Scope Decisions, the Hub

Net Sec Group is an IASME and NCSC certification body. Across our 800-plus engagement history, scoping is the work that decides whether an engagement runs cleanly or rolls into rework. Get the scope right and the rest of the engagement is straightforward; get it wrong and the SAQ goes back from the assessor with corrections that take longer than the SAQ itself. This hub indexes the four scope-decision spokes for the buyer profiles where scoping is non-trivial.

The four spokes are: the microbusiness scope playbook for 1 to 9 person firms, the cloud-only business scope translation of the five controls when there is no on-premise infrastructure, the BYOD decision tree for personal devices, and the no-IT-team work map for ops leads running preparation without internal technical specialism. Each spoke walks the scope-shape questions for its profile and links to the timeline-path articles for the engagement itself.

Articles in this hub

Cyber Essentials for a 1 to 9 Person Business, the Microbusiness Scope Playbook

The scope playbook for a 1 to 9 person firm, what UK government guidance also calls a small business at the lower end of the SME range. Walks the five scope questions a founder must answer at this size: who counts as a user, which devices are in scope (including the founder's personal hardware), the home-office boundary firewall question, cloud accounts and admin separation, contractors and short engagements. Microbusinesses pass faster than mid-size firms; the typical preparation time with MFA already in place is 5 to 7 days.

Cyber Essentials for a Cloud-Only Business, the Five Controls Translated

The five Cyber Essentials controls translated into a cloud-only environment. No office, no on-premise firewall, no servers; the boundary is the host-based firewall on each laptop plus the cloud-platform security groups, and the secure-configuration baseline is the SaaS hardening configuration. Per-control evidence formats with the AWS, Microsoft 365, and Google Workspace specifics, plus the three principles that thread through the cloud-only translation (identity is the new perimeter, the SaaS platform is in scope, auto-update is not the evidence the report is).

BYOD and Cyber Essentials, the 15-Minute Scope Decision Tree

The 15-minute decision tree for personal devices. Six yes/no nodes with the IASME rule behind each: data access, sandboxed container, customer versus employee, cloud admin work, MDM enrolment, OS support. The tree lands every device class at one of three outcomes (out of scope, in scope as a managed device, in scope as a BYOD device with specific evidence requirements). The fastest BYOD scope decision is to issue a managed device for cloud admin work and take that branch out of scope ambiguity entirely.

Cyber Essentials When You Have No IT Team, the Ops-Lead Work Map

The two-column work map for an ops lead, office manager, or founder running CE preparation without internal IT. Column A is six tasks an ops lead can complete alone (asset list, MFA enable, leaver process documentation, password manager rollout, evidence collection, basic policy documentation). Column B is four tasks needing technical input (boundary firewall evidence in cloud-only, default-deny application configuration, vulnerability scanning at CE Plus tier, complex access reviews). Column A is 10 to 14 hours of ops work; column B is 4 to 8 hours of helper time.

When to read which article

| Where you are | Read this | |---|---| | 1 to 9 person firm scoping for the first time | Microbusiness scope playbook | | No office, all cloud, unsure how the firewall control applies | Cloud-only business scope | | Personal devices in the mix and unsure which are in scope | BYOD decisions, fast | | Ops lead or office manager running CE preparation alone | Cyber Essentials without an IT team | | Multiple of the above apply | Read in order: microbusiness first, then BYOD or cloud-only as the next decision, then no-IT-team if running solo |

How this hub relates to the other two

The scope-decisions hub is one of three on this site. The other two:

The buyer journey runs: scope-decisions (settle who and what) → comparisons (settle which certification and which execution model) → timelines (pick the speed path) → spoke article on the chosen timeline path.

Common questions

Can I scope just one business unit instead of the whole organisation?

Yes, but the scope statement must clearly delineate the included business unit, the excluded units, and document why each excluded unit has no logical path into the in-scope estate. The IASME default is "the whole organisation"; defined-subset scoping requires clear evidence the boundary is real.

Which part of scoping causes the highest-frequency error?

The asset-list reconciliation. Devices and cloud services in finance records that do not appear in MDM, devices in MDM that finance has stopped paying for, contractor laptops that finance never knew about. Spend the time on day 1 of any prep plan to reconcile MDM, identity provider, and finance into one master inventory.

Is there a separate Cyber Essentials scope for tenants and parent companies?

Yes. A subsidiary in a group of companies can certify on its own scope; the parent and other subsidiaries are out of scope by default. The scope statement names the certifying entity. For shared services (a parent-company AWS tenant, for example), the scope statement clarifies which subscriptions or accounts are in scope.

What if my scope is genuinely ambiguous?

Book a scoping call before booking the engagement. Net Sec Group's pre-engagement scoping is free; we resolve the scope question and confirm the engagement sizing before any cost commits.

Where do we book?

Once the scope is settled, follow the path you picked on the timelines hub. The booking link there returns a confirmed engagement timeline.

Reference material

For the broader Net Sec Group references on scoping: