How to scope cloud services for Cyber Essentials
5 September 2026 · 5 min read
Cloud services are in scope for Cyber Essentials whenever your organisation's data or accounts sit in them. That includes email, file storage, accounting, CRM, payroll, project tools, password managers and anything a member of staff signed up for on a company card.
Build the list from evidence rather than memory. Card statements, your identity provider's application list and a quick poll of each team usually surface tools nobody remembered — the design subscription, the survey tool, the old file share still holding client documents.
For each service, record three things: who has administrative access, whether multi-factor authentication is enforced for everyone, and how accounts are removed when someone leaves. Those three answers cover most of the user access control questions in the assessment.
Shadow IT is the recurring problem. A service that never appears on your list is a service nobody is checking, and it is exactly what an assessor's follow-up questions expose. It is better to list a tool and note that it is being retired than to omit it.
Keep the register dated. A list refreshed monthly is evidence; a list written the week of your assessment is a guess.
Kept's scan reads your connected cloud services and turns them into that register automatically, flagging accounts without multi-factor authentication and administrators you may have forgotten about.
Kept