Technology Intelligence
Ask the Advisor

What Counts as a Cloud Service for Cyber Essentials?

Asked anonymously4 minutes read29 July 2026

For Cyber Essentials, a cloud service is accessed over the internet through an account and stores or processes organisational data on hosted infrastructure.

This question has been published anonymously. Details that could identify the person or organisation have been removed.

“I’m doing Cyber Essentials, but no one can actually define what a cloud service is.”

Advisor’s short answer

For Cyber Essentials, a cloud service is an internet-accessed service hosted on shared infrastructure, which you access through an account and which stores or processes data for your organisation.

Examples include Microsoft 365, Google Workspace, Dropbox, Xero, Salesforce, hosted CRM systems and cloud backup platforms.

The confusion is understandable — “cloud” is often used as a vague marketing term. For Cyber Essentials, the definition is now much clearer.

The simplest way to recognise a cloud service is that you normally access it over the internet using an account, while the underlying service is hosted on infrastructure shared between customers and operated by a provider. For Cyber Essentials, the service must also store or process data for your organisation.

Based on the current Cyber Essentials Requirements for IT Infrastructure: a cloud service is an on-demand, scalable service hosted on shared infrastructure and accessed over the internet. For Cyber Essentials purposes, it is accessed through an account and stores or processes organisational data.

Last checked: 29 July 2026.

A quick way to decide

Ask the following questions about any internet-based service your organisation uses:

  1. 1Do you access the service through the internet?
  2. 2Do you sign in using a user account, business email address or organisational credentials?
  3. 3Does the provider host and operate the underlying service?
  4. 4Is the infrastructure shared between multiple customers, even though their data is separated?
  5. 5Does the service store or process information for your organisation?

If the answer to these questions is broadly yes, it is likely to be a cloud service for Cyber Essentials purposes. This is a practical discovery test, not a replacement for the official scheme definition. When in doubt, confirm with your Cyber Essentials assessor or certification body.

Examples of cloud services

The following are common examples. Whether each falls within your Cyber Essentials scope depends on how your organisation uses it:

  • Microsoft 365 (including Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams)
  • Google Workspace (including Gmail used for business and Google Drive)
  • Dropbox
  • Xero
  • QuickBooks Online
  • Salesforce
  • HubSpot
  • Cloud-hosted CRM systems
  • Web-based HR platforms
  • Cloud backup platforms
  • Hosted telephone and VoIP systems
  • Web-based ticketing and support systems
  • Azure-hosted applications
  • Amazon Web Services-hosted applications
  • Hosted virtual desktops
  • Remote monitoring and management platforms

What is not automatically a cloud service?

Simply visiting an ordinary public website does not necessarily make it one of your organisation’s cloud services. Examples that are unlikely to be in scope on their own include: reading a public news website, viewing a supplier’s public product page, using a public search engine without signing into a business account, and visiting an informational government website.

However, if your organisation signs into an online portal and that portal stores or processes business information, it may well be a cloud service.

The important distinction

The important distinction is not simply that the service is on the internet; it is that your organisation uses an account to access a hosted service that stores or processes its data.

What does “shared infrastructure” mean?

A cloud service is a little like an office building occupied by several businesses. The building, utilities and common infrastructure are shared, but each organisation has its own controlled area. Cloud providers use technical separation so that one customer should not have access to another customer’s data.

A private cloud may be dedicated to a single organisation, but the Cyber Essentials definition and scope should be confirmed against the current scheme guidance and the service’s actual design.

Why this matters for Cyber Essentials

Cloud services cannot simply be ignored because the servers belong to somebody else.

Cloud services used to store or process organisational data must be considered within the Cyber Essentials assessment scope. Your organisation remains responsible for ensuring that the relevant Cyber Essentials controls are applied. Depending on the type of service, some controls may be implemented by the cloud provider, some by your organisation, and some by both.

For most Software as a Service (SaaS) platforms — the kind most SMEs use — the provider secures the underlying cloud platform. Customer responsibilities typically include:

  • Enabling and enforcing multi-factor authentication
  • Managing user accounts and access permissions
  • Removing accounts when staff leave
  • Controlling administrator access
  • Reviewing and updating permissions regularly
  • Configuring the service’s security settings correctly
  • Keeping any customer-managed applications or components updated
  • Protecting the devices used to access the service

The shared-responsibility principle

The provider secures the cloud platform; your organisation must still secure how it uses the service.

Common Cyber Essentials misunderstandings

  1. 1“We don’t have any cloud services.” — Microsoft 365, Google Workspace, hosted email, online accounting and cloud backup are all common examples. Most businesses use several.
  2. 2“The supplier handles all the security.” — The provider is responsible for the underlying infrastructure, but your organisation remains responsible for how it configures and uses the service.
  3. 3“It is only a website.” — A signed-in web application that stores or processes business data is likely to be a cloud service for Cyber Essentials purposes.
  4. 4“We do not own the server, so it is outside scope.” — Physical server ownership does not determine whether the service is in scope. How your organisation accesses and uses it is what matters.
  5. 5“Only our IT department needs to list cloud services.” — Finance, HR, marketing and operations may use separate cloud platforms that IT is unaware of. A complete inventory requires input from across the business.
  6. 6“A free online account does not count.” — Cost is not the deciding factor. A free service accessed through a business email address and storing or processing organisational data may still be relevant to scope.

Before completing your Cyber Essentials assessment

  • □ List every online service used by the organisation
  • □ Include services purchased directly by individual departments
  • □ Include free services used with business email addresses
  • □ Record what organisational data each service stores or processes
  • □ Identify who administers each service
  • □ Confirm whether MFA is available and enabled on each service
  • □ Review administrator accounts
  • □ Remove accounts belonging to former staff
  • □ Review the provider’s and organisation’s security responsibilities
  • □ Confirm which services fall within the agreed Cyber Essentials scope

IT Club Advisor’s view

The phrase “cloud service” sounds more technical than it needs to be. For most SMEs, the practical answer is: if staff sign into an internet-based business system and it stores or processes company information, treat it as a potential cloud service and include it in the Cyber Essentials scope review.

It is safer to list a service and confirm its status with your assessor than to leave it out because nobody recognised it as cloud computing.

If you log into it for work and it holds or processes business data, put it on the list.

So, in plain English: a cloud service is a service hosted and operated over shared internet infrastructure, accessed through an account, and used to store or process data for your organisation. Microsoft 365, Google Workspace, online accounting, hosted CRM systems, cloud backups and many other web-based business platforms are therefore cloud services for Cyber Essentials purposes.

When in doubt, include the service in your inventory and confirm the position with your Cyber Essentials assessor or certification body rather than excluding it without review.

Related questions

Is Microsoft 365 a cloud service for Cyber Essentials?

Yes. Microsoft 365 is a cloud service. It is an on-demand, internet-accessed service hosted on shared infrastructure, accessed through business accounts, and used to store and process organisational data. Exchange Online, SharePoint Online, OneDrive for Business and Microsoft Teams are all components of Microsoft 365 and would be considered cloud services for Cyber Essentials purposes.

Is Google Workspace in scope for Cyber Essentials?

Yes. Google Workspace is a cloud service. It is accessed over the internet through business accounts, hosted on shared infrastructure operated by Google, and stores and processes organisational data. The same logic applies to Gmail used for business purposes, Google Drive and other Workspace components.

Does online banking count as a cloud service?

Online banking that is accessed through a business account and used to manage organisational finances is likely to be considered a cloud service for Cyber Essentials purposes. However, many organisations apply a risk-based approach and confirm the position with their assessor. The key questions remain: is it internet-accessed, account-based, hosted on shared infrastructure, and does it store or process organisational data?

Is a hosted VoIP telephone system a cloud service?

A hosted VoIP system that is accessed over the internet, managed through an online account, and operated on shared provider infrastructure is likely to be a cloud service for Cyber Essentials purposes. If the system stores call records, voicemail or contacts associated with your organisation, it processes organisational data.

Does cloud backup fall within Cyber Essentials?

A cloud backup service is typically accessed over the internet through an account, hosted on shared infrastructure, and stores organisational data. It is therefore likely to be considered a cloud service for Cyber Essentials purposes. The relevant controls — such as account management, MFA and access permissions — should be applied.

Are free online services in scope?

Cost is not the determining factor. A free service used through a business account and storing or processing organisational data may fall within Cyber Essentials scope. The practical test is how the service is used, not what it costs.

Does every cloud service need MFA?

For Cyber Essentials, multi-factor authentication should be enabled on all cloud services where it is available, particularly for administrator accounts and any accounts accessible over the internet. Check the current Cyber Essentials requirements for the precise control requirements, as these are updated periodically.

Who is responsible for cloud security?

Cloud security is shared between the provider and the customer. The provider is responsible for securing the underlying platform and infrastructure. The customer is responsible for how it configures and uses the service — including account management, access controls, MFA and keeping any customer-managed elements up to date. This is known as the shared-responsibility model.

What is the difference between SaaS, PaaS and IaaS?

Software as a Service (SaaS) delivers a complete application over the internet, such as Microsoft 365 or Xero — the customer uses it but does not manage the underlying infrastructure or platform. Platform as a Service (PaaS) provides a development environment where customers can build and run their own applications. Infrastructure as a Service (IaaS) provides raw computing resources — servers, storage and networking — which customers configure and manage themselves. Most SMEs primarily use SaaS, where the provider carries the greatest share of infrastructure responsibility.

Can cloud services be excluded from Cyber Essentials scope?

In certain circumstances, a cloud service may be excluded from scope, but this should be discussed with and confirmed by your Cyber Essentials assessor or certification body. The scheme guidance defines what can and cannot be excluded. Do not exclude a service from scope without that confirmation — an incorrect exclusion could result in a failed assessment or inadequate security coverage.

Plain-English Takeaway

A cloud service is a service hosted and operated over shared internet infrastructure, accessed through an account, and used to store or process data for your organisation. Microsoft 365, Google Workspace, online accounting, hosted CRM systems, cloud backups and many other web-based business platforms are cloud services for Cyber Essentials purposes. When in doubt, include the service in your inventory and confirm the position with your assessor.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor