Aside from the built-in system accounts (LocalSystem, NetworkService, and LocalService), there are no "service accounts". Those that you configure to run services are no different from regular accounts (at least from the password management standpoint) with exception of the extra privilege to log on as a service). Effectively, I don't see why they wouldn't be in scope. The passwords of the built-in system accounts are managed by the OS - so their complexity is not something you can control.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin