Cyber Essentials Aberdeen: a practical certification guide
Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.

Section 01
Cyber Essentials Aberdeen: a practical certification guide
Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.
Section 02
Energy services and changing delivery models
Aberdeen City Council’s Net Zero Aberdeen material describes the city’s energy-sector role and transition priorities. This gives a relevant setting for considering field work, remote support and changing service portfolios. It does not establish universal certification requirements for energy operators or their contractors.
Obtain the requirement for the actual engagement. Confirm the certificate level, contracting entity and date by which evidence is expected. Keep other technical, safety and contractual standards separate rather than assuming a CE certificate satisfies the whole supplier assurance process.
Section 03
Example: an engineering supplier with rotational staff
Consider an Aberdeen consultancy whose personnel alternate between office work and customer assignments. Staff use company laptops and several customer access systems. This is an illustrative preparation scenario, not a claim about a named operator or Fig engagement.
Start by confirming the devices and business services used during each part of the rotation. Determine whether laptops away from the office remain visible to the normal management process. A device missing from a recent report needs investigation; it should not silently disappear from the assessment inventory.
Identify software installed for individual assignments, including remote tools and specialist applications. Check who is responsible for support and updates when the device is being used under customer operational constraints. Resolve the arrangement with the technical and operational owners before assuming it meets the scheme.
Review account access when an assignment ends. A person can remain employed by the consultancy while no longer needing a particular customer role. Agree how the company requests customer-side removal and how its own privileged access is reviewed. The process should distinguish an employment change from a project change.
Section 04
Separate office assurance from operational technology
Ask the assessor to confirm the treatment of specialist systems and their connections under the current scope requirements. Do not automatically exclude equipment because it is operational, or imply that an organisational CE assessment is a full industrial-control-system review.
Where a customer requests additional operational assurance, determine the appropriate specialist work and authorisation. A certification project does not grant permission to test a customer’s infrastructure or alter safety-relevant systems. Changes need the normal approved operational process as well as a compliant technical outcome.
Section 05
Work with providers on factual evidence
An MSP may manage business laptops while another supplier supports engineering tools. Create a responsibility record that identifies which party operates each relevant control. General statements that the equipment is supported do not necessarily answer questions about current software versions, administrator access or update completion.
Gather evidence proportionately. Avoid putting customer plant information, sensitive diagrams or live credentials into a general-purpose questionnaire file. Use sanitised configuration records and agree an appropriate channel if more detail is needed.
The organisation’s authorised representative should review the declared scope and answers. If a control remains unresolved, complete the necessary remediation before submission rather than describing an intended future arrangement as current practice.
Section 06
Use certification during service transitions
When the business adds another energy service or changes its customer support model, review whether the existing scope description remains accurate. A new remote-access tool, acquisition or additional specialist device group can change the environment independently of the annual renewal date.
Keep the certificate with a concise explanation of the assessed entity and systems. Check it against each buyer request before sharing it. If Plus, DCC or another assurance route is specified, confirm that separately; neither the city’s energy focus nor a previous customer’s acceptance determines the right answer for a new contract.
This approach keeps certification connected to the organisation’s real controls while leaving broader safety, continuity and customer-specific obligations visible to the people responsible for them.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Aberdeen businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Aberdeen
Aberdeen City Council’s Net Zero Aberdeen material describes the city’s energy-sector role and transition priorities. It provides context for an energy-services example, not evidence that operators universally require CE or that certification covers operational safety.
Business contexts covered
- Energy services
- Engineering support
- Technical consultancies
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Aberdeen City Council: Net Zero Aberdeen - The city’s energy and transition context.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read articleGuides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read article

