Skip to content
Guides

Cyber Essentials Aberdeen: a practical certification guide

Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.

a city on a hill

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Aberdeen: a practical certification guide

Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.

Section 02

Energy services and changing delivery models

Aberdeen City Council’s Net Zero Aberdeen material describes the city’s energy-sector role and transition priorities. This gives a relevant setting for considering field work, remote support and changing service portfolios. It does not establish universal certification requirements for energy operators or their contractors.

Obtain the requirement for the actual engagement. Confirm the certificate level, contracting entity and date by which evidence is expected. Keep other technical, safety and contractual standards separate rather than assuming a CE certificate satisfies the whole supplier assurance process.

Section 03

Example: an engineering supplier with rotational staff

Consider an Aberdeen consultancy whose personnel alternate between office work and customer assignments. Staff use company laptops and several customer access systems. This is an illustrative preparation scenario, not a claim about a named operator or Fig engagement.

Start by confirming the devices and business services used during each part of the rotation. Determine whether laptops away from the office remain visible to the normal management process. A device missing from a recent report needs investigation; it should not silently disappear from the assessment inventory.

Identify software installed for individual assignments, including remote tools and specialist applications. Check who is responsible for support and updates when the device is being used under customer operational constraints. Resolve the arrangement with the technical and operational owners before assuming it meets the scheme.

Review account access when an assignment ends. A person can remain employed by the consultancy while no longer needing a particular customer role. Agree how the company requests customer-side removal and how its own privileged access is reviewed. The process should distinguish an employment change from a project change.

Section 04

Separate office assurance from operational technology

Ask the assessor to confirm the treatment of specialist systems and their connections under the current scope requirements. Do not automatically exclude equipment because it is operational, or imply that an organisational CE assessment is a full industrial-control-system review.

Where a customer requests additional operational assurance, determine the appropriate specialist work and authorisation. A certification project does not grant permission to test a customer’s infrastructure or alter safety-relevant systems. Changes need the normal approved operational process as well as a compliant technical outcome.

Section 05

Work with providers on factual evidence

An MSP may manage business laptops while another supplier supports engineering tools. Create a responsibility record that identifies which party operates each relevant control. General statements that the equipment is supported do not necessarily answer questions about current software versions, administrator access or update completion.

Gather evidence proportionately. Avoid putting customer plant information, sensitive diagrams or live credentials into a general-purpose questionnaire file. Use sanitised configuration records and agree an appropriate channel if more detail is needed.

The organisation’s authorised representative should review the declared scope and answers. If a control remains unresolved, complete the necessary remediation before submission rather than describing an intended future arrangement as current practice.

Section 06

Use certification during service transitions

When the business adds another energy service or changes its customer support model, review whether the existing scope description remains accurate. A new remote-access tool, acquisition or additional specialist device group can change the environment independently of the annual renewal date.

Keep the certificate with a concise explanation of the assessed entity and systems. Check it against each buyer request before sharing it. If Plus, DCC or another assurance route is specified, confirm that separately; neither the city’s energy focus nor a previous customer’s acceptance determines the right answer for a new contract.

This approach keeps certification connected to the organisation’s real controls while leaving broader safety, continuity and customer-specific obligations visible to the people responsible for them.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Aberdeen businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Aberdeen

Aberdeen City Council’s Net Zero Aberdeen material describes the city’s energy-sector role and transition priorities. It provides context for an energy-services example, not evidence that operators universally require CE or that certification covers operational safety.

Business contexts covered

  • Energy services
  • Engineering support
  • Technical consultancies

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig