Cyber Essentials Belfast: a practical certification guide
Belfast technology suppliers can use Cyber Essentials to demonstrate a national technical baseline while keeping product security and customer-specific assurance separate. Expertise in cybersecurity does not remove the need to verify how the company’s own accounts, devices and business services are managed.

Section 01
Cyber Essentials Belfast: a practical certification guide
Belfast technology suppliers can use Cyber Essentials to demonstrate a national technical baseline while keeping product security and customer-specific assurance separate. Expertise in cybersecurity does not remove the need to verify how the company’s own accounts, devices and business services are managed.
Section 02
A technical ecosystem, not automatic assurance
Queen’s University Belfast’s CSIT describes its research and industry-collaboration role in Northern Ireland’s cybersecurity ecosystem. That provides a relevant context for this guide. It does not imply that CSIT endorses Fig, requires every partner to hold CE or certifies the businesses around it.
A company’s technical credentials and the controls in its corporate environment are different forms of evidence. Before assessment, identify the organisation being certified and the systems through which staff perform business work. Do not assume that a secure product automatically means every internal cloud account or endpoint is managed consistently.
Section 03
Example: a security product company with customer demonstrations
Imagine a Belfast supplier that operates corporate IT, development services and several demonstration environments. A prospect asks for Cyber Essentials during onboarding. This is a planning example, not an account of a Fig customer or a named buyer’s policy.
Begin by separating the purpose and ownership of each environment. Record which systems store or process business information, who administers them and how staff access them. Take uncertain scope to the assessor rather than assuming that anything labelled a demo is outside the assessment.
Review accounts created for sales trials. A demonstration tenant can remain active after a prospect disengages, particularly if the account belongs to an individual salesperson or developer. Establish who approves it, who maintains relevant settings and who closes it when no longer needed.
Check the software and devices used to administer those environments. A technically sophisticated team may use a wide variety of tools. Confirm supported versions and the update process with the people responsible rather than relying on expertise as a substitute for evidence.
Section 04
Avoid extending the certificate to the product
Cyber Essentials is not a penetration test of every customer-facing feature or proof that a product detects all attacks. If a buyer requests application testing, code review or other assurance, scope that separately and explain what evidence has actually been produced.
The same care applies to customer deployments. Your company’s certificate does not automatically certify a customer’s configuration or infrastructure. State the assessed entity and scope clearly so the buyer can understand the distinction between supplier assurance and assurance about its own environment.
Section 05
Procurement across different markets
For a Northern Ireland public-sector opportunity, use the buyer’s own documents and clarification process. Do not assume a policy applying to a different public authority provides the answer. Confirm the certificate level, evidence deadline and any accepted alternatives for that contract.
If the business serves customers outside the UK, ask whether they accept Cyber Essentials and what additional evidence they require. A UK certificate should not be presented as equivalent to another country’s framework without a defensible basis and buyer agreement.
Section 06
Prepare a concise internal review
Bring together corporate IT, engineering and the commercial owner. Agree which team answers questions about each service and who implements necessary changes. The authorised representative should review the completed assessment against the actual environment, even if the company employs experienced security professionals.
Keep customer data, live secrets and unreleased product material out of general enquiry forms. Use sanitised configuration evidence and agree a suitable transfer method where more detail is needed. A large technical evidence export is not automatically a better or safer answer.
After certification, maintain the environment inventory through product launches and new sales demonstrations. Review changes when they occur rather than copying the previous questionnaire at renewal. This keeps supplier assurance connected to the company’s working practices while avoiding unsupported claims about the security of every product, customer or partner in its ecosystem.
When a sales demonstration ends, check whether temporary accounts or shared links remain accessible and assign responsibility for closing them.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Belfast businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Belfast
Queen’s University Belfast describes CSIT’s research and industry collaboration role in Northern Ireland’s cybersecurity ecosystem. The guide uses a technical supplier scenario without implying endorsement, affiliation or a certification requirement from CSIT.
Business contexts covered
- Cybersecurity businesses
- Technology suppliers
- Research-led companies
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Queen’s University Belfast: CSIT - CSIT’s research, innovation and industry-collaboration role.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read articleGuides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read articleGuides
Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.
Read article

