Cyber Essentials Birmingham: a practical certification guide
A Birmingham business can arrange Cyber Essentials remotely, using the same control requirements as organisations elsewhere in the UK. The most useful preparation is to connect the certificate request to your legal entity, service and actual technology environment before buying an assessment.

Section 01
Cyber Essentials Birmingham: a practical certification guide
A Birmingham business can arrange Cyber Essentials remotely, using the same control requirements as organisations elsewhere in the UK. The most useful preparation is to connect the certificate request to your legal entity, service and actual technology environment before buying an assessment.
Section 02
One city, different assurance conversations
Birmingham’s economic development material identifies professional and business services, life sciences, and creative and digital activity among its priorities. That diversity makes it important not to present one procurement rule as applying to the whole city.
A consultancy answering a corporate supplier questionnaire has a different starting point from a laboratory preparing for a research partnership. Both can use Cyber Essentials to demonstrate the scheme’s technical baseline, but neither should infer the customer’s full security requirements from its sector alone. Obtain the relevant written request and identify any separate contractual obligations.
Section 03
Example: a professional-services group with several offices
Consider a Birmingham-led professional-services business that has added another office through acquisition. Both teams use the same trading brand, but their cloud tenants and IT providers remain separate. This is a planning example, not a statement about a particular Birmingham firm.
Before describing the organisation as a single managed environment, confirm the legal entities involved and which services the proposed certificate will cover. A common logo does not prove common account administration, update management or device configuration. Ask the assessor to review the proposed boundary before completing answers that assume the two offices are identical.
Then compare how people join, change roles and leave across the offices. Identify whether an acquired employee has both an old mailbox and a new group account. Check who can administer each tenant and whether old remote-support tools remain active. These details can create inconsistencies between a central policy document and the controls used in practice.
Give each unresolved item an owner. The integration programme may be long-running, but answers for the assessment must reflect the controls in place at submission. Do not describe a planned tenant migration as though it has already removed an unsupported system or brought every device under management.
Section 04
Prepare for client questions without overselling the certificate
Professional-service customers may ask about confidentiality, incident response, data handling or access to their systems. Keep those questions separate from the evidence assessed under Cyber Essentials. The certificate is not proof that every contractual security obligation or professional regulation has been independently audited.
If a client requests Cyber Essentials Plus, confirm the scope and arrange the additional technical verification. If an insurer asks about certification, provide accurate policy and control information rather than assuming the certificate guarantees cover or a premium reduction. Ask the appropriate insurance professional about the insurance requirement.
Section 05
Public-sector opportunities
For a council, health, university or wider public-sector tender, use that opportunity’s procurement documents. The national Cyber Essentials procurement policy has a defined application; it is not evidence that every Birmingham public-body purchase requires CE or Plus.
Resolve unclear wording through the buyer’s published clarification route. Ask what evidence is accepted, when it must be available and whether the requirement extends to subcontractors. Record the answer in the bid file so your IT team is not trying to interpret an informal sales conversation under deadline pressure.
Section 06
A clear submission handover
The business owner should confirm the entity and service boundary. IT or the MSP should provide the factual control information. The authorised representative should review and approve the submission. Agree those responsibilities at the start, particularly where several offices or external providers are involved.
Keep a concise inventory of the devices, cloud services and administrator arrangements relevant to the assessment. Store evidence securely and avoid including client case files or personal data when a configuration record will answer the question. After certification, maintain the same ownership arrangements through renewals and organisational changes. This is more useful than collecting a certificate whose scope nobody can explain when the next client asks.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Birmingham businesses
Swipe across the table to view all columns.
Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Birmingham
Birmingham’s council-backed economic development material identifies professional and business services, life sciences, creative and digital activity. These are contexts for the guide’s preparation examples, not proof of certification demand from named customers.
Business contexts covered
- Professional services
- Life sciences
- Digital businesses
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Growth in Brum: key economic sectors - The city’s stated sector priorities.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read articleGuides
Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.
Read article

