Cyber Essentials Brighton: a practical certification guide
A Brighton agency or digital business does not need a traditional fixed office to approach Cyber Essentials, but it does need a clear account of the systems used for work. Shared workspace, home working and external collaborators should be considered through the current scope requirements rather than treated as reasons to leave parts of the business unexplained.

Section 01
Cyber Essentials Brighton: a practical certification guide
A Brighton agency or digital business does not need a traditional fixed office to approach Cyber Essentials, but it does need a clear account of the systems used for work. Shared workspace, home working and external collaborators should be considered through the current scope requirements rather than treated as reasons to leave parts of the business unexplained.
Section 02
Creative work across different locations
Brighton & Hove City Council’s workspace announcement addresses creative, cultural and digital organisations. It provides a local setting for a guide about changing workplaces and shared facilities. It does not establish certification requirements for participants or endorsement of a certification provider.
The location of a desk is only one part of the environment. Identify the cloud services, devices and accounts used to deliver the customer’s work. Ask who manages them and what information moves between company systems and customer platforms.
Section 03
Example: an agency moving into shared workspace
Imagine a Brighton company whose staff have worked remotely and are taking shared office space. It uses company laptops, freelance collaborators and hosted project tools. A customer has asked for certification. This is a planning example, not a report of a named agency or Fig engagement.
Start by separating the workspace provider’s services from the agency’s responsibilities. Establish who manages connectivity and any shared network equipment. Do not assume that a professionally operated building configures your cloud accounts, updates your laptops or manages your project users.
Review the working arrangements that remain outside the new office. Staff may still access business email and customer assets from home or while travelling. Discuss relevant devices and scope with the assessor rather than assuming the move makes the organisation an office-only environment.
Check external collaborator access across active and completed projects. A project manager may close the commercial job while an account remains in storage or a customer portal. Assign responsibility for ending access and confirming any customer-controlled action.
Section 04
Keep the technical inventory practical
List the services that actually store or process business information. Include tools adopted by individual teams, not just those on the main software subscription list. Confirm that the organisation can administer access and apply the required settings.
Review specialist creative applications and supporting components on workstations. An up-to-date main application does not establish that every plug-in, browser or operating system remains supported. Ask the responsible technical person for factual information and complete remediation where needed before submission.
Section 05
Respond accurately to customer assurance requests
Obtain the exact level, certified entity and deadline from the buyer. Do not assume that every brand, public body or cultural commissioner asks for the same evidence. If the request includes product testing, privacy obligations or other assurance, track those separately from the CE certificate.
Cyber Essentials does not certify every website the agency builds or every customer platform it accesses. It assesses a defined organisational technical baseline. Explain that scope when using the certificate in a proposal instead of implying the whole project ecosystem has been independently tested.
Section 06
Make the submission a business decision
Have the technical owner confirm the facts and the authorised representative review the answers. If an MSP prepares the questionnaire, ensure the agency understands what it is authorising. A policy saying staff should use managed devices is not evidence that every relevant device is actually managed.
Keep configuration evidence free from unnecessary customer assets, personal information and credentials. Agree a suitable channel where more sensitive detail is needed. Allow time for required changes rather than assuming the assessment review period includes preparation work.
After certification, revisit the scope when the agency moves again, changes its collaboration platform or expands its external team. Retain the certificate with a concise explanation that commercial staff can use accurately. Clear ownership across locations is more valuable than presenting a new office address as proof that the company’s security arrangements are complete.
For freelance projects, record who can approve access extensions when delivery dates change, and who confirms access has ended after handover.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Brighton businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Brighton
Brighton & Hove City Council’s August 2026 workspace announcement addresses creative, cultural and digital organisations. The guide uses changing workspaces and project access as its preparation focus; the council initiative is not a certification or endorsement programme.
Business contexts covered
- Creative agencies
- Digital businesses
- Cultural organisations
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Brighton & Hove City Council: creative workspace initiative - The announced workspace initiative and intended business audiences.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.
Read articleGuides
Cyber Essentials Stevenage: a practical certification guide
Cyber Essentials preparation for a Stevenage business should begin with the organisation’s own systems and the customer’s written requirement. Life-sciences and engineering work can involve shared facilities, external research partners and specialist applications, making responsibilities more important than the postcode of the office.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read article

