Skip to content
Guides

Cyber Essentials Brighton: a practical certification guide

A Brighton agency or digital business does not need a traditional fixed office to approach Cyber Essentials, but it does need a clear account of the systems used for work. Shared workspace, home working and external collaborators should be considered through the current scope requirements rather than treated as reasons to leave parts of the business unexplained.

a view of a crowded beach from a pier

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Brighton: a practical certification guide

A Brighton agency or digital business does not need a traditional fixed office to approach Cyber Essentials, but it does need a clear account of the systems used for work. Shared workspace, home working and external collaborators should be considered through the current scope requirements rather than treated as reasons to leave parts of the business unexplained.

Section 02

Creative work across different locations

Brighton & Hove City Council’s workspace announcement addresses creative, cultural and digital organisations. It provides a local setting for a guide about changing workplaces and shared facilities. It does not establish certification requirements for participants or endorsement of a certification provider.

The location of a desk is only one part of the environment. Identify the cloud services, devices and accounts used to deliver the customer’s work. Ask who manages them and what information moves between company systems and customer platforms.

Section 03

Example: an agency moving into shared workspace

Imagine a Brighton company whose staff have worked remotely and are taking shared office space. It uses company laptops, freelance collaborators and hosted project tools. A customer has asked for certification. This is a planning example, not a report of a named agency or Fig engagement.

Start by separating the workspace provider’s services from the agency’s responsibilities. Establish who manages connectivity and any shared network equipment. Do not assume that a professionally operated building configures your cloud accounts, updates your laptops or manages your project users.

Review the working arrangements that remain outside the new office. Staff may still access business email and customer assets from home or while travelling. Discuss relevant devices and scope with the assessor rather than assuming the move makes the organisation an office-only environment.

Check external collaborator access across active and completed projects. A project manager may close the commercial job while an account remains in storage or a customer portal. Assign responsibility for ending access and confirming any customer-controlled action.

Section 04

Keep the technical inventory practical

List the services that actually store or process business information. Include tools adopted by individual teams, not just those on the main software subscription list. Confirm that the organisation can administer access and apply the required settings.

Review specialist creative applications and supporting components on workstations. An up-to-date main application does not establish that every plug-in, browser or operating system remains supported. Ask the responsible technical person for factual information and complete remediation where needed before submission.

Section 05

Respond accurately to customer assurance requests

Obtain the exact level, certified entity and deadline from the buyer. Do not assume that every brand, public body or cultural commissioner asks for the same evidence. If the request includes product testing, privacy obligations or other assurance, track those separately from the CE certificate.

Cyber Essentials does not certify every website the agency builds or every customer platform it accesses. It assesses a defined organisational technical baseline. Explain that scope when using the certificate in a proposal instead of implying the whole project ecosystem has been independently tested.

Section 06

Make the submission a business decision

Have the technical owner confirm the facts and the authorised representative review the answers. If an MSP prepares the questionnaire, ensure the agency understands what it is authorising. A policy saying staff should use managed devices is not evidence that every relevant device is actually managed.

Keep configuration evidence free from unnecessary customer assets, personal information and credentials. Agree a suitable channel where more sensitive detail is needed. Allow time for required changes rather than assuming the assessment review period includes preparation work.

After certification, revisit the scope when the agency moves again, changes its collaboration platform or expands its external team. Retain the certificate with a concise explanation that commercial staff can use accurately. Clear ownership across locations is more valuable than presenting a new office address as proof that the company’s security arrangements are complete.

For freelance projects, record who can approve access extensions when delivery dates change, and who confirms access has ended after handover.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Brighton businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Brighton

Brighton & Hove City Council’s August 2026 workspace announcement addresses creative, cultural and digital organisations. The guide uses changing workspaces and project access as its preparation focus; the council initiative is not a certification or endorsement programme.

Business contexts covered

  • Creative agencies
  • Digital businesses
  • Cultural organisations

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig