Skip to content
Guides

Cyber Essentials Cambridge: a practical certification guide

Cambridge companies preparing for Cyber Essentials should be clear about the boundary between the business and the research or investment ecosystem around it. A university connection, science-park address or cloud provider’s certificate does not automatically cover a separate company’s systems.

brown concrete building under blue sky during

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Cambridge: a practical certification guide

Cambridge companies preparing for Cyber Essentials should be clear about the boundary between the business and the research or investment ecosystem around it. A university connection, science-park address or cloud provider’s certificate does not automatically cover a separate company’s systems.

Section 02

Certification for an independently operating business

Cambridge Science Park describes its longstanding role bringing business and academia together. That is useful local context for a guide about research spin-outs and technology companies. It does not establish that every tenant or investor requires Cyber Essentials.

Before assessment, identify the legal entity seeking certification and the systems through which it operates. This can be more involved than counting office laptops if the company still uses services inherited from a research project. Ask which resources are controlled by the business, which belong to a university and which are provided by external partners.

Section 03

Example: a spin-out separating its IT from a research group

Consider an illustrative Cambridge spin-out preparing for an enterprise customer. The founders have company email, but some project material remains in an academic workspace and some applications are accessed through individual accounts. The preparation task is to describe the real arrangements, not the intended future separation.

List each service used for company business and establish who administers it. Identify what happens if an academic affiliation ends or an individual founder becomes unavailable. Confirm whether the company has authority to manage user access and obtain the information needed for its assessment.

Review the devices used to move between those services. A researcher may use the same laptop for academic and company work. Apply the current scope requirements with the assessor rather than assuming that the device is excluded because someone else bought it. Ownership, use and management responsibility need to be described accurately.

If the company plans to move data into a new tenant, distinguish completed migration from work still outstanding. Check for active accounts and applications in the old environment. A migration plan should not be used as evidence that access has already been removed or required settings have been applied.

Section 04

Intellectual property needs more than a badge

Cyber Essentials does not determine ownership of research results, protect every trade secret by itself or certify that a product’s source code is secure. It assesses specified technical controls. Keep legal agreements, product testing and wider information-security measures as separate workstreams where they are required.

When an investor or customer asks about security, provide the certificate with a clear scope explanation and answer additional questions on their own terms. Do not imply that certification means the investor has approved the company or that a research partner’s infrastructure was included in the assessment.

Section 05

Plan evidence gathering around real responsibilities

Bring together the business owner, technical lead and any external IT provider. Decide who can answer questions about corporate services, development tools and specialist equipment. If a provider cannot confirm a setting, treat it as an unresolved item rather than filling the gap with an assumption.

Gather configuration evidence without sharing confidential research, source-code secrets or customer datasets unnecessarily. A system description and factual account of how it is managed are appropriate starting points. Agree a suitable channel for more detailed material when needed.

The person approving the submission should understand the declared boundary and any dependencies on third parties. That remains important even when the questionnaire has been prepared by an experienced MSP. The organisation’s sign-off is not merely a purchasing formality.

Section 06

Choosing CE or Plus

Use the customer’s written requirement and the assurance you want to obtain. Plus provides independent technical verification of the same control areas; it is not automatically required because the company works in science or handles valuable intellectual property. If another scheme is named, confirm that separately before purchase.

After issue, keep the scope record current as the company recruits, moves premises or takes full ownership of previously shared services. Review control changes when they happen, not only at annual renewal. A growing spin-out benefits from a certification record that follows its actual operating model rather than preserving assumptions from its earliest research phase.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Cambridge businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Cambridge

Cambridge Science Park describes its role connecting academia and business. The guide considers the transition from research arrangements to independently managed company systems; it does not imply that park membership or university affiliation provides certification coverage.

Business contexts covered

  • Science businesses
  • Technology companies
  • Research spin-outs

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig