Cyber Essentials Cambridge: a practical certification guide
Cambridge companies preparing for Cyber Essentials should be clear about the boundary between the business and the research or investment ecosystem around it. A university connection, science-park address or cloud provider’s certificate does not automatically cover a separate company’s systems.

Section 01
Cyber Essentials Cambridge: a practical certification guide
Cambridge companies preparing for Cyber Essentials should be clear about the boundary between the business and the research or investment ecosystem around it. A university connection, science-park address or cloud provider’s certificate does not automatically cover a separate company’s systems.
Section 02
Certification for an independently operating business
Cambridge Science Park describes its longstanding role bringing business and academia together. That is useful local context for a guide about research spin-outs and technology companies. It does not establish that every tenant or investor requires Cyber Essentials.
Before assessment, identify the legal entity seeking certification and the systems through which it operates. This can be more involved than counting office laptops if the company still uses services inherited from a research project. Ask which resources are controlled by the business, which belong to a university and which are provided by external partners.
Section 03
Example: a spin-out separating its IT from a research group
Consider an illustrative Cambridge spin-out preparing for an enterprise customer. The founders have company email, but some project material remains in an academic workspace and some applications are accessed through individual accounts. The preparation task is to describe the real arrangements, not the intended future separation.
List each service used for company business and establish who administers it. Identify what happens if an academic affiliation ends or an individual founder becomes unavailable. Confirm whether the company has authority to manage user access and obtain the information needed for its assessment.
Review the devices used to move between those services. A researcher may use the same laptop for academic and company work. Apply the current scope requirements with the assessor rather than assuming that the device is excluded because someone else bought it. Ownership, use and management responsibility need to be described accurately.
If the company plans to move data into a new tenant, distinguish completed migration from work still outstanding. Check for active accounts and applications in the old environment. A migration plan should not be used as evidence that access has already been removed or required settings have been applied.
Section 04
Intellectual property needs more than a badge
Cyber Essentials does not determine ownership of research results, protect every trade secret by itself or certify that a product’s source code is secure. It assesses specified technical controls. Keep legal agreements, product testing and wider information-security measures as separate workstreams where they are required.
When an investor or customer asks about security, provide the certificate with a clear scope explanation and answer additional questions on their own terms. Do not imply that certification means the investor has approved the company or that a research partner’s infrastructure was included in the assessment.
Section 05
Plan evidence gathering around real responsibilities
Bring together the business owner, technical lead and any external IT provider. Decide who can answer questions about corporate services, development tools and specialist equipment. If a provider cannot confirm a setting, treat it as an unresolved item rather than filling the gap with an assumption.
Gather configuration evidence without sharing confidential research, source-code secrets or customer datasets unnecessarily. A system description and factual account of how it is managed are appropriate starting points. Agree a suitable channel for more detailed material when needed.
The person approving the submission should understand the declared boundary and any dependencies on third parties. That remains important even when the questionnaire has been prepared by an experienced MSP. The organisation’s sign-off is not merely a purchasing formality.
Section 06
Choosing CE or Plus
Use the customer’s written requirement and the assurance you want to obtain. Plus provides independent technical verification of the same control areas; it is not automatically required because the company works in science or handles valuable intellectual property. If another scheme is named, confirm that separately before purchase.
After issue, keep the scope record current as the company recruits, moves premises or takes full ownership of previously shared services. Review control changes when they happen, not only at annual renewal. A growing spin-out benefits from a certification record that follows its actual operating model rather than preserving assumptions from its earliest research phase.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Cambridge businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Cambridge
Cambridge Science Park describes its role connecting academia and business. The guide considers the transition from research arrangements to independently managed company systems; it does not imply that park membership or university affiliation provides certification coverage.
Business contexts covered
- Science businesses
- Technology companies
- Research spin-outs
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Cambridge Science Park: our story - The park’s academia-industry role.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read articleGuides
Cyber Essentials Nottingham: a practical certification guide
For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.
Read articleGuides
Cyber Essentials Oxford: a practical certification guide
For an Oxford organisation, the value of Cyber Essentials depends on a clear scope and truthful answers about how its systems are managed. Research partnerships and specialist facilities can make that boundary less obvious than a single office address suggests.
Read article

