Skip to content
Guides

Cyber Essentials Cardiff: a practical certification guide

A Cardiff company may encounter Cyber Essentials in a tender, a partner review or its own security improvement programme. Start by establishing which of those situations applies. A customer deadline and a voluntary improvement goal need different planning, even though the national technical controls remain the same.

A seagull perches on a bridge rail

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Cardiff: a practical certification guide

A Cardiff company may encounter Cyber Essentials in a tender, a partner review or its own security improvement programme. Start by establishing which of those situations applies. A customer deadline and a voluntary improvement goal need different planning, even though the national technical controls remain the same.

Section 02

A regional context for supplier assurance

Cardiff Capital Region describes financial technology, creative activity and cybersecurity within the regional economy. That gives a useful setting for a guide about businesses serving several kinds of customer. It does not mean every Cardiff supplier has the same assurance obligations.

Ask each buyer to provide its actual requirement. A financial customer may request wider controls alongside certification, while a creative commission may focus on access to project material. Keep those requirements distinct. A CE certificate should not be used to imply regulatory approval or comprehensive assurance for every service the company offers.

Section 03

Example: a digital supplier with several service lines

Imagine a Cardiff business offering website development, hosted support and project consultancy. Different teams use different cloud tools, and one customer asks for certification. This is a planning scenario, not a claim about a named local company or Fig customer.

First, confirm the legal entity and proposed assessment scope. Do not assume the certificate covers only the team whose customer asked for it, or that it automatically covers every related business sharing the brand. Settle the permissible boundary with the assessor before gathering answers.

Next, inventory the services used across that boundary. Development repositories, customer-support tools and ordinary business email may have different administrators. Identify which accounts can access business information and whether the organisation can manage them consistently. A tool introduced by one team can be missed by an inventory based only on the main IT contract.

Compare the declared controls with daily practice. If the policy says only managed devices can access business data, check how consultants and external specialists actually work. Resolve differences before sign-off rather than relying on a policy statement that does not describe implementation.

Section 04

Welsh procurement: use the opportunity documents

For a Welsh public-sector tender, read the specific security conditions and use its official clarification process. Do not assume an unrelated central-government note determines every local or devolved purchase. Confirm the certificate level, accepted evidence and deadline with the buyer.

If the requirement mentions subcontractors, establish what evidence is expected from them. Your certificate does not automatically certify independent delivery partners. Equally, a subcontractor’s certificate does not establish the controls across your own organisation.

Section 05

Coordinate technical answers without sharing unnecessary data

Ask the responsible teams for factual information about device management, cloud settings, supported software and administrator access. An MSP can help prepare the questionnaire, but the business must review and authorise the submission. Identify the signatory early enough to resolve questions before the customer deadline.

Keep evidence focused on controls. Avoid including customer website credentials, financial information or confidential project content in a general enquiry. Use sanitised configuration records and agree an appropriate transfer channel if more detail is needed.

Where remediation is required, assign an owner and confirm completion before declaring compliance. A plan to consolidate tools or replace software is not the same as an implemented control. Build time for that work into the schedule separately from assessment review.

Section 06

A certificate that supports several customer relationships

After issue, retain a scope explanation with the certificate. Check the entity, validity and requested level before sharing it with each buyer. If one customer requires Plus or separate testing, address that explicitly rather than assuming the basic certificate is sufficient for every service line.

Review the inventory when another service is launched, a team adopts a new platform or the business changes its delivery partners. Those changes can affect the accuracy of the assessment answers between renewals. Maintaining a clear record of ownership and scope makes certification useful across the business without turning it into an unsupported claim that all products and partnerships are independently certified secure.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Cardiff businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Cardiff

Cardiff Capital Region describes financial technology, creative activity and cybersecurity within its regional economy. The guide applies that context to a supplier serving multiple customers; regional priorities do not establish mandatory certification for each business.

Business contexts covered

  • Financial technology
  • Creative businesses
  • Cybersecurity suppliers

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig