Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.

Section 01
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Section 02
Engineering context, not a blanket buyer mandate
Derby City Council’s Team Derby announcement identifies strengths in rail, aerospace, nuclear and advanced manufacturing. Those sectors provide a relevant context for thinking about supplier security. They do not establish that Rolls-Royce, Alstom, Toyota or every local subcontractor applies the same CE requirement.
Ask the commercial owner to retrieve the actual customer security schedule. Identify the entity providing the work, the requested certificate and the acceptance deadline. Where multiple customers ask for different assurance, keep a requirement register rather than treating the most familiar request as the answer to every contract.
Section 03
Example: an engineering team with field-service laptops
An illustrative Derby supplier has design workstations in its office and service laptops used at customer sites. Some laptops connect to customer equipment and others are used for business email or vendor support. Before answering the questionnaire, establish their roles and connectivity rather than grouping every device under a single description.
Check whether a field laptop returns to the organisation’s normal management process after a site visit. Identify who monitors software support, applies required updates and removes temporary accounts. Equipment that spends time away from the office can otherwise disappear from a report that only shows recently connected devices.
A customer may restrict changes on equipment used at its site. Resolve that constraint with the operational owner and assessor early. Do not assume that a customer preference automatically provides an exception to a scheme requirement. Nor should a certification deadline lead to an untested change on safety-relevant equipment. The scope, applicable requirements and safe change process need to be settled together.
Maintain a record of the device, business purpose, responsible administrator and completed actions. Keep customer engineering data out of general-purpose evidence exports. Where sensitive support arrangements need explanation, agree a suitable channel for the discussion.
Section 04
Separate technical baseline from engineering assurance
Cyber Essentials is not a rail safety approval, aerospace quality certification or a complete review of industrial control systems. It assesses specified technical controls within its scope. A customer can still require engineering standards, contractual security measures or specialist testing that sit outside the scheme.
The same distinction applies to defence work. If the contract names a Defence Cyber Certification level, confirm that requirement against the MOD Cyber Security Model and the contract’s risk profile. Do not substitute CE Plus because the names sound similar or assume DCC applies simply because your business supplies an engineering company.
Section 05
Questions for a shared IT team
If group IT administers several legal entities, ask which policies and systems apply to the entity being certified. A group-wide endpoint product does not show that every device is enrolled or that every subsidiary follows the same account process. Obtain evidence at the correct boundary.
For design software, identify supporting applications and plug-ins as well as the headline CAD package. For supplier portals, establish who owns accounts and how access is removed when a project ends. For remote support, identify the approved tools and administrator responsibilities. These checks help align answers from engineering, IT and commercial teams before sign-off.
Section 06
Plan the assessment around delivery commitments
Work backwards from the customer’s evidence deadline. Allow separate time for scope clarification, controlled remediation, internal review and any required Plus testing. The time taken to assess a compliant questionnaire is not the time needed to upgrade a complex engineering environment.
Once certified, keep the certificate and a short scope explanation in the supplier-assurance record. Review the control information when a new customer project introduces another remote connection, a workshop changes its systems or the business acquires a separate network. Reusing accurate evidence is helpful; reusing answers after the environment changes is not.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Derby businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Derby
Derby City Council’s Team Derby announcement identifies rail, aerospace, nuclear and advanced manufacturing strengths. The guide uses engineering delivery as its preparation context, without asserting universal CE or Plus requirements from individual manufacturers.
Business contexts covered
- Rail engineering
- Aerospace supply chains
- Advanced manufacturing
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Derby City Council: Team Derby - The city’s identified industrial strengths.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Bradford: a practical certification guide
Bradford businesses with several sites or different working teams should agree the Cyber Essentials scope before collecting answers. A certificate based on a head-office assumption can be difficult to use accurately if the organisation’s warehouse, workshop or remote staff operate through different systems.
Read articleGuides
Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.
Read articleGuides
Cyber Essentials Aberdeen: a practical certification guide
Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.
Read article

