Skip to content
Guides

Cyber Essentials Derby: a practical certification guide

For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.

a view of a city with tall buildings

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Derby: a practical certification guide

For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.

Section 02

Engineering context, not a blanket buyer mandate

Derby City Council’s Team Derby announcement identifies strengths in rail, aerospace, nuclear and advanced manufacturing. Those sectors provide a relevant context for thinking about supplier security. They do not establish that Rolls-Royce, Alstom, Toyota or every local subcontractor applies the same CE requirement.

Ask the commercial owner to retrieve the actual customer security schedule. Identify the entity providing the work, the requested certificate and the acceptance deadline. Where multiple customers ask for different assurance, keep a requirement register rather than treating the most familiar request as the answer to every contract.

Section 03

Example: an engineering team with field-service laptops

An illustrative Derby supplier has design workstations in its office and service laptops used at customer sites. Some laptops connect to customer equipment and others are used for business email or vendor support. Before answering the questionnaire, establish their roles and connectivity rather than grouping every device under a single description.

Check whether a field laptop returns to the organisation’s normal management process after a site visit. Identify who monitors software support, applies required updates and removes temporary accounts. Equipment that spends time away from the office can otherwise disappear from a report that only shows recently connected devices.

A customer may restrict changes on equipment used at its site. Resolve that constraint with the operational owner and assessor early. Do not assume that a customer preference automatically provides an exception to a scheme requirement. Nor should a certification deadline lead to an untested change on safety-relevant equipment. The scope, applicable requirements and safe change process need to be settled together.

Maintain a record of the device, business purpose, responsible administrator and completed actions. Keep customer engineering data out of general-purpose evidence exports. Where sensitive support arrangements need explanation, agree a suitable channel for the discussion.

Section 04

Separate technical baseline from engineering assurance

Cyber Essentials is not a rail safety approval, aerospace quality certification or a complete review of industrial control systems. It assesses specified technical controls within its scope. A customer can still require engineering standards, contractual security measures or specialist testing that sit outside the scheme.

The same distinction applies to defence work. If the contract names a Defence Cyber Certification level, confirm that requirement against the MOD Cyber Security Model and the contract’s risk profile. Do not substitute CE Plus because the names sound similar or assume DCC applies simply because your business supplies an engineering company.

Section 05

Questions for a shared IT team

If group IT administers several legal entities, ask which policies and systems apply to the entity being certified. A group-wide endpoint product does not show that every device is enrolled or that every subsidiary follows the same account process. Obtain evidence at the correct boundary.

For design software, identify supporting applications and plug-ins as well as the headline CAD package. For supplier portals, establish who owns accounts and how access is removed when a project ends. For remote support, identify the approved tools and administrator responsibilities. These checks help align answers from engineering, IT and commercial teams before sign-off.

Section 06

Plan the assessment around delivery commitments

Work backwards from the customer’s evidence deadline. Allow separate time for scope clarification, controlled remediation, internal review and any required Plus testing. The time taken to assess a compliant questionnaire is not the time needed to upgrade a complex engineering environment.

Once certified, keep the certificate and a short scope explanation in the supplier-assurance record. Review the control information when a new customer project introduces another remote connection, a workshop changes its systems or the business acquires a separate network. Reusing accurate evidence is helpful; reusing answers after the environment changes is not.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Derby businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Derby

Derby City Council’s Team Derby announcement identifies rail, aerospace, nuclear and advanced manufacturing strengths. The guide uses engineering delivery as its preparation context, without asserting universal CE or Plus requirements from individual manufacturers.

Business contexts covered

  • Rail engineering
  • Aerospace supply chains
  • Advanced manufacturing

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig