Skip to content
Guides

Cyber Essentials Dundee: a practical certification guide

A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.

A large body of water with a city in the back

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Dundee: a practical certification guide

A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.

Section 02

A relevant creative-industry setting

Dundee City Council’s screen-industry update discusses production services and games/screen convergence across the wider Fife Tay region. That provides context for a guide about collaborative studio work. It does not establish that every publisher, commissioner or project partner requires CE or Plus.

Before assessment, obtain the actual buyer request. Identify the organisation to be certified and whether the customer also wants product testing, development-process evidence or specific contractual controls. Those requests should be tracked separately rather than answered with a single broad security claim.

Section 03

Example: a studio using external artists and build services

Imagine a Dundee company whose employees and external artists collaborate through asset storage, source repositories and hosted build services. It wants certification before a new commercial engagement. This is an illustrative scenario, not a description of a Fig customer or a named publisher’s rules.

Begin with an account inventory. Identify who owns each service, who can administer it and which collaborators retain access. A tool adopted for one project may continue operating through an individual account long after the team grows. Confirm that the organisation can manage access and remove it when the role ends.

Review the devices used for business work, including specialist workstations and any personally owned equipment relevant under the current scope rules. Do not limit the inventory to standard office laptops if artists and developers use different systems. Ask the assessor about uncertain arrangements before completing the questionnaire.

Check supporting software as well as the headline creative tools. Plug-ins, browsers, remote utilities and operating systems can have different support lifecycles. Record who tracks those dependencies and implements required updates. A current subscription to the main application is not proof that the whole workstation is supported.

Section 04

Keep secrets and unreleased material out of general evidence

Use sanitised configuration records when explaining controls. Do not paste signing credentials, repository tokens or unreleased assets into a general enquiry. If a more detailed discussion is needed, agree the purpose and a suitable transfer channel.

Cyber Essentials is not a source-code audit or a review of every build-system permission. If a customer requests a penetration test or code-security review, scope that activity separately. Certification of the organisation should not be marketed as independent testing of every release.

Section 05

Fit access management to the project lifecycle

Agree how the business is notified when an external specialist finishes. Someone should own removal from company systems and the request to close customer-controlled accounts. A production manager’s knowledge that work has ended is not enough if no technical action follows.

Review old project spaces before submission. Establish which services remain in use, which accounts are unnecessary and who can approve changes. Where a control needs remediation, complete it before the authorised representative signs off the assessment. A future clean-up task does not describe the current environment accurately.

Section 06

Choosing the right route in Scotland

The Cyber Essentials technical standard is UK-wide. For a Scottish public-sector opportunity, check the specific tender’s requirements and clarification route; do not assume that an unrelated central-government policy or another studio’s experience determines the answer.

Confirm whether CE or Plus is requested and allow separate time for any technical audit. Keep preparation effort distinct from the review time for a compliant self-assessment. Customer deadlines often also depend on internal approval and project access arrangements.

After issue, retain the certificate with a clear scope explanation. Revisit the inventory when a new project adds another repository, build service or external team. This makes renewal a review of current controls rather than a reconstruction of a year’s worth of informal tool and account decisions.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Dundee businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Dundee

Dundee City Council’s September 2026 screen-industry update discusses production services and games/screen convergence in the wider Fife Tay region. The guide uses studio collaboration as an example, not as evidence of a mandatory certification policy from publishers or commissioners.

Business contexts covered

  • Games businesses
  • Screen production
  • Digital services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig