Cyber Essentials Dundee: a practical certification guide
A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.

Section 01
Cyber Essentials Dundee: a practical certification guide
A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.
Section 02
A relevant creative-industry setting
Dundee City Council’s screen-industry update discusses production services and games/screen convergence across the wider Fife Tay region. That provides context for a guide about collaborative studio work. It does not establish that every publisher, commissioner or project partner requires CE or Plus.
Before assessment, obtain the actual buyer request. Identify the organisation to be certified and whether the customer also wants product testing, development-process evidence or specific contractual controls. Those requests should be tracked separately rather than answered with a single broad security claim.
Section 03
Example: a studio using external artists and build services
Imagine a Dundee company whose employees and external artists collaborate through asset storage, source repositories and hosted build services. It wants certification before a new commercial engagement. This is an illustrative scenario, not a description of a Fig customer or a named publisher’s rules.
Begin with an account inventory. Identify who owns each service, who can administer it and which collaborators retain access. A tool adopted for one project may continue operating through an individual account long after the team grows. Confirm that the organisation can manage access and remove it when the role ends.
Review the devices used for business work, including specialist workstations and any personally owned equipment relevant under the current scope rules. Do not limit the inventory to standard office laptops if artists and developers use different systems. Ask the assessor about uncertain arrangements before completing the questionnaire.
Check supporting software as well as the headline creative tools. Plug-ins, browsers, remote utilities and operating systems can have different support lifecycles. Record who tracks those dependencies and implements required updates. A current subscription to the main application is not proof that the whole workstation is supported.
Section 04
Keep secrets and unreleased material out of general evidence
Use sanitised configuration records when explaining controls. Do not paste signing credentials, repository tokens or unreleased assets into a general enquiry. If a more detailed discussion is needed, agree the purpose and a suitable transfer channel.
Cyber Essentials is not a source-code audit or a review of every build-system permission. If a customer requests a penetration test or code-security review, scope that activity separately. Certification of the organisation should not be marketed as independent testing of every release.
Section 05
Fit access management to the project lifecycle
Agree how the business is notified when an external specialist finishes. Someone should own removal from company systems and the request to close customer-controlled accounts. A production manager’s knowledge that work has ended is not enough if no technical action follows.
Review old project spaces before submission. Establish which services remain in use, which accounts are unnecessary and who can approve changes. Where a control needs remediation, complete it before the authorised representative signs off the assessment. A future clean-up task does not describe the current environment accurately.
Section 06
Choosing the right route in Scotland
The Cyber Essentials technical standard is UK-wide. For a Scottish public-sector opportunity, check the specific tender’s requirements and clarification route; do not assume that an unrelated central-government policy or another studio’s experience determines the answer.
Confirm whether CE or Plus is requested and allow separate time for any technical audit. Keep preparation effort distinct from the review time for a compliant self-assessment. Customer deadlines often also depend on internal approval and project access arrangements.
After issue, retain the certificate with a clear scope explanation. Revisit the inventory when a new project adds another repository, build service or external team. This makes renewal a review of current controls rather than a reconstruction of a year’s worth of informal tool and account decisions.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Dundee businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Dundee
Dundee City Council’s September 2026 screen-industry update discusses production services and games/screen convergence in the wider Fife Tay region. The guide uses studio collaboration as an example, not as evidence of a mandatory certification policy from publishers or commissioners.
Business contexts covered
- Games businesses
- Screen production
- Digital services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Dundee City Council: film and TV production update - Regional screen activity and games/screen convergence; not a Dundee-only market total.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read articleGuides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read articleGuides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read article

