Cyber Essentials Edinburgh: a practical certification guide
An Edinburgh organisation can complete Cyber Essentials through a UK certification body without needing a separate Scottish version of the technical standard. The important distinction is between the national scheme and the particular assurance conditions in a customer’s contract.

Section 01
Cyber Essentials Edinburgh: a practical certification guide
An Edinburgh organisation can complete Cyber Essentials through a UK certification body without needing a separate Scottish version of the technical standard. The important distinction is between the national scheme and the particular assurance conditions in a customer’s contract.
Section 02
Customer assurance in a financial and technology setting
The council’s Economic Needs Study discusses Edinburgh’s financial services, technology and research activity. For suppliers working in those settings, certification may be one part of a wider security response. It should not be presented as approval from a regulator or as proof that every contractual obligation has been audited.
Ask the buyer what it wants to establish. A certificate request can concern the supplier’s corporate IT, while other questions concern the security of a hosted service, incident response or subcontracting. Separate those questions so the same certificate is not used to answer matters beyond its scope.
Section 03
Example: an outsourced service preparing for a renewal review
Consider an Edinburgh consultancy supplying a recurring business service to a financial organisation. Employees use company devices and a client workspace. A renewal questionnaire asks about certification and several other controls. This is an example, not a claim about any named financial firm’s requirements.
Confirm which legal entity supplies the service and whether the customer expects a whole-organisation certificate or another permissible scope. If the business belongs to a group, do not assume the parent’s certificate covers every subsidiary. Compare the requested evidence with the actual certificate boundary.
Next, map access to the client workspace. Establish which organisation administers it, which company devices can reach it and whether information is downloaded elsewhere. Ask the technical owner to explain the controls your organisation operates without claiming that it manages the customer’s entire environment.
Review the joiner and leaver process across both company and client accounts. A departure may require action by two organisations. Record who initiates the customer-side removal and how completion is confirmed. This is especially important when the commercial relationship continues but individual consultants change.
Section 04
Do not treat procurement regimes as interchangeable
For a Scottish public-sector opportunity, read its own published documents and clarification guidance. Do not assume that a central-government procurement note automatically supplies the answer for every devolved or local purchase. The buyer should confirm the certification level, accepted evidence and deadline for that opportunity.
Where a contract permits an equivalent assurance route, ask what evidence the buyer accepts rather than deciding equivalence yourself. Conversely, if Plus is explicitly required, do not present basic CE as meeting the same requirement simply because both use the five control areas.
Section 05
Prepare technical answers that can be defended
Ask IT or the MSP for information specific to the environment being assessed. A group security policy or support contract is not proof that all devices are managed or all cloud settings implemented. Reconcile the policy with actual configuration and staff practice before sign-off.
Keep customer information out of unnecessary evidence exports. A configuration record should not require sharing financial case files, personal records or live credentials. Agree a suitable method if further detail is needed to explain the control.
Resolve outstanding requirements before submission. An accepted business risk or a future improvement plan does not turn an unmet scheme control into a compliant answer. The authorised representative should understand the scope and confirm that the statements reflect the organisation’s current arrangements.
Section 06
Use certification accurately throughout the relationship
After issue, keep the certificate, scope explanation and buyer requirement together. Review the validity before uploading it to a supplier portal and assign responsibility for renewal reminders. Answer additional customer questions using the relevant evidence rather than extending the certificate’s meaning.
If the business changes its delivery model, acquires another service team or introduces a different client-access arrangement, revisit the control information then. Annual certification is easier to maintain when those decisions are recorded as normal business changes instead of reconstructed under the next renewal deadline.
For renewal reviews, agree who can answer follow-up technical questions when the commercial account owner does not administer the systems.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Edinburgh businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Edinburgh
Edinburgh’s Economic Needs Study discusses financial services, technology and research-related activity. This provides a local setting for supplier assurance; it does not establish that every regulated customer or Scottish public-sector contract requires the same certification.
Business contexts covered
- Financial services suppliers
- Technology companies
- Research businesses
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- City of Edinburgh Council: Economic Needs Study - The economic study’s financial, technology and research context.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.
Read articleGuides
Cyber Essentials Leeds: a practical certification guide
For a Leeds organisation, Cyber Essentials is most useful when the certificate answers a clear customer question and accurately describes the business assessed. Before beginning, establish whether a prospect wants the basic certification, independent technical verification through Plus, or additional assurance beyond either scheme.
Read articleGuides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read article

