Skip to content
Guides

Cyber Essentials Edinburgh: a practical certification guide

An Edinburgh organisation can complete Cyber Essentials through a UK certification body without needing a separate Scottish version of the technical standard. The important distinction is between the national scheme and the particular assurance conditions in a customer’s contract.

a group of people walking down a street next

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Edinburgh: a practical certification guide

An Edinburgh organisation can complete Cyber Essentials through a UK certification body without needing a separate Scottish version of the technical standard. The important distinction is between the national scheme and the particular assurance conditions in a customer’s contract.

Section 02

Customer assurance in a financial and technology setting

The council’s Economic Needs Study discusses Edinburgh’s financial services, technology and research activity. For suppliers working in those settings, certification may be one part of a wider security response. It should not be presented as approval from a regulator or as proof that every contractual obligation has been audited.

Ask the buyer what it wants to establish. A certificate request can concern the supplier’s corporate IT, while other questions concern the security of a hosted service, incident response or subcontracting. Separate those questions so the same certificate is not used to answer matters beyond its scope.

Section 03

Example: an outsourced service preparing for a renewal review

Consider an Edinburgh consultancy supplying a recurring business service to a financial organisation. Employees use company devices and a client workspace. A renewal questionnaire asks about certification and several other controls. This is an example, not a claim about any named financial firm’s requirements.

Confirm which legal entity supplies the service and whether the customer expects a whole-organisation certificate or another permissible scope. If the business belongs to a group, do not assume the parent’s certificate covers every subsidiary. Compare the requested evidence with the actual certificate boundary.

Next, map access to the client workspace. Establish which organisation administers it, which company devices can reach it and whether information is downloaded elsewhere. Ask the technical owner to explain the controls your organisation operates without claiming that it manages the customer’s entire environment.

Review the joiner and leaver process across both company and client accounts. A departure may require action by two organisations. Record who initiates the customer-side removal and how completion is confirmed. This is especially important when the commercial relationship continues but individual consultants change.

Section 04

Do not treat procurement regimes as interchangeable

For a Scottish public-sector opportunity, read its own published documents and clarification guidance. Do not assume that a central-government procurement note automatically supplies the answer for every devolved or local purchase. The buyer should confirm the certification level, accepted evidence and deadline for that opportunity.

Where a contract permits an equivalent assurance route, ask what evidence the buyer accepts rather than deciding equivalence yourself. Conversely, if Plus is explicitly required, do not present basic CE as meeting the same requirement simply because both use the five control areas.

Section 05

Prepare technical answers that can be defended

Ask IT or the MSP for information specific to the environment being assessed. A group security policy or support contract is not proof that all devices are managed or all cloud settings implemented. Reconcile the policy with actual configuration and staff practice before sign-off.

Keep customer information out of unnecessary evidence exports. A configuration record should not require sharing financial case files, personal records or live credentials. Agree a suitable method if further detail is needed to explain the control.

Resolve outstanding requirements before submission. An accepted business risk or a future improvement plan does not turn an unmet scheme control into a compliant answer. The authorised representative should understand the scope and confirm that the statements reflect the organisation’s current arrangements.

Section 06

Use certification accurately throughout the relationship

After issue, keep the certificate, scope explanation and buyer requirement together. Review the validity before uploading it to a supplier portal and assign responsibility for renewal reminders. Answer additional customer questions using the relevant evidence rather than extending the certificate’s meaning.

If the business changes its delivery model, acquires another service team or introduces a different client-access arrangement, revisit the control information then. Annual certification is easier to maintain when those decisions are recorded as normal business changes instead of reconstructed under the next renewal deadline.

For renewal reviews, agree who can answer follow-up technical questions when the commercial account owner does not administer the systems.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Edinburgh businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Edinburgh

Edinburgh’s Economic Needs Study discusses financial services, technology and research-related activity. This provides a local setting for supplier assurance; it does not establish that every regulated customer or Scottish public-sector contract requires the same certification.

Business contexts covered

  • Financial services suppliers
  • Technology companies
  • Research businesses

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig