Skip to content
Guides

Cyber Essentials Exeter: a practical certification guide

Cyber Essentials can help an Exeter organisation demonstrate a defined baseline of technical security. Before starting, establish whether you are responding to a contractual requirement or choosing certification as part of your own improvement programme. That decision affects the deadline and evidence a buyer expects, but not the national control standard.

a group of buildings with a road in front of

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Exeter: a practical certification guide

Cyber Essentials can help an Exeter organisation demonstrate a defined baseline of technical security. Before starting, establish whether you are responding to a contractual requirement or choosing certification as part of your own improvement programme. That decision affects the deadline and evidence a buyer expects, but not the national control standard.

Section 02

Preparing a research or technology business

Exeter Science Park provides offices, laboratories and support for STEMM businesses. A company working in that environment may depend on a mixture of hosted applications, specialist equipment and external collaborators. The practical certification question is who controls each part of the working environment.

A shared building’s internet service is not an assurance statement about a tenant’s devices. Likewise, a university collaborator’s security policy does not establish how a separate company configures its own cloud accounts. Document those boundaries early so the questionnaire reflects your organisation rather than the whole research partnership.

Section 03

Example: moving a data project into commercial delivery

Consider a small Exeter data-analysis business preparing to supply a commercial customer. Its team has worked with trial cloud accounts and project-specific repositories. It now needs repeatable administration and a clear owner for access. This is an example to support planning, not a reported customer outcome.

Begin by identifying accounts created during research or prototyping. Some may be owned by an individual employee rather than the company. Establish whether the organisation can administer them, enforce the required authentication settings and remove access when a person leaves. Do not assume that using a recognised cloud brand makes every tenant setting compliant.

Check which machines can download or process the project information. A powerful research workstation, a developer laptop and a personally owned tablet used for business email may require different management arrangements. Apply the current scheme scope rules with your assessor instead of limiting the inventory to items bought through the main IT budget.

Next, review specialist applications and supporting components. An analysis environment can contain browsers, package tools, remote access utilities and operating systems with different support lifecycles. Keep an inventory that the person responsible for updates can actually maintain. If a control cannot yet be demonstrated, record a remediation action rather than drafting a more optimistic answer.

Section 04

Keep research assurance separate from certification

Cyber Essentials does not establish scientific validity, research ethics approval or compliance with every requirement governing health information. A research sponsor can ask for additional assurance alongside the certificate. Separate those requests into their respective workstreams so a successful CE assessment is not presented as approval for uses of data it has not assessed.

If your prospect is the Met Office, Devon County Council, an NHS organisation or another public body, obtain that opportunity’s security conditions. This guide does not claim that those organisations impose the same certification rule on every supplier. Check the requested level, scope, evidence date and any permitted equivalent through the official procurement clarification channel.

Section 05

Make your preparation meeting productive

Bring the person who administers your cloud services, the owner of any specialist equipment and the colleague authorised to approve the submission. Use the meeting to resolve ownership, not to circulate confidential datasets. A concise system description and configuration evidence are more useful than an export of research records.

Agree how remote workers and project guests are represented in the assessment. Record which organisation operates shared infrastructure and obtain factual confirmation where you depend on a building provider or IT partner. Outsourcing an activity does not remove the need to understand how the relevant controls are delivered.

After remediation, have the authorised representative review the answers against the actual environment. Preserve the scope record and the buyer’s request with the final certificate. When a prototype becomes a production service, a new laboratory opens or a project introduces another cloud tenant, revisit that record rather than assuming the original answers remain accurate.

Section 06

Can we certify before every wider security project is complete?

You must meet the applicable Cyber Essentials requirements within the agreed scope before certification. Broader improvements can have their own plan, but an outstanding CE requirement cannot be converted into compliance by accepting the risk. Ask about uncertain controls before submission so the assessment is based on implemented measures.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Exeter businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Exeter

Exeter Science Park describes its focus on science, technology, engineering, mathematics and medicine businesses. The guide applies that setting to research collaboration and cloud-service preparation; it does not assert a standard procurement rule for the Met Office, Devon County Council or NHS Devon.

Business contexts covered

  • Science and technology
  • Research services
  • Professional services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig