Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.

Section 01
Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.
Section 02
Project-based businesses in Glasgow
The city’s Economic Strategy identifies digital technology, creative activity and business services among its priorities. Those sectors provide a relevant context for examining temporary teams and shared project services. They do not establish one certification rule for every Glasgow buyer.
Begin with the service being sold and the customer’s written requirement. Confirm whether it asks for CE, Plus or additional assurance such as product testing. Identify the entity that will contract with the customer and appear on the certificate. Shared branding across partner organisations does not establish shared certification coverage.
Section 03
Example: a production business assembling project teams
Imagine a Glasgow creative company that brings in specialists for a time-limited project. It uses company laptops, hosted collaboration and a customer asset portal. This is a planning example, not a claim about a particular broadcaster or Fig customer.
List the services used for business work and the accounts with continuing access. Distinguish an external recipient of a finished deliverable from a collaborator who can enter the company’s workspace. Ask the assessor how the current requirements apply to each arrangement rather than assuming that everyone called a freelancer is outside scope.
Check how project accounts are created and closed. A producer may know a specialist has finished while IT has not received the instruction to remove access. Agree the trigger and owner for that action. Review old projects as well as the current one so the inventory reflects access that remains active.
For specialist software, identify the supporting operating system, plug-ins and remote tools. A creative application can be current while another component on the same device is unsupported. Gather factual information from the person managing the workstation, not just the purchasing record for the main software licence.
Section 04
Distinguish customer requirements from production deadlines
A customer may ask for certification before releasing assets or completing onboarding. Obtain the actual evidence deadline and level required. Do not interpret an informal request for a secure supplier as confirmation that any particular certificate will be accepted.
For public-sector opportunities in Scotland, use the tender documents and official clarification route. This guide does not claim that every Glasgow council, education or cultural contract requires CE. Different buyers and services can have different assurance conditions.
Section 05
Prepare without exposing confidential material
Use configuration records and sanitised system descriptions where possible. Do not place unreleased creative assets, personal information or customer credentials in a general enquiry. If a more detailed explanation is needed, agree an appropriate transfer method and confirm that disclosure is authorised.
The assessment should describe the company’s implemented controls. A contract requiring freelancers to behave securely is not automatically evidence of the settings on a relevant device or account. Resolve uncertainty with the technical owner and assessor before the organisation signs off the questionnaire.
Section 06
Keep the certificate’s boundaries visible
Cyber Essentials does not certify the quality of a production, the security of every customer portal or every independent partner business. Share the certificate with its scope explanation and avoid claiming that a whole project ecosystem has been assessed.
If a buyer asks for additional testing, agree that work separately. A certificate is not permission to scan a customer’s platform, and CE is not a replacement for a penetration test where one is required.
After issue, maintain the account closure and software management processes through the next project cycle. New collaborators, hired equipment and additional cloud tools can change the environment before renewal. Reviewing those changes as part of project mobilisation and close-out makes the annual assessment more accurate and reduces the need to reconstruct decisions later.
Include account closure in the production handover so temporary project access does not depend on a producer remembering every invitation.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Glasgow businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Glasgow
Glasgow’s Economic Strategy identifies digital technology, creative activity and business services among its sector priorities. The guide uses project-based delivery as a practical setting without suggesting that the strategy imposes a Cyber Essentials requirement.
Business contexts covered
- Digital services
- Creative production
- Business services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Glasgow City Council: Economic Strategy - The strategy’s digital, creative and business-services priorities.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Brighton: a practical certification guide
A Brighton agency or digital business does not need a traditional fixed office to approach Cyber Essentials, but it does need a clear account of the systems used for work. Shared workspace, home working and external collaborators should be considered through the current scope requirements rather than treated as reasons to leave parts of the business unexplained.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read articleGuides
Cyber Essentials Stevenage: a practical certification guide
Cyber Essentials preparation for a Stevenage business should begin with the organisation’s own systems and the customer’s written requirement. Life-sciences and engineering work can involve shared facilities, external research partners and specialist applications, making responsibilities more important than the postcode of the office.
Read article

