Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.

Section 01
Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.
Section 02
Local specialisms, practical preparation
Guildford Borough Council’s Economic Development Strategy identifies video games, space technology and professional services among the area’s specialisms. This provides context for a guide about distributed development and external support. It does not establish identical certification requirements across those industries.
Retrieve the actual customer request before choosing a route. Confirm whether the buyer wants CE, Plus or additional testing, which legal entity needs the certificate and when it must be available. A partner badge or research-park address does not answer those questions.
Section 03
Example: a development business using external specialists
Consider a Guildford company with an internal development team and external specialists who join projects for defined periods. It uses company cloud services, customer repositories and a hosted support platform. This is a planning example, not a claim about a named publisher or Fig customer.
Begin by identifying the accounts and services the company administers. Record which external people retain access and what devices they use for business work. Discuss uncertain scope with the assessor rather than treating all contractors as automatically excluded.
Review how access is closed when a milestone or contract ends. A delivery manager may know a specialist has finished while the account remains active in another team’s platform. Assign responsibility for notifying administrators and confirming the relevant access changes.
Check specialist applications, plug-ins and remote-support tools on development devices. The main application’s licence or update status does not describe every supporting component. Ask the technical owner to confirm software support and the process for applying required updates across the actual estate.
Section 04
Development security needs its own evidence
Cyber Essentials does not assess every source-code change, design decision or product permission model. If a customer asks for code review, penetration testing or assurance about a specialist system, define that work separately. Explain what each activity covers instead of using one certificate as a shorthand for all of them.
For customer-controlled repositories or platforms, distinguish the customer’s administration responsibilities from your responsibility for company users and endpoints. Your certificate should not imply that the customer’s entire infrastructure was included in the assessment.
Section 05
Prepare a scope record the commercial team can use
Name the entity, service boundary and principal systems. Record the buyer’s requested evidence and any clarification. If the company is part of a group, check whether related entities and shared services are included under the proposed arrangement rather than assuming a common brand provides coverage.
Bring corporate IT, development and the external support provider together where their responsibilities overlap. The organisation needs accurate answers across the scope, not separate statements that each team has completed its own checklist. Resolve gaps before the authorised representative reviews and signs off the submission.
Keep evidence proportionate. Configuration information should not expose customer source code, live secrets or unreleased assets unnecessarily. Agree a suitable channel for any sensitive detail needed to explain a control.
Section 06
Allow time for changes before assessment
If software needs upgrading or account arrangements need restructuring, schedule that work before the buyer’s deadline. A future remediation task is not an implemented control. Plus testing also requires separate arrangements; the review time for a compliant CE questionnaire does not describe the whole technical-audit process.
After certification, keep the scope explanation with the certificate and revisit it when new projects introduce additional services or external teams. Check the certificate’s entity, validity and level before using it in another supplier response. Accurate boundaries make assurance more credible than broad claims that every product and partner in a Guildford technology business is certified secure.
For external developers, distinguish access to project repositories from access to business administration, and document who approves changes to each.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Guildford businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Guildford
Guildford Borough Council’s Economic Development Strategy identifies video games, space technology and professional services among local specialisms. The guide uses external development and support access as its preparation focus, not a claim about publisher or research-park procurement conditions.
Business contexts covered
- Games development
- Space technology
- Professional services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Guildford Borough Council: Economic Development Strategy - The strategy’s local sector specialisms.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read articleGuides
Cyber Essentials Belfast: a practical certification guide
Belfast technology suppliers can use Cyber Essentials to demonstrate a national technical baseline while keeping product security and customer-specific assurance separate. Expertise in cybersecurity does not remove the need to verify how the company’s own accounts, devices and business services are managed.
Read articleGuides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read article

