Cyber Essentials Hull: a practical certification guide
Hull suppliers preparing for Cyber Essentials should begin with the service they operate and the systems their people use. Working in a port-related or renewable-energy supply chain does not automatically mean the certificate covers operational infrastructure or satisfies every customer security condition.

Section 01
Cyber Essentials Hull: a practical certification guide
Hull suppliers preparing for Cyber Essentials should begin with the service they operate and the systems their people use. Working in a port-related or renewable-energy supply chain does not automatically mean the certificate covers operational infrastructure or satisfies every customer security condition.
Section 02
A Humber supply-chain setting
Hull City Council’s Green Port Hull information describes a collaboration supporting renewable-energy investment and supply chains in the Humber region. This provides a local context for examining supplier operations. It is not evidence that every associated business must hold CE or Plus.
Ask the buyer for the actual requirement, including the entity, level and evidence deadline. Separate certification from other obligations covering engineering quality, operational safety or customer access. Those matters can require additional assurance beyond the technical baseline assessed by CE.
Section 03
Example: a supplier combining office and field support
Imagine a Hull company whose coordinators use office systems while service personnel work at customer locations. Staff rely on mobile devices, company laptops and customer scheduling platforms. This is a planning example, not a claim about a named energy operator or Fig customer.
Start by listing devices and services used for business work. Establish who manages the equipment used away from the office and whether it remains visible to the normal support process. A missing device report should prompt a check, not an assumption that the equipment is no longer relevant.
Review software installed for individual assignments. Remote tools and specialist applications can remain after the customer work ends. Identify what is still authorised and supported, who can install changes and how unnecessary access is removed.
Check the boundary around customer platforms. The customer may manage its scheduling service while your company remains responsible for its users and endpoints. Record who can revoke access when a person changes role or a contract ends. A supplier certificate should not imply assessment of the customer’s entire environment.
Section 04
Understand operational-system limits
If equipment has connections to company systems, explain the arrangement to the assessor and agree its treatment under the current scope requirements. Do not assume that an operational label automatically excludes it. Equally, do not present the certificate as a complete industrial-control-system or offshore safety assessment.
Changes on customer or safety-relevant systems need the appropriate authorisation and operational process. A certification deadline is not permission to scan, test or modify infrastructure outside your authority. Where additional assurance is needed, scope it separately.
Section 05
Align support providers before submission
An MSP may manage office devices while an equipment vendor supports specialist tools. Create a responsibility record that shows who operates each relevant control. Ask for factual configuration and support information rather than relying on a general statement that the service is managed.
Where a required change is outstanding, assign an owner and confirm completion before declaring compliance. A maintenance plan or accepted business risk does not turn an unmet scheme requirement into a compliant answer. Build preparation time into the customer schedule separately from assessment review.
Use sanitised evidence. Do not include customer plant diagrams, personal information or live credentials in a general enquiry when a system description or configuration record will answer the question. Agree a suitable channel if more detail is needed.
Section 06
Keep the certificate useful as contracts change
The authorised representative should review the final answers and understand the scope. After issue, store the certificate with a concise explanation for the commercial team. Verify its entity, validity and level before sending it in response to another buyer request.
Revisit the record when the business adds a service, takes on a new customer-access arrangement or replaces a support platform. Such changes can alter the control environment before annual renewal. Maintaining current responsibility and access information helps the business use certification accurately without turning a defined organisational assessment into a claim about every part of the wider Humber supply chain.
For field-support work, record which remote-access services remain active between visits and who can revoke access if the engagement ends.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Hull businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Hull
Hull City Council describes Green Port Hull as a collaboration supporting renewable-energy investment and supply chains in the Humber region. The guide addresses supplier systems and changing contracts, not certification of port infrastructure or offshore operations.
Business contexts covered
- Renewable-energy suppliers
- Port-related services
- Engineering support
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Hull City Council: Green Port Hull - The collaboration’s renewable-energy and supply-chain purpose.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read articleGuides
Cyber Essentials Aberdeen: a practical certification guide
Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.
Read articleGuides
Cyber Essentials Southampton: a practical certification guide
Southampton businesses working in maritime and logistics services should define what their Cyber Essentials certificate covers before using it in customer assurance. A supplier’s office and business systems are not the same thing as a vessel, port or customer-operated network.
Read article

