Skip to content
Guides

Cyber Essentials Leicester: a practical certification guide

Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.

people walking on sidewalk near building duri

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Leicester: a practical certification guide

Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.

Section 02

A manufacturing and supplier context

The council’s textile partnership review describes the local role of textiles and related skills work during 2021–22. It provides historical context for a supplier example. It does not establish current CE adoption or a certification requirement from every fashion, manufacturing or public-sector buyer.

Before assessment, obtain the customer’s actual request. Confirm the certificate level, contracting entity and evidence deadline. If the buyer asks for several types of assurance, keep them as distinct requirements rather than assuming the CE certificate resolves the whole supplier questionnaire.

Section 03

Example: a supplier connecting orders to production

Imagine a Leicester business using a cloud ordering service, office computers and shared terminals for production information. An external provider supports some systems while an internal manager looks after others. This is a planning scenario, not a description of a Fig customer or a named retailer’s policy.

Start by mapping how orders and business information move between systems. Identify the devices used, the accounts that can access them and who administers each service. A central cloud application does not make every endpoint managed or every local account unnecessary.

Review shared terminals and temporary-worker access. Establish how permissions are granted, how roles change and how access ends. Several people using one piece of equipment is not the same issue as everyone using unrestricted shared credentials. Describe the actual arrangement and resolve any relevant control gap.

Check software support beyond the main ordering platform. Browsers, operating systems, remote utilities and specialist applications can have different lifecycles. Ask the responsible person for factual information and agree who completes required updates across the whole assessed scope.

Section 04

Keep supplier relationships separate from certification coverage

Your certificate does not automatically certify independent subcontractors, customer portals or every company involved in making a product. Explain the assessed entity and systems accurately. If a customer requires evidence from delivery partners, establish what it expects from those organisations separately.

Likewise, a provider’s certificate is not a substitute for understanding the controls your own business must implement. Check the division of responsibility in the service arrangement rather than assuming a managed service covers every setting or device.

Section 05

Procurement questions to resolve early

Ask whether the buyer requires CE, Plus or additional testing. For a public-sector opportunity, use the tender documents and official clarification route. This guide does not claim that all Leicester council, education, health or manufacturing suppliers face one universal certification rule.

Record the answer with the bid or renewal file. If the requirement changes during negotiation, review the selected route before submission. A previous customer’s acceptance does not prove that the same certificate will satisfy a different contract.

Section 06

Prepare evidence that reflects daily work

Bring the office administrator, production-system owner and MSP into the same preparation discussion where their responsibilities overlap. Assign each unresolved item to an owner and complete required remediation before the authorised representative signs off the questionnaire.

Do not use a draft policy or planned software replacement as evidence that a control is already implemented. Allow time for necessary changes and internal review separately from the assessment turnaround. Plus testing, where required, has its own arrangements.

Use configuration records without unnecessarily exposing customer orders, personal information or live credentials. Agree a suitable channel if detailed evidence is needed.

After certification, keep the scope explanation with the certificate and assign a renewal owner. Revisit the control inventory when another production site, ordering platform or support provider is introduced. This makes certification a reliable part of supplier assurance without overstating its relevance to wider manufacturing, labour or product-compliance matters.

Where ordering and production systems exchange files, document the transfer method and the person responsible for maintaining the supporting software.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Leicester businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Leicester

Leicester’s published 2021–22 textile partnership review describes the sector’s local role and skills work. The guide uses a supplier with ordering and production systems as an example; historical sector evidence is not presented as current certification demand or a buyer mandate.

Business contexts covered

  • Textile suppliers
  • Manufacturing businesses
  • Business services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig