Cyber Essentials Liverpool: a practical certification guide
Liverpool businesses can use Cyber Essentials to demonstrate the scheme’s baseline controls without treating it as a guarantee of customer approval. The practical route is to identify the systems used for the service, establish the buyer’s requirement and complete any necessary changes before assessment.

Section 01
Cyber Essentials Liverpool: a practical certification guide
Liverpool businesses can use Cyber Essentials to demonstrate the scheme’s baseline controls without treating it as a guarantee of customer approval. The practical route is to identify the systems used for the service, establish the buyer’s requirement and complete any necessary changes before assessment.
Section 02
Liverpool’s supply-chain context
The Liverpool City Region growth plan identifies health and life sciences, digital technology and advanced manufacturing, supported by maritime and business services. These are different commercial settings, not a single certification market with identical rules.
For a business coordinating deliveries or exchanging customer records, the useful starting question is where that work happens digitally. Booking portals, dispatch systems and business email can sit with different providers. Map the service before assuming that one office network describes the whole assessment scope.
Section 03
Example: a logistics coordinator with shift-based teams
Consider a Liverpool-area service business whose office team schedules work while colleagues use shared terminals and mobile devices. It has been asked to provide security evidence during a customer renewal. This is an illustrative scenario, not a description of a port operator’s policy or a Fig customer.
Identify which devices access the organisation’s data and services. Record the purpose of shared terminals, the accounts used on them and the person responsible for their configuration. Shared equipment and shared credentials are different issues; do not assume that a device used by several people must therefore have one unrestricted account.
Ask how access changes between shifts and when temporary workers leave. Check whether the process covers cloud services as well as the office login. If a supervisor creates accounts informally to avoid delaying a delivery, reconcile that practice with the controls the organisation intends to declare.
For mobile devices, identify ownership, support status and the management arrangements applicable to their business use. Discuss uncertain scope with the assessor rather than omitting devices because they are away from the office. A report limited to desktop computers can miss an important part of the working service.
Section 04
Keep customer systems outside unsupported claims
A customer may operate the booking portal your staff use. Distinguish its responsibility for that platform from your responsibility for accounts, access decisions and the devices your people use. Your certificate should not be presented as certification of the customer’s portal or port infrastructure.
The same care applies to physical operations. Cyber Essentials is not an assessment of maritime safety, cargo security or every operational technology system. If the customer asks for additional assurance, identify the relevant requirement and deal with it separately rather than extending the meaning of the certificate.
Section 05
Prepare for the buyer’s evidence deadline
Obtain the exact certification name, entity and scope expected. Ask whether the certificate must be current at bid submission, contract start or throughout delivery. For a public-sector opportunity, use the tender’s official clarification route. This guide does not state that every Liverpool council, health or maritime supplier must hold CE or Plus.
Give your IT provider enough time to resolve unsupported software, account-management issues or unclear network responsibilities. Operational teams may need to coordinate changes around service hours. The assessment turnaround for a compliant submission does not include the time needed to arrange those changes.
Section 06
What a useful handover contains
Keep a concise service inventory, the buyer’s written requirement and a record of completed remediation. Identify the colleague authorised to review and sign off the submission. Do not include live customer manifests, personal records or passwords when a configuration description is sufficient.
After certification, check the certificate details before sending it to the customer. Maintain a renewal reminder and revisit the scope when another depot, service or cloud platform is introduced. If a buyer asks a broader security question, answer it with the appropriate current evidence rather than assuming the certificate answers every part of a supplier questionnaire.
For a distributed business, the strongest preparation is a clear account of who operates each system and how controls are maintained across the working day. That remains useful long after the initial certificate has been issued.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Liverpool businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Liverpool
Liverpool City Region’s growth plan identifies health, digital and manufacturing strengths supported by maritime and business services. This is regional context; the guide does not assert procurement requirements for port operators, health organisations or individual employers.
Business contexts covered
- Maritime-related services
- Health and life sciences
- Digital suppliers
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Liverpool City Region: growth plan - The growth plan’s named sectors, including maritime support.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.
Read articleGuides
Cyber Essentials Exeter: a practical certification guide
Cyber Essentials can help an Exeter organisation demonstrate a defined baseline of technical security. Before starting, establish whether you are responding to a contractual requirement or choosing certification as part of your own improvement programme. That decision affects the deadline and evidence a buyer expects, but not the national control standard.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read article

