Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.

Section 01
Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.
Section 02
Manchester’s digital economy: what to prepare
The Greater Manchester Digital Blueprint identifies a resilient digital economy as a regional priority. For a digital supplier, this creates a useful starting point for a security conversation: can you explain how the systems used to deliver your service are managed? It is not evidence that Manchester City Council, GMCA, broadcasters or insurers universally require a particular certificate.
For an agency working across client projects, begin with a service map rather than an office address. Record where briefs, creative assets, personal information and customer credentials are stored. Include the collaboration platforms used by account managers and the devices used by people working away from the office. A certificate described as covering an office can be misleading if most delivery happens through cloud accounts accessed elsewhere.
Section 03
Example: a creative supplier with freelance support
Consider a Manchester agency preparing for a customer security review. Its employees use managed laptops, while freelance specialists access project folders through their own devices. This is an illustrative planning situation, not a Fig customer case study or a statement about broadcaster requirements.
The agency should first distinguish a guest who receives a finished file from someone with continuing access to business systems. Identify the account owner, the information accessible and the devices used for that work. Ask the assessor how the current scheme requirements apply to that arrangement rather than assuming all contractors are either included or excluded.
Next, check the working process against the proposed answers. Does a contractor retain access after the production ends? Can a shared creative account bypass the organisation’s normal authentication settings? Are browser extensions or editing applications installed outside the managed software process? These questions help identify gaps that an inventory limited to employee laptops could miss.
An appropriate preparation record names the service, responsible owner, access arrangement and outstanding action. It should not contain customer passwords, unreleased creative assets or unnecessary personal information. Resolve the access and software issues before the authorised representative signs off the assessment.
Section 04
Keep customer requirements distinct
Ask the buyer to supply the exact contractual wording. Confirm whether it asks for Cyber Essentials, Cyber Essentials Plus or another assurance measure, which legal entity must hold it, and the date by which evidence is needed. A request for a certificate is different from a request for a penetration test or an information-security policy.
If the request relates to a public-sector opportunity, use its tender documents and clarification process. The government’s Cyber Essentials procurement policy has a defined scope and risk-based application; it should not be interpreted as a rule covering every local authority purchase. Keep the buyer’s written answer alongside the bid so that commercial and technical teams work to the same requirement.
Section 05
A practical handover to your IT provider
Give your MSP the proposed certificate scope, current service inventory and submission deadline. Request factual answers about supported software, administrator access, cloud authentication and update coverage. A statement that the business has an IT support contract does not describe the controls actually in operation.
Agree who will fix each identified gap and who will confirm completion. If your MSP supplies evidence for several customers, keep your organisation’s records separate. Its own certificate is not a substitute for certification covering your business.
Before sharing the final certificate, check that the organisation name and scope match the customer’s request. Retain a short explanation of any agreed boundary so a later procurement reviewer does not have to reconstruct the decision. When a project ends, remove access through the normal leaver process; certification should support that routine, not replace it.
Section 06
Does a Manchester postcode change the assessment?
No. Location does not change the Cyber Essentials controls. A distributed business should describe the systems used for its work, not assume that a Manchester registered address limits the assessment to one building. Where a group includes several legal entities or materially different networks, confirm the proposed arrangement before selecting and submitting the questionnaire.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Manchester businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Manchester
Greater Manchester’s Digital Blueprint connects business technology adoption with a more resilient digital economy. That provides a regional context for discussing security with customers; it does not establish a certification requirement for every Manchester supplier.
Business contexts covered
- Digital services
- Creative suppliers
- Professional services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- GMCA: Digital Strategy - Regional digital priorities, not individual tender conditions.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Liverpool: a practical certification guide
Liverpool businesses can use Cyber Essentials to demonstrate the scheme’s baseline controls without treating it as a guarantee of customer approval. The practical route is to identify the systems used for the service, establish the buyer’s requirement and complete any necessary changes before assessment.
Read articleGuides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read articleGuides
Cyber Essentials Bradford: a practical certification guide
Bradford businesses with several sites or different working teams should agree the Cyber Essentials scope before collecting answers. A certificate based on a head-office assumption can be difficult to use accurately if the organisation’s warehouse, workshop or remote staff operate through different systems.
Read article

