Skip to content
Guides

Cyber Essentials Manchester: a practical certification guide

A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.

people walking on sidewalk near buildings dur

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Manchester: a practical certification guide

A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.

Section 02

Manchester’s digital economy: what to prepare

The Greater Manchester Digital Blueprint identifies a resilient digital economy as a regional priority. For a digital supplier, this creates a useful starting point for a security conversation: can you explain how the systems used to deliver your service are managed? It is not evidence that Manchester City Council, GMCA, broadcasters or insurers universally require a particular certificate.

For an agency working across client projects, begin with a service map rather than an office address. Record where briefs, creative assets, personal information and customer credentials are stored. Include the collaboration platforms used by account managers and the devices used by people working away from the office. A certificate described as covering an office can be misleading if most delivery happens through cloud accounts accessed elsewhere.

Section 03

Example: a creative supplier with freelance support

Consider a Manchester agency preparing for a customer security review. Its employees use managed laptops, while freelance specialists access project folders through their own devices. This is an illustrative planning situation, not a Fig customer case study or a statement about broadcaster requirements.

The agency should first distinguish a guest who receives a finished file from someone with continuing access to business systems. Identify the account owner, the information accessible and the devices used for that work. Ask the assessor how the current scheme requirements apply to that arrangement rather than assuming all contractors are either included or excluded.

Next, check the working process against the proposed answers. Does a contractor retain access after the production ends? Can a shared creative account bypass the organisation’s normal authentication settings? Are browser extensions or editing applications installed outside the managed software process? These questions help identify gaps that an inventory limited to employee laptops could miss.

An appropriate preparation record names the service, responsible owner, access arrangement and outstanding action. It should not contain customer passwords, unreleased creative assets or unnecessary personal information. Resolve the access and software issues before the authorised representative signs off the assessment.

Section 04

Keep customer requirements distinct

Ask the buyer to supply the exact contractual wording. Confirm whether it asks for Cyber Essentials, Cyber Essentials Plus or another assurance measure, which legal entity must hold it, and the date by which evidence is needed. A request for a certificate is different from a request for a penetration test or an information-security policy.

If the request relates to a public-sector opportunity, use its tender documents and clarification process. The government’s Cyber Essentials procurement policy has a defined scope and risk-based application; it should not be interpreted as a rule covering every local authority purchase. Keep the buyer’s written answer alongside the bid so that commercial and technical teams work to the same requirement.

Section 05

A practical handover to your IT provider

Give your MSP the proposed certificate scope, current service inventory and submission deadline. Request factual answers about supported software, administrator access, cloud authentication and update coverage. A statement that the business has an IT support contract does not describe the controls actually in operation.

Agree who will fix each identified gap and who will confirm completion. If your MSP supplies evidence for several customers, keep your organisation’s records separate. Its own certificate is not a substitute for certification covering your business.

Before sharing the final certificate, check that the organisation name and scope match the customer’s request. Retain a short explanation of any agreed boundary so a later procurement reviewer does not have to reconstruct the decision. When a project ends, remove access through the normal leaver process; certification should support that routine, not replace it.

Section 06

Does a Manchester postcode change the assessment?

No. Location does not change the Cyber Essentials controls. A distributed business should describe the systems used for its work, not assume that a Manchester registered address limits the assessment to one building. Where a group includes several legal entities or materially different networks, confirm the proposed arrangement before selecting and submitting the questionnaire.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Manchester businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Manchester

Greater Manchester’s Digital Blueprint connects business technology adoption with a more resilient digital economy. That provides a regional context for discussing security with customers; it does not establish a certification requirement for every Manchester supplier.

Business contexts covered

  • Digital services
  • Creative suppliers
  • Professional services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig