Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.

Section 01
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Section 02
A useful distinction for digital suppliers
Invest Newcastle describes the city’s technology, data and healthy-ageing innovation activity. For a business building a digital service in that setting, customer assurance may cover both corporate IT and the product delivered to users. Those questions overlap, but they are not identical.
Start by obtaining the actual customer request. Identify whether it asks for a Cyber Essentials certificate, technical testing of the service, or wider evidence about development and operations. Do not infer a national procurement requirement from the presence of a local university, innovation centre or public-sector customer.
Section 03
Example: a software team moving from pilot to paid service
Imagine a Newcastle company that has developed a pilot using cloud infrastructure and a small development team. Before onboarding a commercial customer, it wants to certify the organisation. This example is a preparation exercise, not an account of a Fig client.
List the company’s business services and development tools separately. Include email, collaboration, source repositories, administration consoles and the devices used to access them. Identify who owns each tenant or account. Services created during a pilot can remain tied to an individual founder, making access management and recovery difficult when the team grows.
Check how administrators perform privileged work. Establish which accounts have elevated access, whether that access is still needed and how it is reviewed. Do not assume that a cloud provider’s own certificate describes the configuration of your organisation’s tenant or the way your developers use it.
Review the actual software estate on development devices. Local tools and supporting applications can be overlooked when the inventory concentrates on production hosting. Ask the responsible technical person to confirm supported versions and the update process. Any unresolved requirement should become an action before submission, not an optimistic statement in the questionnaire.
Section 04
Keep product testing as its own workstream
Cyber Essentials is not a substitute for a code review, penetration test or a review of the application’s authorisation logic. If a customer requests those activities, scope them explicitly and agree the systems, permissions and reporting needed. A successful organisational assessment should not be marketed as an independent security test of every product feature.
For a health-related pilot, also separate clinical, research and data-governance requirements from CE. Certification does not decide whether a proposed use of information is lawful or clinically appropriate. Obtain the appropriate specialist input rather than stretching the certificate’s meaning to cover those questions.
Section 05
A practical preparation record
Create a list of systems, owners and unresolved controls. Include the customer’s requested certificate scope and deadline. Have the commercial owner and technical lead agree the same description of the service before the authorised representative approves the answers.
If an MSP administers corporate IT but engineers manage development services, ask both teams for factual information. Neither should assume that the other covers every cloud account. Record the handover points so questions about authentication, devices and updates have a clear owner.
Use sanitised configuration evidence. Do not include customer datasets, source-code secrets or production credentials in a general enquiry. Where more detail is necessary, arrange an appropriate transfer channel and confirm the purpose of the request.
Section 06
After the first certificate
Keep the certificate with its scope explanation and review date. Revisit the control inventory when the pilot becomes a production service, another customer tenant is introduced or a new support provider takes responsibility. A fast-growing company can change significantly between annual renewals.
When responding to a prospect, explain which organisation was certified and which additional assurance has been completed separately. Clear boundaries make a security response more credible than a broad claim that the platform or every customer environment is compliant simply because the company holds Cyber Essentials.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Newcastle businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Newcastle
Invest Newcastle describes a local technology and data ecosystem alongside healthy-ageing innovation. The guide applies that context to an organisation developing and delivering digital services, without presenting a local investment programme as a certification mandate.
Business contexts covered
- Digital technology
- Data services
- Health innovation
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Invest Newcastle: investment overview - Local data, technology and healthy-ageing innovation context.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.
Read articleGuides
Cyber Essentials Belfast: a practical certification guide
Belfast technology suppliers can use Cyber Essentials to demonstrate a national technical baseline while keeping product security and customer-specific assurance separate. Expertise in cybersecurity does not remove the need to verify how the company’s own accounts, devices and business services are managed.
Read articleGuides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read article

