Skip to content
Guides

Cyber Essentials Norwich: a practical certification guide

Norwich research and service businesses should identify their own certification boundary before borrowing descriptions from a host institution or project partner. Cyber Essentials assesses the organisation and systems within the agreed scope, not an entire collaborative ecosystem simply because its members share a location.

a couple of people that are standing in front

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Norwich: a practical certification guide

Norwich research and service businesses should identify their own certification boundary before borrowing descriptions from a host institution or project partner. Cyber Essentials assesses the organisation and systems within the agreed scope, not an entire collaborative ecosystem simply because its members share a location.

Section 02

Research collaboration as a preparation context

Norwich Research Park describes work in food, genomics and health involving independent institutions and businesses. That provides a useful setting for examining shared services and external collaboration. It does not establish a universal certificate requirement for park occupiers, institutes or customers.

Start by naming the entity seeking certification and the service it delivers. Identify which systems it operates, which it uses under another organisation’s agreement and who can provide factual control information. A research partnership can be closely integrated commercially while retaining separate IT responsibilities.

Section 03

Example: a data service working across institutional boundaries

Imagine a Norwich company supplying analysis services to research partners. It uses company email and workstations, a partner workspace and specialist software. This is an illustrative planning example, not a description of a particular institute or Fig Group customer.

Map where business information is stored and processed. Establish whether the company can administer its accounts, enforce relevant settings and remove access when staff leave. For partner-controlled services, identify the contact who can confirm the arrangement and act on access changes.

Review the devices used by researchers and analysts. A workstation may be maintained by a specialist team while ordinary laptops are managed by an MSP. Confirm the applicable scope with the assessor and record who supports each part. Avoid an inventory that includes only the devices visible to one provider.

Look at supporting applications and operating systems as well as the main analysis package. Specialist workflows can rely on components whose support status differs from the headline software. Identify required remediation early, particularly where a change needs compatibility testing or coordination with a research timetable.

Section 04

Research controls and CE controls are not identical

Cyber Essentials does not determine whether a dataset can lawfully be used, validate a scientific result or approve a research protocol. Keep those requirements with the people responsible for them. The certificate may form part of a wider assurance response, but it should not be presented as replacing those reviews.

Similarly, a partner’s certificate is not automatic evidence for your company. Confirm the scope of each certificate and the relationship between the systems involved. Avoid claiming that a whole collaborative project is certified when only one participant has completed an assessment.

Section 05

Gather the right evidence, not the research itself

Prepare system descriptions, responsibility records and configuration evidence. Do not include genomic records, confidential research results or personal information in a general enquiry when the question concerns a technical setting. Agree an appropriate transfer channel if a more detailed explanation is needed.

Ask external providers precise questions about the controls they operate. A statement that a workspace is professionally managed does not necessarily answer a question about account configuration or supported software on the devices accessing it. Resolve uncertainty before the authorised representative signs off the submission.

Section 06

Turn a buyer request into a realistic sequence

Obtain the requested level, certified entity and evidence deadline. If Plus or another assurance activity is required, plan it separately. This guide does not claim that every Norwich health, university or public-sector customer follows one procurement rule.

Allow time for scope clarification, technical changes and internal review before assessment. A compliant questionnaire can be reviewed quickly, but research equipment and third-party dependencies may need preparation first. Do not describe planned changes as completed controls.

After certification, maintain the scope record when another collaboration begins, a new analysis service is adopted or the company moves between facilities. Review the certificate before sharing it with a new customer. Clear boundaries make the evidence useful while avoiding unsupported claims about the security or compliance of every institution in the research network.

For collaborative analysis, identify which institution controls account removal and record any action your organisation must request rather than perform itself.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Norwich businesses

Swipe across the table to view all columns.

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Norwich

Norwich Research Park describes research in food, genomics and health across several independent institutions and businesses. The guide focuses on responsibility across collaborative environments; park association does not provide certification coverage for a separate organisation.

Business contexts covered

  • Food research businesses
  • Genomics services
  • Health-related innovation

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group