Skip to content
Guides

Cyber Essentials Nottingham: a practical certification guide

For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.

a building with a tower

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Nottingham: a practical certification guide

For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.

Section 02

From local research activity to business controls

The University of Nottingham’s scientific careers guidance identifies BioCity as a bioscience innovation centre in the city. That provides context for discussing growing research businesses; it does not establish a procurement policy for BioCity, the university or their partners.

A company using shared facilities still needs to understand its own systems. Separate building connectivity, landlord-managed infrastructure, company-owned devices and hosted services. The question is not simply whether the premises are modern or professionally managed, but who implements each relevant control for the organisation being certified.

Section 03

Example: a laboratory business taking on its first commercial contract

Imagine a Nottingham company whose founders used personal accounts during early research. It now has employees and a customer asking for a security baseline. This is an illustrative scenario, not a report of a Fig customer.

Start by establishing an authoritative list of business accounts. Identify cloud storage, collaboration, finance and specialist services that the organisation relies on. Confirm that the business can administer access and recover control if an individual leaves. A service paid through an employee expense claim can be just as relevant as one on the main IT invoice.

Next, identify the devices used for business work, including specialist workstations and personally owned devices where applicable under the current scheme. Ask the assessor about uncertain arrangements before completing scope answers. Do not omit an endpoint merely because it belongs to a founder or is used mainly in a laboratory.

Review the relationship between equipment software and the wider network. Establish who supports the operating system, who can install changes and whether remote assistance is enabled. If the equipment vendor and MSP each assume the other manages updates, record the gap and assign responsibility before submission.

Section 04

What shared premises do and do not establish

A tenancy agreement can help identify who operates connectivity or network equipment. It is not, by itself, evidence that the company’s accounts and laptops meet Cyber Essentials. Ask the provider for the specific information needed to answer the relevant questions.

Similarly, the certificate should not imply that the entire building, research partnership or laboratory process has been assessed. Keep the certified entity and systems clear. Cyber Essentials does not validate scientific findings, approve clinical use or replace other obligations applying to the company’s work.

Section 05

Turn a customer request into an assessment plan

Obtain the exact certification name and acceptance deadline. Check whether the buyer asks for CE, Plus or a broader assurance package. If it is a public-sector opportunity, resolve uncertainty through the published clarification process rather than assuming every Nottingham public body has the same rule.

Agree the scope before selecting the assessment route. Give the technical owner time to gather factual information and complete remediation. If Plus testing is required, arrange that separately; the turnaround for reviewing a compliant CE questionnaire does not describe the scheduling or completion of a technical audit.

Section 06

Keep evidence useful and proportionate

Create a preparation record with systems, owners and completed actions. Use configuration evidence without including research datasets, patient information or live credentials. Where a provider must supply information, record which service its statement covers and whether any responsibility remains with your company.

The authorised representative should review the final answers against the working environment. If an MSP prepares them, the business still needs to understand and authorise the submission. Answers based solely on a proposed policy or future migration should be corrected before sign-off.

After certification, review the inventory when another laboratory, cloud tenant or commercial service is added. Maintain a clear renewal owner and keep the certificate’s scope explanation with customer assurance material. That makes certification easier to use accurately as the business moves beyond its initial research arrangements.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Nottingham businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Nottingham

The University of Nottingham identifies BioCity as a local bioscience innovation centre. The guide uses early-stage laboratory and business systems as its preparation context, without asserting that BioCity, the university or health customers require a particular certificate.

Business contexts covered

  • Bioscience businesses
  • Research support
  • Technology services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig