Cyber Essentials Nottingham: a practical certification guide
For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.

Section 01
Cyber Essentials Nottingham: a practical certification guide
For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.
Section 02
From local research activity to business controls
The University of Nottingham’s scientific careers guidance identifies BioCity as a bioscience innovation centre in the city. That provides context for discussing growing research businesses; it does not establish a procurement policy for BioCity, the university or their partners.
A company using shared facilities still needs to understand its own systems. Separate building connectivity, landlord-managed infrastructure, company-owned devices and hosted services. The question is not simply whether the premises are modern or professionally managed, but who implements each relevant control for the organisation being certified.
Section 03
Example: a laboratory business taking on its first commercial contract
Imagine a Nottingham company whose founders used personal accounts during early research. It now has employees and a customer asking for a security baseline. This is an illustrative scenario, not a report of a Fig customer.
Start by establishing an authoritative list of business accounts. Identify cloud storage, collaboration, finance and specialist services that the organisation relies on. Confirm that the business can administer access and recover control if an individual leaves. A service paid through an employee expense claim can be just as relevant as one on the main IT invoice.
Next, identify the devices used for business work, including specialist workstations and personally owned devices where applicable under the current scheme. Ask the assessor about uncertain arrangements before completing scope answers. Do not omit an endpoint merely because it belongs to a founder or is used mainly in a laboratory.
Review the relationship between equipment software and the wider network. Establish who supports the operating system, who can install changes and whether remote assistance is enabled. If the equipment vendor and MSP each assume the other manages updates, record the gap and assign responsibility before submission.
Section 04
What shared premises do and do not establish
A tenancy agreement can help identify who operates connectivity or network equipment. It is not, by itself, evidence that the company’s accounts and laptops meet Cyber Essentials. Ask the provider for the specific information needed to answer the relevant questions.
Similarly, the certificate should not imply that the entire building, research partnership or laboratory process has been assessed. Keep the certified entity and systems clear. Cyber Essentials does not validate scientific findings, approve clinical use or replace other obligations applying to the company’s work.
Section 05
Turn a customer request into an assessment plan
Obtain the exact certification name and acceptance deadline. Check whether the buyer asks for CE, Plus or a broader assurance package. If it is a public-sector opportunity, resolve uncertainty through the published clarification process rather than assuming every Nottingham public body has the same rule.
Agree the scope before selecting the assessment route. Give the technical owner time to gather factual information and complete remediation. If Plus testing is required, arrange that separately; the turnaround for reviewing a compliant CE questionnaire does not describe the scheduling or completion of a technical audit.
Section 06
Keep evidence useful and proportionate
Create a preparation record with systems, owners and completed actions. Use configuration evidence without including research datasets, patient information or live credentials. Where a provider must supply information, record which service its statement covers and whether any responsibility remains with your company.
The authorised representative should review the final answers against the working environment. If an MSP prepares them, the business still needs to understand and authorise the submission. Answers based solely on a proposed policy or future migration should be corrected before sign-off.
After certification, review the inventory when another laboratory, cloud tenant or commercial service is added. Maintain a clear renewal owner and keep the certificate’s scope explanation with customer assurance material. That makes certification easier to use accurately as the business moves beyond its initial research arrangements.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Nottingham businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Nottingham
The University of Nottingham identifies BioCity as a local bioscience innovation centre. The guide uses early-stage laboratory and business systems as its preparation context, without asserting that BioCity, the university or health customers require a particular certificate.
Business contexts covered
- Bioscience businesses
- Research support
- Technology services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- University of Nottingham: scientific careers and local industry - BioCity’s Nottingham bioscience presence.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Stevenage: a practical certification guide
Cyber Essentials preparation for a Stevenage business should begin with the organisation’s own systems and the customer’s written requirement. Life-sciences and engineering work can involve shared facilities, external research partners and specialist applications, making responsibilities more important than the postcode of the office.
Read articleGuides
Cyber Essentials Glasgow: a practical certification guide
For a Glasgow organisation delivering projects through employees and external specialists, Cyber Essentials preparation should focus on the systems and access arrangements used to do the work. A certificate is more useful when the business can explain its scope than when it is treated as a general claim about every project partner.
Read articleGuides
Cyber Essentials Cambridge: a practical certification guide
Cambridge companies preparing for Cyber Essentials should be clear about the boundary between the business and the research or investment ecosystem around it. A university connection, science-park address or cloud provider’s certificate does not automatically cover a separate company’s systems.
Read article

