Skip to content
Guides

Cyber Essentials Oxford: a practical certification guide

For an Oxford organisation, the value of Cyber Essentials depends on a clear scope and truthful answers about how its systems are managed. Research partnerships and specialist facilities can make that boundary less obvious than a single office address suggests.

a large building with a dome on top of it

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Oxford: a practical certification guide

For an Oxford organisation, the value of Cyber Essentials depends on a clear scope and truthful answers about how its systems are managed. Research partnerships and specialist facilities can make that boundary less obvious than a single office address suggests.

Section 02

Oxford’s research setting

Oxford City Council’s economic strategy identifies science, medical research and knowledge-driven businesses among the city’s strengths. This supports a guide focused on collaboration and specialist systems. It does not establish a common certification rule for universities, hospitals, laboratories or their suppliers.

Start with the organisation and service that a buyer wants to assess. A commercial company, a university department and a separately incorporated research venture are not interchangeable simply because they share facilities or work on the same project. Confirm the entity that will appear on the certificate before compiling technical answers.

Section 03

Example: a consultancy coordinating external researchers

Imagine an Oxford consultancy whose employees work alongside external specialists using shared project spaces. The company is preparing for a customer assurance review. This is a planning example, not a statement about a particular university or Fig engagement.

Map the collaboration services and identify who administers each one. Record which people have ongoing access, which accounts belong to another organisation and how that access can be ended. A signed collaboration agreement may define responsibilities, but the assessment needs an accurate account of the controls in operation.

Check where project information can be stored after it is downloaded. If staff use company laptops away from the office, include those working arrangements in the scope discussion. Do not assume that information stays inside a shared research platform merely because that is where the project started.

Identify specialist applications, remote-support tools and the operating systems they depend on. Ask who tracks support dates and applies required updates. If a change needs testing with a research workflow, arrange that work early enough to complete it before submission. A justified business concern about disruption still needs a compliant resolution where the scheme requires one.

Section 04

Separate research obligations from the technical baseline

Cyber Essentials does not approve research ethics, establish compliance with every rule governing health information or validate a scientific method. It should not be presented as a certificate for the research itself. Explain its organisational scope when sharing it with a customer or partner.

If the buyer requests additional assurance, create separate actions for those requirements. A penetration test, information-security management system or contractual data-handling review may have a different purpose and scope. Completing one does not automatically complete the others.

Section 05

Work with the actual procurement requirement

Ask the buyer for the certificate level, required entity and evidence deadline. If the wording is unclear, use the official clarification route for the opportunity. This guide does not claim that all Oxford public bodies or research customers require Cyber Essentials as standard.

Record any agreed scope clarification so that the commercial team and assessor are working from the same information. If the request changes during negotiations, review the planned route before submission rather than assuming the original purchasing decision still fits.

Section 06

Prepare a defensible submission

Have the technical owner confirm the facts and the authorised representative review the final answers. Where an MSP or facilities provider operates a control, obtain information specific to that service. The existence of a support agreement alone does not show that every device is managed or every account configured correctly.

Keep evidence proportionate and securely stored. Avoid placing research results, personal records or confidential partner material in a general enquiry form. Sanitised configuration information usually makes a better starting point for a scope conversation.

After certification, retain the scope explanation with the certificate. Revisit it when a project introduces new collaborators, another cloud tenant or a different set of specialist devices. Renewal should confirm the current environment, not simply repeat answers from a research arrangement that has since changed. This keeps the certificate useful in customer discussions without overstating the assurance it provides.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Oxford businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Oxford

Oxford City Council’s strategy identifies science, medical research and knowledge-driven businesses as local strengths. The guide addresses organisational boundaries and external collaboration; it does not turn those economic strengths into a universal certification requirement.

Business contexts covered

  • Life sciences
  • Knowledge-based businesses
  • Research services

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig