Cyber Essentials Plymouth: a practical certification guide
For a Plymouth marine-technology supplier, Cyber Essentials should be described as an assessment of defined organisational controls. It is not a certificate of vessel safety, autonomous-system performance or the security of every piece of equipment a business develops or supports.

Section 01
Cyber Essentials Plymouth: a practical certification guide
For a Plymouth marine-technology supplier, Cyber Essentials should be described as an assessment of defined organisational controls. It is not a certificate of vessel safety, autonomous-system performance or the security of every piece of equipment a business develops or supports.
Section 02
Marine innovation and supplier assurance
Plymouth City Council’s marine-autonomy announcement provides a local setting for businesses developing and supporting marine technology. It does not establish that all participants or suppliers must hold the same cyber certificate.
Before purchasing, obtain the specific customer requirement. Ask which organisation must be certified, whether CE or Plus is requested and whether other contractual standards apply. If DCC is named, confirm the required level and risk profile separately rather than inferring it from the maritime or defence connection.
Section 03
Example: a supplier running demonstrations and field trials
Imagine a Plymouth company whose staff use office systems, development tools and equipment for customer demonstrations. A commercial partner asks for organisational certification. This is a planning scenario, not a report of a Fig Group engagement or a named marine programme.
The first task is to map the company’s systems and connections. Identify which devices access business information, who administers them and whether field equipment relies on a connected support laptop. Ask the assessor how the current scope rules apply; neither the word prototype nor the word operational automatically resolves the question.
Next, review temporary arrangements introduced for trials. A remote-access tool, supplier account or shared dashboard may remain after an event. Identify which services are still authorised and necessary, and who is responsible for removing access when the trial ends.
Check supporting software on development and field devices. A specialist application can depend on an operating system or component with a different support lifecycle. Agree how required updates are managed without bypassing the organisation’s safe testing and change process. If remediation is needed, complete it before declaring that the control is implemented.
Section 04
Keep product and operational assurance separate
Cyber Essentials is not a substitute for assessing the security of autonomous decision-making, communications links or application logic. If a customer requests product testing or a specialist system review, define that work separately. Be clear about which evidence comes from organisational certification and which comes from other assurance activities.
Likewise, a certificate does not authorise access to a customer’s equipment or test environment. Obtain the relevant permission before any scanning or testing. An existing commercial relationship does not provide unlimited authority to inspect connected systems.
Section 05
Defence requirements depend on the contract
The MOD Cyber Security Model describes the relationship between supplier controls and cyber risk profiles. Use the contract’s specified requirement to choose the route. A Plymouth address, marine customer or planned defence opportunity does not determine a DCC level.
Keep the buyer’s clarification with the assessment record. This helps the commercial and technical teams work to the same requirement and prevents a later renewal from relying on an assumption that applied only to an earlier engagement.
Section 06
Prepare evidence without exposing sensitive designs
Use a concise inventory, responsibility record and sanitised configuration evidence. Avoid sharing unreleased designs, customer trial data or live credentials through a general enquiry. If further detail is necessary, agree a suitable channel and confirm the disclosure is permitted.
Have the technical owner verify the facts and the authorised representative review the final answers. Where an MSP manages office IT but engineers manage trial devices, reconcile both sets of information before submission rather than assuming one provider covers everything.
After issue, retain the certificate with a clear scope explanation. Review that record when a prototype becomes a supported product, another field device is introduced or a customer changes the access arrangement. This keeps certification aligned with the business as it develops, without turning a defined technical baseline into a claim about every aspect of marine safety or product security.
For field trials, establish how equipment returns are recorded and who checks the device before it reconnects to routine business services.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Plymouth businesses
Swipe across the table to view all columns.
Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Plymouth
Plymouth City Council’s June 2025 announcement describes the city’s marine-autonomy role. The guide separates organisational certification from product testing, operational safety and any defence-specific contractual requirements.
Business contexts covered
- Marine technology
- Engineering suppliers
- Autonomy research businesses
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Plymouth City Council: marine autonomy announcement - The announced marine-autonomy focus, not requirements for every supplier.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Dundee: a practical certification guide
A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.
Read articleGuides
Cyber Essentials Leicester: a practical certification guide
Leicester suppliers should treat Cyber Essentials as a defined technical assessment rather than a general approval of their supply chain. A business can use the certificate in customer assurance while still needing separate evidence about product quality, employment practices, continuity and contractual security obligations.
Read articleGuides
Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.
Read article

