Skip to content
Guides

Cyber Essentials Portsmouth: a practical certification guide

Portsmouth suppliers should choose a certification route from the actual customer requirement, not from the assumption that all maritime or defence-related work needs the same certificate. Cyber Essentials, Plus and Defence Cyber Certification have distinct roles and should be described accurately.

a street with buildings on both sides

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Portsmouth: a practical certification guide

Portsmouth suppliers should choose a certification route from the actual customer requirement, not from the assumption that all maritime or defence-related work needs the same certificate. Cyber Essentials, Plus and Defence Cyber Certification have distinct roles and should be described accurately.

Section 02

Local supply chains, separate obligations

Portsmouth City Council describes the port’s contribution to marine-related businesses and wider supply chains. This supports a guide about supplier access and service delivery. It is not evidence that every port supplier must hold a particular certification.

Retrieve the security schedule for the service being purchased. Establish whether the requirement applies to the bidding company, a delivery subcontractor or a defined system boundary. If the contract names a defence cyber risk profile, confirm the applicable DCC requirement rather than assuming basic CE is sufficient or Plus is interchangeable with it.

Section 03

Example: a technical support company with subcontractors

Imagine a Portsmouth company providing technical support through employees and specialist subcontractors. Its office uses a managed cloud tenant, but project support involves additional tools and customer accounts. This is an illustrative scenario, not a claim about a specific port or defence customer.

Begin by listing the systems your company operates. Identify support applications, business email and the devices used to access them. Then record customer-controlled environments separately, including who grants and revokes your staff’s access. The certificate must not imply ownership or assessment of every customer system your people can reach.

Ask how subcontractors access company information. Establish whether they use guest accounts, company devices or their own managed environments. Take uncertain scope arrangements to the assessor instead of excluding them solely because the people are not employees. The current scheme requirements and actual access pattern matter.

Review privileged support accounts carefully. Determine which roles are necessary, how they are approved and how access ends with an assignment. A generic statement that subcontractors are trusted professionals does not answer a technical control question about account management.

Section 04

Distinguish certification from authorisation

A certificate does not provide permission to connect to, scan or test a customer’s systems. Agree those activities through the appropriate authorisation process. Nor does Cyber Essentials establish physical access approval, personnel clearance or maritime safety assurance.

For defence-related opportunities, the MOD Cyber Security Model is a reference for the relationship between controls and risk profiles. The contract remains the place to confirm the requirement for your engagement. Do not infer a level from being based in Portsmouth or working near a defence establishment.

Section 05

Prepare a submission that the business can approve

Allocate factual questions to the people who operate the systems. The MSP may know office device settings, while service managers know which support tools and project accounts are active. Reconcile those answers before the authorised representative reviews them.

If a required control is not implemented, record and complete remediation. A future contract amendment, planned tool replacement or draft policy is not evidence that the current environment already meets the requirement. Allow time for controlled changes rather than relying on the assessor to resolve operational ownership during review.

Use proportionate evidence. Configuration records should avoid revealing customer infrastructure details, live credentials or sensitive project material unnecessarily. Agree a suitable channel if more detailed information is needed to understand the scope.

Section 06

Keep the commercial message precise

When the certificate is issued, check the legal entity, scope and validity before sharing it. Explain what was assessed without extending the claim to customer networks or every subcontractor organisation. Where a buyer wants additional evidence, respond to that request separately.

Maintain the same discipline at renewal. New subcontractors, support applications or remote-access arrangements can change the environment between assessments. Review those changes when they are introduced and keep a current scope explanation with the supplier evidence pack. This makes the certificate easier to use responsibly across different Portsmouth and national customer engagements.

For subcontracted support, identify who approves each remote account and who checks its removal when the support agreement ends.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Portsmouth businesses

Swipe across the table to view all columns.

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Portsmouth

Portsmouth City Council describes Portsmouth International Port’s role in marine-related business and supply chains. The guide separates a supplier’s technical baseline from port operations and any distinct defence-contract obligations.

Business contexts covered

  • Marine-related suppliers
  • Port services
  • Technical support businesses

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.