Cyber Essentials Portsmouth: a practical certification guide
Portsmouth suppliers should choose a certification route from the actual customer requirement, not from the assumption that all maritime or defence-related work needs the same certificate. Cyber Essentials, Plus and Defence Cyber Certification have distinct roles and should be described accurately.

Section 01
Cyber Essentials Portsmouth: a practical certification guide
Portsmouth suppliers should choose a certification route from the actual customer requirement, not from the assumption that all maritime or defence-related work needs the same certificate. Cyber Essentials, Plus and Defence Cyber Certification have distinct roles and should be described accurately.
Section 02
Local supply chains, separate obligations
Portsmouth City Council describes the port’s contribution to marine-related businesses and wider supply chains. This supports a guide about supplier access and service delivery. It is not evidence that every port supplier must hold a particular certification.
Retrieve the security schedule for the service being purchased. Establish whether the requirement applies to the bidding company, a delivery subcontractor or a defined system boundary. If the contract names a defence cyber risk profile, confirm the applicable DCC requirement rather than assuming basic CE is sufficient or Plus is interchangeable with it.
Section 03
Example: a technical support company with subcontractors
Imagine a Portsmouth company providing technical support through employees and specialist subcontractors. Its office uses a managed cloud tenant, but project support involves additional tools and customer accounts. This is an illustrative scenario, not a claim about a specific port or defence customer.
Begin by listing the systems your company operates. Identify support applications, business email and the devices used to access them. Then record customer-controlled environments separately, including who grants and revokes your staff’s access. The certificate must not imply ownership or assessment of every customer system your people can reach.
Ask how subcontractors access company information. Establish whether they use guest accounts, company devices or their own managed environments. Take uncertain scope arrangements to the assessor instead of excluding them solely because the people are not employees. The current scheme requirements and actual access pattern matter.
Review privileged support accounts carefully. Determine which roles are necessary, how they are approved and how access ends with an assignment. A generic statement that subcontractors are trusted professionals does not answer a technical control question about account management.
Section 04
Distinguish certification from authorisation
A certificate does not provide permission to connect to, scan or test a customer’s systems. Agree those activities through the appropriate authorisation process. Nor does Cyber Essentials establish physical access approval, personnel clearance or maritime safety assurance.
For defence-related opportunities, the MOD Cyber Security Model is a reference for the relationship between controls and risk profiles. The contract remains the place to confirm the requirement for your engagement. Do not infer a level from being based in Portsmouth or working near a defence establishment.
Section 05
Prepare a submission that the business can approve
Allocate factual questions to the people who operate the systems. The MSP may know office device settings, while service managers know which support tools and project accounts are active. Reconcile those answers before the authorised representative reviews them.
If a required control is not implemented, record and complete remediation. A future contract amendment, planned tool replacement or draft policy is not evidence that the current environment already meets the requirement. Allow time for controlled changes rather than relying on the assessor to resolve operational ownership during review.
Use proportionate evidence. Configuration records should avoid revealing customer infrastructure details, live credentials or sensitive project material unnecessarily. Agree a suitable channel if more detailed information is needed to understand the scope.
Section 06
Keep the commercial message precise
When the certificate is issued, check the legal entity, scope and validity before sharing it. Explain what was assessed without extending the claim to customer networks or every subcontractor organisation. Where a buyer wants additional evidence, respond to that request separately.
Maintain the same discipline at renewal. New subcontractors, support applications or remote-access arrangements can change the environment between assessments. Review those changes when they are introduced and keep a current scope explanation with the supplier evidence pack. This makes the certificate easier to use responsibly across different Portsmouth and national customer engagements.
For subcontracted support, identify who approves each remote account and who checks its removal when the support agreement ends.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Portsmouth businesses
Swipe across the table to view all columns.
Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Portsmouth
Portsmouth City Council describes Portsmouth International Port’s role in marine-related business and supply chains. The guide separates a supplier’s technical baseline from port operations and any distinct defence-contract obligations.
Business contexts covered
- Marine-related suppliers
- Port services
- Technical support businesses
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Portsmouth City Council: Portsmouth International Port - The port’s local business and supply-chain role, not supplier certification conditions.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Related guides
Continue reading
Guides
Cyber Essentials Southampton: a practical certification guide
Southampton businesses working in maritime and logistics services should define what their Cyber Essentials certificate covers before using it in customer assurance. A supplier’s office and business systems are not the same thing as a vessel, port or customer-operated network.
Read articleGuides
Cyber Essentials Woking: a practical certification guide
Woking engineering and technical-service businesses should select Cyber Essentials from the customer’s written requirement and the organisation’s actual operating model. Supplying an automotive or technology company does not, by itself, determine whether CE, Plus or another assurance route is required.
Read articleGuides
Cyber Essentials Hull: a practical certification guide
Hull suppliers preparing for Cyber Essentials should begin with the service they operate and the systems their people use. Working in a port-related or renewable-energy supply chain does not automatically mean the certificate covers operational infrastructure or satisfies every customer security condition.
Read article

