Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.

Section 01
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Section 02
Enterprise technology context
Reading Borough Council’s profile describes ICT and business services as important parts of the local economy. That makes tenant administration, partner access and customer support useful preparation topics. It is not evidence that every technology vendor or enterprise customer imposes the same certification requirement.
Obtain the actual request before choosing CE or Plus. Confirm whether the buyer is asking about your corporate environment, a service delivered to it or a separately certified customer organisation. A familiar vendor badge or partnership status does not answer that question.
Section 03
Example: a reseller with delegated customer access
Consider a Reading-based reseller whose employees administer its own cloud tenant and have delegated access to several customer tenants. The business wants to use certification in enterprise onboarding. This is an illustrative example, not a claim about an existing Fig customer.
Start with the reseller’s own organisation. List staff devices, business services, privileged accounts and the systems used for support. Then document the customer-access arrangements separately. Identify who grants access, which roles are available and who can revoke them when an employee leaves or a contract ends.
Do not assume that a vendor’s security features are enabled merely because the business has the relevant licence. Confirm actual settings and the way administrators use them. A product capability is not evidence of implementation, particularly where different teams manage corporate IT and customer services.
Check whether legacy partner accounts, trial tenants or old remote-support tools remain active. These can fall outside a report focused only on the current main tenant. Record the owner and purpose of each service and resolve unnecessary access before the questionnaire is approved.
Section 04
Keep customer certification separate
Your company’s certificate does not automatically certify its customers. If you help a customer complete an assessment, keep its scope, evidence and authorised sign-off separate from your own. Likewise, a customer’s certificate does not establish that every part of your support organisation has been assessed.
Explain these distinctions in commercial material. A statement that your business holds Cyber Essentials is different from a claim that a particular managed service or software product has been independently tested. Where a buyer wants product testing or wider contractual assurance, scope that work explicitly.
Section 05
A practical handover between teams
Ask corporate IT to provide the information it controls, and service delivery to explain the support tools and access arrangements it operates. The commercial owner should supply the buyer’s exact wording and deadline. Bring unresolved boundaries to the assessor rather than allowing each team to assume another has covered them.
Use a concise evidence record. Identify the system, relevant control, responsible owner and date checked. Avoid exporting customer tenant details or credentials into a shared bid folder. Where more sensitive evidence is necessary, agree a suitable channel and limit it to the purpose of the review.
The authorised representative should review the final submission. This is particularly important when the company’s technical knowledge makes it tempting to treat the questionnaire as a routine administrative task. Accurate answers still require confirmation of the environment being certified.
Section 06
Plan for changes in the partner portfolio
Adding another vendor, acquiring a support business or changing the remote-management platform can affect the organisation’s controls. Review those changes when they happen and keep the scope description current. A previous certificate is not proof that a newly acquired tenant or service uses the same arrangements.
Before sharing the certificate, verify its entity, scope and validity against the buyer’s request. If the requirement is Plus or another scheme, address it directly rather than presenting the basic certificate as equivalent. Clear boundaries and current evidence make a supplier response more credible than broad claims about the security of an entire partner ecosystem.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Reading businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Reading
Reading Borough Council’s profile identifies ICT and business services as important parts of the local economy. The guide focuses on corporate tenants, reseller access and service boundaries, without asserting that any named technology company mandates certification for all partners.
Business contexts covered
- Technology suppliers
- Business services
- Enterprise support
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Reading Borough Council: profile of Reading - The local ICT and business-services context.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Aberdeen: a practical certification guide
Aberdeen energy-service suppliers should be precise about what a Cyber Essentials certificate demonstrates. It can provide a technical baseline for the assessed organisation, but it is not a complete assurance statement about offshore operations, industrial systems or every customer environment supported by its staff.
Read articleGuides
Cyber Essentials Dundee: a practical certification guide
A Dundee studio or digital supplier preparing for Cyber Essentials should distinguish its organisational IT controls from assurance about the content or software it produces. The certificate can support a customer conversation, but it does not certify that a game, application or production pipeline is free from every security issue.
Read articleGuides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read article

