Skip to content
Guides

Cyber Essentials Reading: a practical certification guide

Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.

A man in a suit walking down a wet street

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Reading: a practical certification guide

Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.

Section 02

Enterprise technology context

Reading Borough Council’s profile describes ICT and business services as important parts of the local economy. That makes tenant administration, partner access and customer support useful preparation topics. It is not evidence that every technology vendor or enterprise customer imposes the same certification requirement.

Obtain the actual request before choosing CE or Plus. Confirm whether the buyer is asking about your corporate environment, a service delivered to it or a separately certified customer organisation. A familiar vendor badge or partnership status does not answer that question.

Section 03

Example: a reseller with delegated customer access

Consider a Reading-based reseller whose employees administer its own cloud tenant and have delegated access to several customer tenants. The business wants to use certification in enterprise onboarding. This is an illustrative example, not a claim about an existing Fig customer.

Start with the reseller’s own organisation. List staff devices, business services, privileged accounts and the systems used for support. Then document the customer-access arrangements separately. Identify who grants access, which roles are available and who can revoke them when an employee leaves or a contract ends.

Do not assume that a vendor’s security features are enabled merely because the business has the relevant licence. Confirm actual settings and the way administrators use them. A product capability is not evidence of implementation, particularly where different teams manage corporate IT and customer services.

Check whether legacy partner accounts, trial tenants or old remote-support tools remain active. These can fall outside a report focused only on the current main tenant. Record the owner and purpose of each service and resolve unnecessary access before the questionnaire is approved.

Section 04

Keep customer certification separate

Your company’s certificate does not automatically certify its customers. If you help a customer complete an assessment, keep its scope, evidence and authorised sign-off separate from your own. Likewise, a customer’s certificate does not establish that every part of your support organisation has been assessed.

Explain these distinctions in commercial material. A statement that your business holds Cyber Essentials is different from a claim that a particular managed service or software product has been independently tested. Where a buyer wants product testing or wider contractual assurance, scope that work explicitly.

Section 05

A practical handover between teams

Ask corporate IT to provide the information it controls, and service delivery to explain the support tools and access arrangements it operates. The commercial owner should supply the buyer’s exact wording and deadline. Bring unresolved boundaries to the assessor rather than allowing each team to assume another has covered them.

Use a concise evidence record. Identify the system, relevant control, responsible owner and date checked. Avoid exporting customer tenant details or credentials into a shared bid folder. Where more sensitive evidence is necessary, agree a suitable channel and limit it to the purpose of the review.

The authorised representative should review the final submission. This is particularly important when the company’s technical knowledge makes it tempting to treat the questionnaire as a routine administrative task. Accurate answers still require confirmation of the environment being certified.

Section 06

Plan for changes in the partner portfolio

Adding another vendor, acquiring a support business or changing the remote-management platform can affect the organisation’s controls. Review those changes when they happen and keep the scope description current. A previous certificate is not proof that a newly acquired tenant or service uses the same arrangements.

Before sharing the certificate, verify its entity, scope and validity against the buyer’s request. If the requirement is Plus or another scheme, address it directly rather than presenting the basic certificate as equivalent. Clear boundaries and current evidence make a supplier response more credible than broad claims about the security of an entire partner ecosystem.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Reading businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Reading

Reading Borough Council’s profile identifies ICT and business services as important parts of the local economy. The guide focuses on corporate tenants, reseller access and service boundaries, without asserting that any named technology company mandates certification for all partners.

Business contexts covered

  • Technology suppliers
  • Business services
  • Enterprise support

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig