Cyber Essentials Salisbury: a practical certification guide
Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.

Section 01
Cyber Essentials Salisbury: a practical certification guide
Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.
Section 02
Read the requirement before choosing a level
Dstl’s published information identifies its Porton Down location near Salisbury. The presence of a defence-science organisation provides relevant local context, but does not prove that every nearby supplier must hold Cyber Essentials, Plus and Defence Cyber Certification together.
For an actual opportunity, obtain the security schedule and any specified cyber risk profile. Establish whether the requirement concerns the organisation, the systems delivering the contract or a subcontractor. Ask which evidence must be available before award and which obligations continue during delivery. Keep physical access, personnel screening and technical certification requirements separate.
The MOD Cyber Security Model explains the relationship between defence supplier controls and risk profiles. If DCC is named in your contract, confirm its required level. Purchasing CE alone because it is quicker is not a substitute for satisfying a different contractual requirement.
Section 03
Example: a specialist consultancy with restricted project information
Consider a small consultancy preparing to provide scientific support from its Salisbury office. Staff use a company cloud environment and may receive access to a customer workspace. This is an illustrative preparation scenario, not an account of a Dstl procurement or a Fig Group customer.
The first task is to separate the company-managed environment from the customer-managed workspace. Record who administers accounts, what devices access each service and where information can be downloaded. Do not assume that a restricted customer environment automatically manages the supplier’s business email, laptops or other applications.
Review access arrangements without copying sensitive project information into the certification preparation file. A system name, responsible owner and description of the control can be sufficient for an initial scope discussion. Where evidence is required, agree how to share it securely and within the customer’s information-handling rules.
If a specialist application needs elevated permissions, establish how those permissions are controlled in practice. A software vendor’s recommendation is not the same as a scheme exemption. Identify a workable configuration with the technical owner and assessor before the authorised representative signs the questionnaire.
Section 04
Ask precise questions of third-party providers
A small supplier may rely on several organisations: an MSP for laptops, a building provider for connectivity and a customer for a project portal. List each responsibility rather than describing everything as outsourced IT. Ask for evidence relevant to the service they actually deliver.
For example, confirmation that the office firewall is managed does not answer whether remote-working devices receive security updates. A customer’s assurance about its portal does not show how your own user accounts are removed when a consultant leaves. Resolve those distinctions while there is time to act on the answers.
Section 05
Keep the certificate’s meaning clear
Cyber Essentials does not certify the safety of a scientific process, approve a handling arrangement for classified information or establish compliance with every defence contract clause. The certificate and its scope should be presented accurately alongside any additional evidence requested by the customer.
Avoid using an office location as a shorthand for certification coverage. If staff work from home, use shared facilities or support a customer on site, describe the actual business systems and applicable scope. The national requirements do not become narrower because the registered address is a small office.
Section 06
Plan around authorisation and remediation
Before purchase, identify who can approve the submission and who can implement changes. If a customer-controlled arrangement needs clarification, resolve it through the authorised contact rather than testing or changing the customer’s systems yourself. A certification project does not create permission to inspect another party’s infrastructure.
Allow time for necessary changes and internal approval before the buyer’s deadline. Retain the final scope explanation and contractual reference with the certificate. On renewal, check whether the service, access arrangements or required certification level has changed. An old successful submission is a useful starting record, not proof that a new engagement has identical requirements.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Salisbury businesses
Swipe across the table to view all columns.
Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Salisbury
Dstl lists its Porton Down location near Salisbury. That establishes a local defence-science connection, not a requirement for every nearby supplier to hold CE, Plus or DCC. The relevant contract determines the assurance needed.
Business contexts covered
- Defence-related services
- Scientific support
- Specialist consultancies
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Dstl: about us and locations - Dstl’s role and Porton Down location.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Liverpool: a practical certification guide
Liverpool businesses can use Cyber Essentials to demonstrate the scheme’s baseline controls without treating it as a guarantee of customer approval. The practical route is to identify the systems used for the service, establish the buyer’s requirement and complete any necessary changes before assessment.
Read articleGuides
Cyber Essentials Warrington: a practical certification guide
Warrington suppliers should approach Cyber Essentials as a defined assessment of their own technical controls, not as blanket approval for an energy or engineering supply chain. The starting point is the organisation delivering the service and the evidence its customer has actually requested.
Read articleGuides
Cyber Essentials Manchester: a practical certification guide
A Manchester organisation can complete Cyber Essentials online without changing certification standards or paying a location-based assessment premium. The important decisions are which organisation and systems the certificate will cover, what a customer has requested, and whether the controls are working before submission.
Read article

