Skip to content
Guides

Cyber Essentials Salisbury: a practical certification guide

Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.

brown brick house near bridge

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Salisbury: a practical certification guide

Salisbury businesses working with sensitive customers should confirm the requested certification before starting an assessment. Cyber Essentials provides a defined technical baseline. It should not be described as automatic approval to work with a defence establishment, handle classified information or access a customer’s facilities.

Section 02

Read the requirement before choosing a level

Dstl’s published information identifies its Porton Down location near Salisbury. The presence of a defence-science organisation provides relevant local context, but does not prove that every nearby supplier must hold Cyber Essentials, Plus and Defence Cyber Certification together.

For an actual opportunity, obtain the security schedule and any specified cyber risk profile. Establish whether the requirement concerns the organisation, the systems delivering the contract or a subcontractor. Ask which evidence must be available before award and which obligations continue during delivery. Keep physical access, personnel screening and technical certification requirements separate.

The MOD Cyber Security Model explains the relationship between defence supplier controls and risk profiles. If DCC is named in your contract, confirm its required level. Purchasing CE alone because it is quicker is not a substitute for satisfying a different contractual requirement.

Section 03

Example: a specialist consultancy with restricted project information

Consider a small consultancy preparing to provide scientific support from its Salisbury office. Staff use a company cloud environment and may receive access to a customer workspace. This is an illustrative preparation scenario, not an account of a Dstl procurement or a Fig Group customer.

The first task is to separate the company-managed environment from the customer-managed workspace. Record who administers accounts, what devices access each service and where information can be downloaded. Do not assume that a restricted customer environment automatically manages the supplier’s business email, laptops or other applications.

Review access arrangements without copying sensitive project information into the certification preparation file. A system name, responsible owner and description of the control can be sufficient for an initial scope discussion. Where evidence is required, agree how to share it securely and within the customer’s information-handling rules.

If a specialist application needs elevated permissions, establish how those permissions are controlled in practice. A software vendor’s recommendation is not the same as a scheme exemption. Identify a workable configuration with the technical owner and assessor before the authorised representative signs the questionnaire.

Section 04

Ask precise questions of third-party providers

A small supplier may rely on several organisations: an MSP for laptops, a building provider for connectivity and a customer for a project portal. List each responsibility rather than describing everything as outsourced IT. Ask for evidence relevant to the service they actually deliver.

For example, confirmation that the office firewall is managed does not answer whether remote-working devices receive security updates. A customer’s assurance about its portal does not show how your own user accounts are removed when a consultant leaves. Resolve those distinctions while there is time to act on the answers.

Section 05

Keep the certificate’s meaning clear

Cyber Essentials does not certify the safety of a scientific process, approve a handling arrangement for classified information or establish compliance with every defence contract clause. The certificate and its scope should be presented accurately alongside any additional evidence requested by the customer.

Avoid using an office location as a shorthand for certification coverage. If staff work from home, use shared facilities or support a customer on site, describe the actual business systems and applicable scope. The national requirements do not become narrower because the registered address is a small office.

Section 06

Plan around authorisation and remediation

Before purchase, identify who can approve the submission and who can implement changes. If a customer-controlled arrangement needs clarification, resolve it through the authorised contact rather than testing or changing the customer’s systems yourself. A certification project does not create permission to inspect another party’s infrastructure.

Allow time for necessary changes and internal approval before the buyer’s deadline. Retain the final scope explanation and contractual reference with the certificate. On renewal, check whether the service, access arrangements or required certification level has changed. An old successful submission is a useful starting record, not proof that a new engagement has identical requirements.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Salisbury businesses

Swipe across the table to view all columns.

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Salisbury

Dstl lists its Porton Down location near Salisbury. That establishes a local defence-science connection, not a requirement for every nearby supplier to hold CE, Plus or DCC. The relevant contract determines the assurance needed.

Business contexts covered

  • Defence-related services
  • Scientific support
  • Specialist consultancies

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group