Cyber Essentials Sheffield: a practical certification guide
Sheffield manufacturers and engineering suppliers should start Cyber Essentials preparation by mapping the connections between office IT, design work and operational support. The assessment needs a defensible scope; it should not rely on a broad statement that everything in a workshop is either automatically included or automatically exempt.

Section 01
Cyber Essentials Sheffield: a practical certification guide
Sheffield manufacturers and engineering suppliers should start Cyber Essentials preparation by mapping the connections between office IT, design work and operational support. The assessment needs a defensible scope; it should not rely on a broad statement that everything in a workshop is either automatically included or automatically exempt.
Section 02
Manufacturing collaboration in the Sheffield area
The University of Sheffield AMRC works in manufacturing research, with facilities in Sheffield and Rotherham. That provides useful regional context for suppliers working across research and production environments. It does not establish certification requirements for every AMRC partner or manufacturing contract.
Ask the buyer to identify the assurance required for your specific service. A design consultancy, a component supplier and a business administering another company’s systems can face different contractual questions. Keep the certificate request separate from engineering quality, safety and intellectual-property conditions.
Section 03
Example: taking a research process into production
Consider a Sheffield-area engineering business that has developed a process with external collaborators and is preparing for commercial production. Its office laptops, design workstations and equipment-support systems have grown through different projects. This is an example to guide preparation, not a customer case study.
Begin with a connection map. Establish how design files reach production equipment, who can administer supporting workstations and whether vendors have remote access. A machine that does not browse the internet may still depend on an internet-connected support computer. Record the actual arrangement and ask the assessor how the current scope requirements apply.
Check whether project accounts remain after a research collaboration ends. Identify any external users, temporary remote tools or shared storage areas that no longer serve an active purpose. Removing unnecessary access is a practical operational task; avoid treating it as merely an exercise in writing a stronger policy.
For specialist software, bring the engineering owner into the review. Support lifecycles and update arrangements may differ from office applications. If a change needs compatibility testing, schedule it early enough to complete the required work before submission. Planned remediation is not an implemented control.
Section 04
Do not confuse a certificate with a factory assessment
Cyber Essentials assesses defined technical controls within its agreed scope. It is not a complete industrial-control-system security review, a machinery safety assessment or proof that a manufactured product is secure. If the customer needs those assurances, identify the relevant specialist activity separately.
Where scope excludes part of a wider environment under an agreed, permissible arrangement, explain the boundary accurately. Do not market the certificate as covering the entire factory or group if it does not. A buyer should be able to understand what organisation and systems the certificate represents.
Section 05
Coordinate engineering, IT and commercial owners
The commercial team should provide the buyer’s request and deadline. IT should confirm the controls it operates. Engineering should explain specialist equipment, applications and support dependencies. The authorised representative should review the combined answers rather than receiving a completed questionnaire with unresolved assumptions hidden inside it.
Use a short action register to settle gaps. Name the owner, required change and evidence of completion. Where several suppliers support the environment, ask which party manages each control instead of assuming the existence of support contracts answers the assessment questions.
Protect confidential designs during evidence gathering. Prefer configuration information and sanitised system descriptions over exporting customer drawings or live production records. Agree an appropriate channel if more detailed material is necessary.
Section 06
Build certification into normal change management
After issue, retain the certificate, scope explanation and key decisions with the supplier-assurance record. When another production line, remote support arrangement or design service is introduced, check whether the existing description is still accurate. Changes should be reviewed when they happen, not discovered only at renewal.
Before sending the certificate to a customer, verify the name, scope and validity against its request. If the buyer asks for Plus or a different scheme, resolve that explicitly. An engineering location or a familiar customer name is not a reliable shortcut for selecting the right certification route.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Sheffield businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Sheffield
The University of Sheffield AMRC operates facilities in Sheffield and Rotherham. Its manufacturing research role supports a guide about collaboration and production-support systems; it is not evidence of a blanket certification condition imposed by AMRC or its partners.
Business contexts covered
- Advanced manufacturing
- Engineering research
- Specialist suppliers
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- University of Sheffield AMRC: locations - AMRC facilities across Sheffield and Rotherham.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Derby: a practical certification guide
For Derby engineering businesses, a useful Cyber Essentials assessment starts with a precise description of how the organisation works. Design, workshop, field-service and office teams can use different systems. The certificate should describe the agreed scope accurately rather than suggest that every activity in an industrial group has been assessed.
Read articleGuides
Cyber Essentials Coventry: a practical certification guide
Coventry engineering suppliers should prepare for Cyber Essentials around the systems used to design, support and administer their services. A manufacturing customer’s name or an automotive project does not determine the certification level. The relevant contract and the organisation’s actual scope should do that.
Read articleGuides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read article

