Cyber Essentials Southampton: a practical certification guide
Southampton businesses working in maritime and logistics services should define what their Cyber Essentials certificate covers before using it in customer assurance. A supplier’s office and business systems are not the same thing as a vessel, port or customer-operated network.

Section 01
Cyber Essentials Southampton: a practical certification guide
Southampton businesses working in maritime and logistics services should define what their Cyber Essentials certificate covers before using it in customer assurance. A supplier’s office and business systems are not the same thing as a vessel, port or customer-operated network.
Section 02
Start with the service you operate
Southampton City Council’s sector information identifies maritime and logistics activity as part of the local economy. That provides context for examining dispersed staff, customer portals and technical support arrangements. It does not establish a certification mandate for every maritime supplier.
Write a short account of the work your organisation performs. Identify where people access business information and which systems you administer. If staff work at customer premises or travel, the registered office address alone will not describe their technology use. Use the current scheme requirements to settle the scope with your assessor.
Section 03
Example: a marine-service supplier with travelling staff
Consider an illustrative Southampton service company whose coordinators work ashore while technical staff visit customers. Employees use company laptops, mobile email and customer booking or support portals. A buyer has requested a certificate for supplier renewal.
The first check is device visibility. Establish whether equipment used away from the office remains part of the normal management and update process. A device that has not reported recently should prompt investigation; its absence from a current report is not proof that it no longer exists or is out of scope.
Next, review the software installed for customer assignments. Remote-support utilities and specialist tools may have been added for a single visit. Identify which are still authorised and supported, who can install them and how they are removed when no longer needed.
Where the customer restricts connectivity or changes on site, explain that arrangement to the assessor and operational owner. Do not assume that travel or intermittent access automatically creates an exception to a required control. Plan a compliant management arrangement before a submission deadline makes the issue urgent.
Section 04
Separate your responsibilities from the customer’s
Record who operates each customer portal and who approves your users. Your responsibility for a company laptop is different from the customer’s responsibility for its hosted system. A clear account of that boundary helps prevent contradictory answers from service delivery and IT.
The certificate should not suggest that a vessel’s navigation, propulsion or safety systems have been assessed unless a separate, appropriate assurance activity actually covers the claim. Cyber Essentials is not a complete maritime cyber-risk programme or an approval to access another party’s infrastructure.
If additional testing is requested, agree its scope and authorisation separately. A customer relationship or a certification project does not itself permit scanning or inspecting systems that you do not own.
Section 05
Fit preparation around operational commitments
Obtain the exact certificate requirement, scope and evidence date from the buyer. Allocate time for devices to be reviewed, necessary changes to be completed and technical answers to be checked. A compliant self-assessment can be reviewed quickly, but that does not remove preparation work on equipment currently in the field.
Give each action a named owner. Where an MSP manages office IT while an engineering team manages specialist laptops, make the handover explicit. A gap between those teams can leave a relevant system unmanaged even when both believe their own part is complete.
Section 06
Share concise evidence after certification
Keep the certificate with a scope explanation that the commercial team can understand. Verify its entity, validity and coverage against each buyer request before uploading it. Do not substitute the basic certificate where Plus or another scheme is explicitly required.
Retain configuration evidence securely rather than putting customer operational information in a general bid folder. Review the scope when services expand, another remote-access tool is introduced or a new customer changes the working arrangement. This makes certification part of an ongoing control process without presenting the certificate as a guarantee of operational safety or uninterrupted service.
For travelling service staff, confirm who can disable a lost device account while the usual office contact is unavailable.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Southampton businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Southampton
Southampton City Council identifies maritime and logistics among the city’s key sectors. The guide focuses on the supplier’s shore-side business systems and remote-working arrangements; it does not claim certification of vessels, ports or maritime safety.
Business contexts covered
- Maritime services
- Logistics support
- Marine technology
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Southampton City Council: key sectors - Local maritime and logistics activity.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Hull: a practical certification guide
Hull suppliers preparing for Cyber Essentials should begin with the service they operate and the systems their people use. Working in a port-related or renewable-energy supply chain does not automatically mean the certificate covers operational infrastructure or satisfies every customer security condition.
Read articleGuides
Cyber Essentials Swansea: a practical certification guide
Swansea organisations should begin Cyber Essentials with a clear account of the business systems they operate and the evidence a buyer has requested. A supplier working with a school, health organisation or council should not assume those relationships all carry the same certification conditions.
Read articleGuides
Cyber Essentials Bradford: a practical certification guide
Bradford businesses with several sites or different working teams should agree the Cyber Essentials scope before collecting answers. A certificate based on a head-office assumption can be difficult to use accurately if the organisation’s warehouse, workshop or remote staff operate through different systems.
Read article

