Cyber Essentials Swansea: a practical certification guide
Swansea organisations should begin Cyber Essentials with a clear account of the business systems they operate and the evidence a buyer has requested. A supplier working with a school, health organisation or council should not assume those relationships all carry the same certification conditions.

Section 01
Cyber Essentials Swansea: a practical certification guide
Swansea organisations should begin Cyber Essentials with a clear account of the business systems they operate and the evidence a buyer has requested. A supplier working with a school, health organisation or council should not assume those relationships all carry the same certification conditions.
Section 02
A service-delivery setting for preparation
Swansea Council’s 2025 economic profile describes public administration, health and education among the local employment settings. This is background for a guide about service suppliers, not proof of a procurement mandate.
For each opportunity, obtain the specific requirement. Identify the contracting entity, certificate level and evidence deadline. If the customer requests wider information-governance or service standards, keep those separate from CE rather than treating the certificate as approval for every aspect of the engagement.
Section 03
Example: an administrative service with distributed staff
Consider a Swansea business providing administrative support through office staff and people working remotely. It uses a business cloud tenant and a customer case-management portal. This is an illustrative scenario, not a statement about a named health, education or council customer.
Start by mapping where the organisation’s work takes place digitally. Identify the devices used to access business email and customer services, who manages them and which accounts are active. A registered office does not limit the assessment to the computers physically located there.
Check the boundary between the company tenant and the customer portal. Record which organisation administers each service and what happens when a worker leaves an assignment. Your company may need to remove its own access and request a separate action from the customer. Agree who follows up rather than assuming one leaver ticket covers both organisations.
If staff use personally owned devices, discuss their actual use and the applicable scope rules with the assessor. Do not omit them solely because they are not company assets. Equally, avoid copying sensitive customer records into an evidence file when configuration information can answer the technical question.
Section 04
Keep information governance visible
Cyber Essentials does not establish compliance with every obligation affecting health, education or personal information. It assesses a defined technical baseline. A customer may need additional evidence about the service, data handling or staff responsibilities, and those questions should be addressed on their own terms.
When completing a supplier questionnaire, explain which organisation and systems the certificate covers. Do not suggest that the customer’s case-management environment was certified through your assessment or that certification authorises new uses of its information.
Section 05
Welsh public-sector buying
Use the tender documents and official clarification route for the particular opportunity. Confirm whether CE, Plus or an accepted alternative is requested, and when the evidence must be available. This guide does not assume a central-government procurement note applies automatically to every Welsh public body.
Keep the written clarification with the bid record. This gives commercial staff, IT and the authorised signatory one agreed requirement to work towards. If a deadline is short, resolve uncertainty before purchasing the wrong assessment route.
Section 06
Prepare and maintain a factual record
Ask the MSP or technical owner for evidence of the controls it operates. The existence of a managed-service contract does not prove that every relevant device is enrolled or every cloud account configured correctly. Check the actual environment and assign remediation where necessary.
Have the authorised representative review the answers before submission. A planned change or draft policy should not be described as an implemented control. Allow time for required changes separately from the assessment turnaround.
Once certified, store the certificate with a concise scope explanation and renewal owner. Revisit the record when another service, customer portal or remote-working arrangement is introduced. Maintaining accurate access and device information during delivery makes the next assessment more straightforward and helps the business answer customer questions without overstating what the certificate proves.
For distributed administrative teams, identify who updates the access register when staff move between customer assignments, and how the technical owner is notified when an assignment ends.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Swansea businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Swansea
Swansea Council’s 2025 economic profile identifies public administration, health and education as significant employment settings. The guide considers suppliers working across those settings, without inferring any universal public-sector certification requirement.
Business contexts covered
- Health-related suppliers
- Education support
- Business administration services
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Swansea Council: 2025 economic profile - Historical local employment context, not current tender conditions.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Reading: a practical certification guide
Reading technology and business-service suppliers should distinguish certification of their own organisation from assurance about the products they resell or the customer environments they support. Cyber Essentials can provide a recognised baseline, but its scope must be clear in a proposal or supplier response.
Read articleGuides
Cyber Essentials Southampton: a practical certification guide
Southampton businesses working in maritime and logistics services should define what their Cyber Essentials certificate covers before using it in customer assurance. A supplier’s office and business systems are not the same thing as a vessel, port or customer-operated network.
Read articleGuides
Cyber Essentials Hull: a practical certification guide
Hull suppliers preparing for Cyber Essentials should begin with the service they operate and the systems their people use. Working in a port-related or renewable-energy supply chain does not automatically mean the certificate covers operational infrastructure or satisfies every customer security condition.
Read article

