Skip to content
Guides

Cyber Essentials Woking: a practical certification guide

Woking engineering and technical-service businesses should select Cyber Essentials from the customer’s written requirement and the organisation’s actual operating model. Supplying an automotive or technology company does not, by itself, determine whether CE, Plus or another assurance route is required.

a street lined with stone buildings and trees

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Woking: a practical certification guide

Woking engineering and technical-service businesses should select Cyber Essentials from the customer’s written requirement and the organisation’s actual operating model. Supplying an automotive or technology company does not, by itself, determine whether CE, Plus or another assurance route is required.

Section 02

A local engineering reference with clear limits

Woking Borough Council’s planning record identifies the McLaren Technology Centre on Chertsey Road. This historical location reference provides context for an engineering-supplier example. It is not evidence of current procurement conditions, customer relationships or certification mandates.

For an actual opportunity, obtain the security schedule and ask which entity must provide evidence. A design service, equipment supplier and outsourced support company may face different questions. Keep the certificate request separate from product quality, engineering standards and contractual confidentiality requirements.

Section 03

Example: a small design supplier with customer transfer tools

Imagine a Woking consultancy whose designers use specialist workstations and customer file-transfer services. It has a managed office environment but several project-specific utilities. This is an illustrative preparation scenario, not a statement about a named manufacturer or Fig engagement.

Start by listing the systems used to create, store and exchange business information. Identify who administers the workstations, transfer accounts and remote-support tools. A customer-approved transfer service does not prove that the supplier’s own endpoints meet the relevant controls.

Review software support across the working environment. The principal design package may be maintained while a plug-in, operating system or remote utility is not. Ask the technical owner for factual version and support information. Where a change needs testing against a design workflow, schedule it before the assessment deadline rather than describing a future upgrade as completed.

Check project accounts when work ends. A supplier can retain access to customer folders or support tools after the commercial team considers the engagement closed. Establish who requests removal, which organisation performs it and how the company confirms its own accounts are no longer needed.

Section 04

Scope the organisation accurately

Confirm the legal entity that should appear on the certificate. If the business has a workshop, home workers or another office, discuss those arrangements with the assessor under the current scheme requirements. Do not assume that only the registered address matters.

A customer network should not be presented as certified through your organisation’s assessment simply because employees can access it. Record which controls belong to the customer and which belong to the supplier. This helps technical and commercial staff answer the same question consistently.

Section 05

Separate CE from wider engineering assurance

Cyber Essentials does not validate a design, certify vehicle safety or assess every product vulnerability. If the customer requests specialist testing or another management standard, address it separately. A certificate can be useful supplier evidence without replacing those obligations.

Where the requirement is unclear, ask the buyer before purchase. Do not rely on an informal statement that another supplier used the basic certificate. The requested level, scope and timing need to match your own engagement.

Section 06

Prepare an efficient internal review

Give the MSP or IT owner a concise scope description and list of project tools. Involve the engineering team where it manages applications or equipment outside the normal office process. Assign responsibility for every unresolved control and confirm completed remediation before submission.

Use configuration evidence without sharing confidential customer designs, live passwords or unnecessary personal information. Agree an appropriate channel if more detailed material is required. The authorised representative should review the final answers and understand what the certificate will and will not cover.

After certification, retain the scope record with customer assurance material. Revisit it when another design platform, remote-support arrangement or business entity is introduced. Check the certificate’s validity and coverage before sharing it with a new buyer. This makes the certification a reliable statement about the company rather than a broad claim about every engineering project in which it participates.

For customer transfer tools, record the administrator contact and access-removal process so project closure does not leave unattended file-sharing accounts.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Woking businesses

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Woking

Woking Borough Council’s published planning record identifies the McLaren Technology Centre on Chertsey Road. That is a specific local engineering reference, not evidence that McLaren or every associated supplier imposes Cyber Essentials requirements.

Business contexts covered

  • Engineering suppliers
  • Automotive-related services
  • Technical consultancies

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig handles this?

Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig