Cyber Essentials Woking: a practical certification guide
Woking engineering and technical-service businesses should select Cyber Essentials from the customer’s written requirement and the organisation’s actual operating model. Supplying an automotive or technology company does not, by itself, determine whether CE, Plus or another assurance route is required.

Section 01
Cyber Essentials Woking: a practical certification guide
Woking engineering and technical-service businesses should select Cyber Essentials from the customer’s written requirement and the organisation’s actual operating model. Supplying an automotive or technology company does not, by itself, determine whether CE, Plus or another assurance route is required.
Section 02
A local engineering reference with clear limits
Woking Borough Council’s planning record identifies the McLaren Technology Centre on Chertsey Road. This historical location reference provides context for an engineering-supplier example. It is not evidence of current procurement conditions, customer relationships or certification mandates.
For an actual opportunity, obtain the security schedule and ask which entity must provide evidence. A design service, equipment supplier and outsourced support company may face different questions. Keep the certificate request separate from product quality, engineering standards and contractual confidentiality requirements.
Section 03
Example: a small design supplier with customer transfer tools
Imagine a Woking consultancy whose designers use specialist workstations and customer file-transfer services. It has a managed office environment but several project-specific utilities. This is an illustrative preparation scenario, not a statement about a named manufacturer or Fig engagement.
Start by listing the systems used to create, store and exchange business information. Identify who administers the workstations, transfer accounts and remote-support tools. A customer-approved transfer service does not prove that the supplier’s own endpoints meet the relevant controls.
Review software support across the working environment. The principal design package may be maintained while a plug-in, operating system or remote utility is not. Ask the technical owner for factual version and support information. Where a change needs testing against a design workflow, schedule it before the assessment deadline rather than describing a future upgrade as completed.
Check project accounts when work ends. A supplier can retain access to customer folders or support tools after the commercial team considers the engagement closed. Establish who requests removal, which organisation performs it and how the company confirms its own accounts are no longer needed.
Section 04
Scope the organisation accurately
Confirm the legal entity that should appear on the certificate. If the business has a workshop, home workers or another office, discuss those arrangements with the assessor under the current scheme requirements. Do not assume that only the registered address matters.
A customer network should not be presented as certified through your organisation’s assessment simply because employees can access it. Record which controls belong to the customer and which belong to the supplier. This helps technical and commercial staff answer the same question consistently.
Section 05
Separate CE from wider engineering assurance
Cyber Essentials does not validate a design, certify vehicle safety or assess every product vulnerability. If the customer requests specialist testing or another management standard, address it separately. A certificate can be useful supplier evidence without replacing those obligations.
Where the requirement is unclear, ask the buyer before purchase. Do not rely on an informal statement that another supplier used the basic certificate. The requested level, scope and timing need to match your own engagement.
Section 06
Prepare an efficient internal review
Give the MSP or IT owner a concise scope description and list of project tools. Involve the engineering team where it manages applications or equipment outside the normal office process. Assign responsibility for every unresolved control and confirm completed remediation before submission.
Use configuration evidence without sharing confidential customer designs, live passwords or unnecessary personal information. Agree an appropriate channel if more detailed material is required. The authorised representative should review the final answers and understand what the certificate will and will not cover.
After certification, retain the scope record with customer assurance material. Revisit it when another design platform, remote-support arrangement or business entity is introduced. Check the certificate’s validity and coverage before sharing it with a new buyer. This makes the certification a reliable statement about the company rather than a broad claim about every engineering project in which it participates.
For customer transfer tools, record the administrator contact and access-removal process so project closure does not leave unattended file-sharing accounts.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Woking businesses
| Organisation size | Staff | Cyber Essentials, excluding VAT |
|---|---|---|
| Micro | 1-9 | £299.99 |
| Small | 10-49 | £399.99 |
| Medium | 50-249 | £449.99 |
| Large | 250-9,999 | £549.99 |
Fig Group is the fastest and cheapest Cyber Essentials certification provider in the UK. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions, not the time your organisation needs to become ready or complete a Plus audit. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Woking
Woking Borough Council’s published planning record identifies the McLaren Technology Centre on Chertsey Road. That is a specific local engineering reference, not evidence that McLaren or every associated supplier imposes Cyber Essentials requirements.
Business contexts covered
- Engineering suppliers
- Automotive-related services
- Technical consultancies
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Woking Borough Council: McLaren Technology Centre planning record - Historical location reference only; no current ownership or procurement claim.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Discover how Fig helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Coventry: a practical certification guide
Coventry engineering suppliers should prepare for Cyber Essentials around the systems used to design, support and administer their services. A manufacturing customer’s name or an automotive project does not determine the certification level. The relevant contract and the organisation’s actual scope should do that.
Read articleGuides
Cyber Essentials Guildford: a practical certification guide
Guildford technology and professional-service businesses should make the distinction between organisational certification and product assurance clear from the outset. Cyber Essentials can demonstrate a technical baseline within scope, but it is not an independent security test of every application, game or specialist system the company develops.
Read articleGuides
Cyber Essentials Leeds: a practical certification guide
For a Leeds organisation, Cyber Essentials is most useful when the certificate answers a clear customer question and accurately describes the business assessed. Before beginning, establish whether a prospect wants the basic certification, independent technical verification through Plus, or additional assurance beyond either scheme.
Read article

