Skip to content
Guides

Cyber Essentials Cheltenham: a practical certification guide

A Cheltenham company should use Cyber Essentials to make a precise statement about its own technical controls, not to imply affiliation with the intelligence or defence community. Location and industry reputation are not substitutes for a defined scope, implemented controls and an authorised assessment submission.

a man standing in front of a park bench

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Cheltenham: a practical certification guide

A Cheltenham company should use Cyber Essentials to make a precise statement about its own technical controls, not to imply affiliation with the intelligence or defence community. Location and industry reputation are not substitutes for a defined scope, implemented controls and an authorised assessment submission.

Section 02

The Golden Valley context

Cheltenham Borough Council’s July 2026 announcement records the start of Golden Valley’s first construction phase and its cyber and technology focus. It describes a development in progress. It should not be used to claim that the campus is already fully operational or that every associated supplier has a specific certification obligation.

For a business considering opportunities in the area, the practical step is to read the actual customer requirement. Ask which entity needs certification, what level is specified and when evidence is required. Keep personnel, physical access and contractual information-handling conditions separate from the CE assessment.

Section 03

Example: a security consultancy with demonstration tools

Imagine a Cheltenham consultancy that provides advice and maintains laboratory or demonstration environments alongside ordinary business IT. It wants to certify the company before a customer review. This is an illustrative scenario, not a description of a Fig Group client or government engagement.

Start by identifying which systems are used for company business and who administers them. Explain the purpose and connectivity of specialist environments to the assessor. Do not assume that a system is automatically outside scope because it is called a lab, or that the presence of security tools proves the organisation meets every scheme requirement.

Check administrative access across business services, development resources and support tools. A small team may have accumulated broad privileges because each person originally performed several roles. Review what is needed now and confirm the controls actually applied to the relevant accounts.

Record software support and update responsibilities. Security professionals can still use unmanaged devices or unsupported supporting applications. The assessment should be based on factual configuration information rather than the team’s expertise or a general statement about its security culture.

Section 04

Keep authorisation and certification distinct

Cyber Essentials does not authorise testing of a customer’s network or give access to sensitive facilities. Any scanning, penetration testing or investigation needs its own agreed scope and permission. Do not treat the certification project as an opportunity to inspect systems beyond the organisation’s authority.

If a defence contract specifies DCC, consult the MOD Cyber Security Model and the actual risk-profile requirement. Proximity to GCHQ or a cyber campus does not determine a certification level. Confirm the route before purchasing rather than assuming CE, Plus and DCC are interchangeable.

Section 05

Evidence suitable for sensitive work

Prepare system descriptions and sanitised configuration records. Avoid putting customer vulnerabilities, classified material, access credentials or sensitive project details into a general enquiry. If further information is needed, agree an appropriate channel and verify that the disclosure is authorised.

The business representative approving the submission should understand both the scope and the limits of the certificate. A specialist employee’s assessment expertise does not remove the need for organisational review and sign-off.

Section 06

Use the certificate without implying endorsement

Once issued, share the certificate with an accurate account of the assessed entity and systems. Do not imply that it establishes government endorsement, clearance or approval of every consultancy method. Additional customer requirements remain separate even where the organisation already has a strong technical reputation.

Keep a record of the requirement that led to the chosen route and review it when new engagements begin. A new service, demonstration environment or remote-support arrangement may change the organisation’s control information before renewal.

Treat the emerging local technology activity as a reason to prepare well, not a promise of procurement success. Clear scope, accurate evidence and realistic preparation time are more useful to a prospective customer than broad claims about being secure by association with a place or institution.

Keep demonstration accounts separate from routine administration, with an identified owner who can explain their purpose and remove access when demonstrations finish.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Cheltenham businesses

Swipe across the table to view all columns.

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Cheltenham

Cheltenham Borough Council reported the start of Golden Valley’s first construction phase in July 2026. The guide treats the development as an emerging local context, not an already completed campus or evidence of certification conditions for tenants and suppliers.

Business contexts covered

  • Cybersecurity services
  • Technology businesses
  • Defence-related suppliers

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group