Skip to content
Guides

Cyber Essentials Plymouth: a practical certification guide

For a Plymouth marine-technology supplier, Cyber Essentials should be described as an assessment of defined organisational controls. It is not a certificate of vessel safety, autonomous-system performance or the security of every piece of equipment a business develops or supports.

a view of a harbor with a sailboat in the wat

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

5 min read

Share

Section 01

Cyber Essentials Plymouth: a practical certification guide

For a Plymouth marine-technology supplier, Cyber Essentials should be described as an assessment of defined organisational controls. It is not a certificate of vessel safety, autonomous-system performance or the security of every piece of equipment a business develops or supports.

Section 02

Marine innovation and supplier assurance

Plymouth City Council’s marine-autonomy announcement provides a local setting for businesses developing and supporting marine technology. It does not establish that all participants or suppliers must hold the same cyber certificate.

Before purchasing, obtain the specific customer requirement. Ask which organisation must be certified, whether CE or Plus is requested and whether other contractual standards apply. If DCC is named, confirm the required level and risk profile separately rather than inferring it from the maritime or defence connection.

Section 03

Example: a supplier running demonstrations and field trials

Imagine a Plymouth company whose staff use office systems, development tools and equipment for customer demonstrations. A commercial partner asks for organisational certification. This is a planning scenario, not a report of a Fig Group engagement or a named marine programme.

The first task is to map the company’s systems and connections. Identify which devices access business information, who administers them and whether field equipment relies on a connected support laptop. Ask the assessor how the current scope rules apply; neither the word prototype nor the word operational automatically resolves the question.

Next, review temporary arrangements introduced for trials. A remote-access tool, supplier account or shared dashboard may remain after an event. Identify which services are still authorised and necessary, and who is responsible for removing access when the trial ends.

Check supporting software on development and field devices. A specialist application can depend on an operating system or component with a different support lifecycle. Agree how required updates are managed without bypassing the organisation’s safe testing and change process. If remediation is needed, complete it before declaring that the control is implemented.

Section 04

Keep product and operational assurance separate

Cyber Essentials is not a substitute for assessing the security of autonomous decision-making, communications links or application logic. If a customer requests product testing or a specialist system review, define that work separately. Be clear about which evidence comes from organisational certification and which comes from other assurance activities.

Likewise, a certificate does not authorise access to a customer’s equipment or test environment. Obtain the relevant permission before any scanning or testing. An existing commercial relationship does not provide unlimited authority to inspect connected systems.

Section 05

Defence requirements depend on the contract

The MOD Cyber Security Model describes the relationship between supplier controls and cyber risk profiles. Use the contract’s specified requirement to choose the route. A Plymouth address, marine customer or planned defence opportunity does not determine a DCC level.

Keep the buyer’s clarification with the assessment record. This helps the commercial and technical teams work to the same requirement and prevents a later renewal from relying on an assumption that applied only to an earlier engagement.

Section 06

Prepare evidence without exposing sensitive designs

Use a concise inventory, responsibility record and sanitised configuration evidence. Avoid sharing unreleased designs, customer trial data or live credentials through a general enquiry. If further detail is necessary, agree a suitable channel and confirm the disclosure is permitted.

Have the technical owner verify the facts and the authorised representative review the final answers. Where an MSP manages office IT but engineers manage trial devices, reconcile both sets of information before submission rather than assuming one provider covers everything.

After issue, retain the certificate with a clear scope explanation. Review that record when a prototype becomes a supported product, another field device is introduced or a customer changes the access arrangement. This keeps certification aligned with the business as it develops, without turning a defined technical baseline into a claim about every aspect of marine safety or product security.

For field trials, establish how equipment returns are recorded and who checks the device before it reconnects to routine business services.

Section 07

Certification, price and next steps

Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.

Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.

Section 08

Cyber Essentials prices for Plymouth businesses

Swipe across the table to view all columns.

Organisation sizeStaffCyber Essentials, excluding VAT
Micro1-9£299.99
Small10-49£399.99
Medium50-249£449.99
Large250-9,999£549.99

Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.

Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.

Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.

Local context and sources: Plymouth

Plymouth City Council’s June 2025 announcement describes the city’s marine-autonomy role. The guide separates organisational certification from product testing, operational safety and any defence-specific contractual requirements.

Business contexts covered

  • Marine technology
  • Engineering suppliers
  • Autonomy research businesses

Questions to discuss with your buyer

  • Which entity and certification level does the buyer require?
  • When must the evidence be available, and what scope is accepted?

Source references

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group