Cyber Essentials Slough: a practical certification guide
Using professionally managed hosting does not automatically make an organisation Cyber Essentials compliant. For a Slough technology business, the important preparation step is to distinguish the facility, the hosted service and the controls that remain with the company using or administering them.

Section 01
Cyber Essentials Slough: a practical certification guide
Using professionally managed hosting does not automatically make an organisation Cyber Essentials compliant. For a Slough technology business, the important preparation step is to distinguish the facility, the hosted service and the controls that remain with the company using or administering them.
Section 02
Hosting location and organisational assurance
Equinix’s LD4 information identifies a facility at Slough Trading Estate. That is a concrete local setting for discussing hosting responsibilities. It does not establish that all tenants or suppliers need a particular certificate, or that a facility’s certifications transfer to each customer.
Read the service agreement to establish what the provider operates. Physical space, connectivity, managed infrastructure and a fully hosted application are different services. Your assessment answers need to reflect the arrangement you actually purchase, not the broad capabilities advertised by the provider.
Section 03
Example: a company using colocation and cloud services
Imagine a Slough business with equipment in a third-party facility, a business cloud tenant and staff working remotely. A customer asks for Cyber Essentials. This is an illustrative scenario, not a claim about an Equinix customer or Fig Group engagement.
Begin with responsibility boundaries. Identify who administers servers, who manages network configuration and who controls user access. A facility may provide power and physical security while your company or MSP remains responsible for software support, updates and accounts. Do not assume those responsibilities are included without checking the actual service.
Map the devices used to administer the hosted environment. A secure building does not establish the configuration of an administrator’s laptop or the way privileged access is used. Include those working arrangements in the scope discussion with the assessor.
Review old management interfaces, support accounts and services introduced during migrations. A workload moved to a new platform can leave an active account or unsupported component behind. Confirm what remains in use and who owns its management before signing off the assessment.
Section 04
Do not inherit another organisation’s certificate
The provider’s certification can be relevant evidence about its own service, but it is not automatically your organisation’s certificate. Check its scope and understand which responsibilities remain with you. The company seeking CE needs accurate answers about its own assessed environment.
Likewise, if your business hosts systems for customers, your certificate should not be marketed as automatically certifying every customer configuration. Describe the entity and scope assessed, and distinguish your controls from settings or devices administered by the customer.
Section 05
Prepare for buyer questions about more than CE
A customer may ask about availability, disaster recovery, data location or application security alongside certification. Cyber Essentials does not establish every one of those assurances. Answer them with appropriate service evidence and contractual information rather than extending the meaning of the certificate.
If the buyer requires Plus or a separate technical review, confirm the scope and plan that work explicitly. This guide does not claim that Slough Council, data-centre operators or enterprise customers all impose one procurement rule.
Section 06
Give each provider a precise evidence request
Create a short list of the controls and services for which you need information. Ask the relevant provider for factual confirmation, including the boundary of what it manages. A general assurance email may not answer a specific question about configuration or update responsibility.
Keep infrastructure details and live credentials out of a general enquiry form. Use sanitised configuration evidence and agree a suitable channel for more sensitive information. The authorised representative should review the final answers against the actual division of responsibility.
After certification, revisit the record when a workload moves, a hosting contract changes or a different MSP takes over. Those changes can alter who operates the controls even if the company’s address stays the same. Maintaining an accurate responsibility map makes future supplier responses and renewal assessments more reliable than relying on the reputation of a hosting location alone.
Where hosting and MSP responsibilities overlap, ask both providers to confirm the boundary in writing, including who handles account changes, software updates and incident-related access requests.
Section 07
Certification, price and next steps
Cyber Essentials is a UK government-backed scheme assessing five technical control areas: firewalls, secure configuration, security update management, user access control and malware protection. The requirements are national, not postcode-specific. Use IASME's current assessment questions and requirements for the version applicable to your assessment account.
Fig Group provides an online assessment service through Fig Compliance Ltd, its IASME-licensed certification body. There is no requirement to use a certification body with an office in your city. An MSP can prepare the assessment on your behalf; your organisation reviews and authorises the submission and provides the required portal sign-off. Answers must describe implemented controls, not planned improvements.
Section 08
Cyber Essentials prices for Slough businesses
Swipe across the table to view all columns.
Fig Group’s fastest and cheapest Cyber Essentials claim is scoped to the UK providers and equivalent offers covered by its dated published comparison; it is not a claim about every possible promotion, subsidy or preparation timetable. Our published price evidence and six-working-hour commitment explain the comparison and terms. Three rounds of assessor feedback are included. Buy certification on its own or add the optional Fig Group platform; a technology subscription is not required.
Standalone Cyber Essentials starts at £299.99 + VAT. Select the size of the organisation being certified on the pricing page to see the applicable fee. Remediation effort and any separately scoped services are distinct from the certification assessment price. Fig Group's published six-working-hour assessment commitment applies to compliant Cyber Essentials submissions received before midday on a UK business day, not the time your organisation needs to become ready or complete a Plus audit. Only complete Basic submissions are covered by that commitment; certificate issuance requires a successful assessment. See the turnaround terms.
Start with the free readiness check, then choose your certification. If your scope or buyer requirement is unclear, discuss it with Fig Group before purchasing. The readiness check is an initial guide, not a certification decision. Cyber Essentials Plus adds independent technical verification of the same control areas; neither certificate replaces contractual, sector-specific or broader risk-management obligations.
Local context and sources: Slough
Equinix identifies its LD4 facility at Slough Trading Estate. The guide uses this concrete hosting context to distinguish facility assurance from a tenant organisation’s own controls; it does not claim that Equinix requires all customers or suppliers to hold CE.
Business contexts covered
- Hosting customers
- Technology services
- Infrastructure suppliers
Questions to discuss with your buyer
- Which entity and certification level does the buyer require?
- When must the evidence be available, and what scope is accepted?
Source references
- Equinix: LD4 Slough facility - The facility’s Slough location, not certification inheritance or procurement conditions.
- IASME: current assessment questions and requirements - National assessment requirements; local economic sources do not establish buyer mandates.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Birmingham: a practical certification guide
A Birmingham business can arrange Cyber Essentials remotely, using the same control requirements as organisations elsewhere in the UK. The most useful preparation is to connect the certificate request to your legal entity, service and actual technology environment before buying an assessment.
Read articleGuides
Cyber Essentials Newcastle: a practical certification guide
A Newcastle technology business should prepare for Cyber Essentials by distinguishing the security of its own organisation from the security claims it makes about a product. Certification can demonstrate the scheme’s technical baseline within scope; it does not automatically certify that an application is free from vulnerabilities.
Read articleGuides
Cyber Essentials Nottingham: a practical certification guide
For a Nottingham business, Cyber Essentials preparation should make the responsibilities around shared services clear. This is particularly useful when a company has grown from a small research team into an organisation with employees, external collaborators and a commercial customer base.
Read article

