Skip to content
Guides

Can small businesses get Cyber Essentials?

Yes - Cyber Essentials is designed for UK small businesses. Fig Group prices the Micro tier for organisations with 1-9 staff at £299.99 + VAT. An eligible scheme-level cyber-liability benefit is arranged separately by IASME and its insurance partner.

A smiling woman stands in her coffee shop

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

4 min read

Share

Section 01

Can small businesses get Cyber Essentials?

Yes - Cyber Essentials is explicitly designed for UK small businesses. The Micro tier covers organisations with 1-9 staff at £299.99 + VAT with Fig Group. Eligible certificate holders may separately receive a cyber-liability benefit arranged by IASME and its insurance partner; eligibility criteria and policy terms apply, and Fig Group does not provide or arrange it.

Section 02

Who the Micro tier is for

  • Sole traders with employees or associates on payroll
  • Micro-limited companies (1-9 headcount)
  • Partnerships of up to 9 partners
  • Charities and community interest companies up to 9 staff
  • Owner-operated professional-services firms (consultancies, accountants, solicitors, designers)

Section 03

What small businesses get for £299.99 + VAT

  • A valid Cyber Essentials certificate, issued digitally and searchable through the IASME certificate search.
  • A separate IASME-arranged cyber-liability benefit where the holder meets the scheme eligibility criteria and policy terms.
  • Use of the Cyber Essentials badge in marketing, tender responses, and email signatures.
  • Evidence for tenders and supplier checks that request Cyber Essentials; the buyer's entity, scope, level and other conditions still determine eligibility.
  • Compliance evidence that the customer may choose to share with an insurer, broker, or underwriter; the recipient decides any insurance outcome.

Section 04

Is Cyber Essentials hard for small businesses?

The work depends on the devices, cloud accounts and controls already in place. The five controls - firewalls, secure configuration, user access, malware protection and security update management - are a practical baseline, but business competence alone does not establish readiness. Common gaps include:

  • Organisation-issued home-office routers still on factory default admin credentials (see remote and hybrid workforces). Ordinary privately owned home routers are outside the scheme boundary, while the business endpoint remains in scope.
  • Phones on out-of-support Android or older iOS.
  • One account used for both admin and daily email.

A free readiness check can flag possible gaps from your answers before you pay. It cannot detect every issue or replace the assessor's review.

Section 05

How long does it take for a small business?

Allow separate time to check scope, prepare controls and complete the questionnaire; time varies with the environment. Fig Group's Basic guarantee starts only after receipt of a complete, compliant submission before midday UK time on a UK Business Day, under the certification terms. Buying the assessment does not start that clock.

Section 06

Can sole traders get Cyber Essentials?

Yes. A one-person business is covered by the Micro tier at the same £299.99 + VAT. See Can a sole trader get Cyber Essentials? for a fuller answer.

Section 07

Bottom line

Cyber Essentials was designed with UK small businesses in mind. Fig Group offers it from £299.99 + VAT with a same-day SLA for compliant submissions. Eligible holders may separately receive an IASME-arranged cyber-liability benefit; Fig Group does not provide or arrange it.

Start Cyber Essentials from £299.99 + VAT | Free readiness check | Cyber Essentials Online

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group