Cyber Essentials for Financial Services: FCA, PRA and Client Expectations
Financial services firms face unique scrutiny on cyber controls. Where does Cyber Essentials fit alongside FCA SYSC, PRA SS1/21, and client due-diligence expectations?

Section 01
Cyber Essentials for Financial Services: FCA, PRA and Client Expectations
UK financial-services firms may face regulator, principal-firm, network, client and insurer expectations for cyber controls. Which ones apply depends on the firm's permissions, activities and contracts. Cyber Essentials can provide baseline evidence where requested, but it does not satisfy every relevant duty.
This guide is for IFAs, wealth managers, principal firm networks, fund-management houses, and the long tail of FCA-authorised firms that are being asked for a Cyber Essentials certificate by a client, an insurer, or a regulator-adjacent due-diligence questionnaire.
Section 02
Does Cyber Essentials satisfy the FCA?
Cyber Essentials may provide useful baseline evidence, but no general FCA rule makes it compulsory for every firm. The FCA does not endorse a single cybersecurity standard. Its Senior Management Arrangements, Systems and Controls sourcebook (SYSC) sets proportionate expectations. For firms in scope of the operational-resilience rules, those rules began on 31 March 2022 and had a 31 March 2025 transition deadline.
For an FCA-authorised firm, the right controls and evidence depend on its activities, systems, customer data and any applicable operational-resilience rules. Cyber Essentials can help demonstrate assessed technical measures such as security updates, malware protection, access control, secure configuration and firewalls. It does not establish that every relevant control remains effective or that every regulatory duty is met.
Cyber Essentials does not cover the full operational-resilience requirements for firms to which those rules apply, including identifying important business services, setting impact tolerances and testing severe-but-plausible disruption. Cyber Essentials Plus and additional records may help, but a firm must assess the full applicable rules and its own evidence.
Section 03
Does it satisfy the PRA?
For PRA-regulated firms, Supervisory Statement SS1/21 on operational resilience and SS2/21 on outsourcing and third-party risk management cover materially more than Cyber Essentials. A PRA firm may ask some suppliers for Cyber Essentials or Plus under its own risk and contract approach. Check the actual firm and contract rather than assuming a universal Plus requirement.
If you are a PRA firm or its supplier, check the firm's own controls, supplier-risk process, questionnaire and contract. Neither role implies a universal Plus requirement.
Section 04
The principal firm and network case
A large share of UK retail financial advice is delivered through principal firm networks - St James's Place, Quilter, True Potential, and others. Network appointed representatives may receive their own cyber-security instructions from a principal firm. This is not an FCA requirement; it is a network-level supervision tool. For St. James's Place Partner practices, published material describes Cyber Essentials Plus or the approved Device-as-a-Service route; other networks must be checked separately.
For an appointed representative or Partner Practice, confirm the principal's current written instructions for the legal entity, device scope, accepted route, deadline and evidence upload. SJP's published Plus-or-approved Device-as-a-Service route should not be generalised to Quilter, True Potential or other networks.
Check the selected supplier's tier price and approved package; the £315 figure is not a verified market tariff. Preparation and the assessment clock are separate. The work and cost depend on the actual devices, cloud services and gaps.
Section 05
Wealth managers and the institutional client case
Wealth managers and discretionary fund managers may receive institutional-client due-diligence requests. A pension trustee, family office or corporate client may ask for Basic, Plus, equivalent evidence or another standard; check its actual questionnaire and contract. Do not infer a universal insurer or Pensions Regulator mandate for Plus.
Where a client specifies Plus, the difference is independent technical testing of the same controls. Ask the client why that level is needed and confirm the entity and scope it expects.
Section 06
Common scoping pitfalls in FS
Three scoping mistakes recur in financial services certifications.
The "back-office only" trap. Some firms try to scope out their client-facing front-office systems on the grounds that they are run by a third party. This is not how the scheme works. If you log into the system from a corporate device, that device is in scope. If your firm's data is in that system, the access controls protecting it are in scope.
Bring-your-own-device gaps. Adviser-owned mobile phones used for business email are a recurring blind spot. The 2026 scheme is unambiguous: a personally-owned device used to access organisational data is in-scope, and must meet the configuration baseline.
Cloud app sprawl. Inventory any CRM, planning tool, back-office system, client portal and research subscription that stores or processes organisational data. Check each service's scope and MFA for all human cloud-service users, including administrators. No firm-wide tool count or most-common failure rate is assumed.
Section 07
Fig Group's financial-services track
Fig Group can discuss certification scope with financial-services firms. Scope may include devices, Microsoft 365, CRM, planning tools and other cloud services according to the firm's actual estate. Ask what preparation support is available for those systems and the applicable principal or network requirement; no pre-populated answer establishes compliance.
The published Basic guarantee applies after receipt of a complete, compliant submission before midday UK time on a UK Business Day, subject to certification terms. Kick-off, remediation and Plus testing have separate timelines. The cost is the same as for any other small business - published on the pricing page - with no FS premium.
Section 08
Next steps
If your network, insurer or client has asked for Cyber Essentials, start with its written requirement and the free readiness check, then confirm the assessment scope and current offer. Contact Fig Group to discuss the firm-specific route.
Talk to an FS specialist assessor → | Start the readiness check → | View pricing →
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Industry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleIndustry
Cyber Essentials for Accountants: Protecting Client Financial Data in 2026
Accountancy firms are data controllers under UK GDPR, handling sensitive financial records for thousands of clients. Here is why Cyber Essentials certification is becoming the expected benchmark for the profession.
Read articleIndustry
Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.
Read article

