Cyber Essentials for Accountants: Protecting Client Financial Data in 2026
Accountancy firms are data controllers under UK GDPR, handling sensitive financial records for thousands of clients. Here is why Cyber Essentials certification is becoming the expected benchmark for the profession.

Section 01
Cyber Essentials for Accountants: Protecting Client Financial Data in 2026
Accountancy practices sit on a goldmine of data that cyber criminals want. Tax returns, payroll records, bank details, company accounts, personal financial statements - the breadth of sensitive information flowing through even a small practice is significant.
The regulatory bodies have taken notice. ICAEW publishes dedicated cyber security guidance for its members. ACCA publishes cybersecurity resources. Under UK GDPR, a practice must identify when it acts as controller or processor and apply appropriate technical and organisational measures for its processing risks.
Cyber Essentials certification provides a structured, verifiable way to demonstrate that those measures are in place.
Section 02
The Regulatory Landscape
Accountancy firms in the UK operate under several overlapping regulatory obligations:
UK GDPR and the Data Protection Act 2018 - Determine when the practice acts as controller or processor. Apply appropriate technical and organisational measures proportionate to the processing risks; encryption and access controls are relevant safeguards, but neither the law nor a Cyber Essentials certificate creates a universal product list or settles all obligations.
ICAEW guidance - the Institute of Chartered Accountants in England and Wales publishes cyber security resources and actively recommends that member firms adopt recognised certification standards. While ICAEW does not currently mandate Cyber Essentials, its guidance on "appropriate systems and controls" aligns closely with the five Cyber Essentials control themes.
ACCA resources - ACCA’s cybersecurity guidance can support preparation. Firms seeking best practice can use these resources; guidance and training do not establish a universal firm-certification requirement; check applicable membership, regulatory and client conditions.
Professional indemnity insurance - PI insurers for accountancy practices increasingly ask about cyber security controls during the renewal process. Holding Cyber Essentials provides a clear, third-party-verified answer.
Client expectations - enterprise clients and public sector organisations increasingly require their professional advisers to hold Cyber Essentials. If your practice advises government departments, NHS trusts, or large corporates, expect to be asked for your certificate.
Section 03
Why Accountancy Firms Are Targeted
Accounting practices are targeted because of what they hold and how they operate:
Volume of sensitive data. A mid-sized practice might hold tax records, bank details, and payroll data for hundreds of clients. That data has direct financial value to criminals. Stolen tax records can be used to file fraudulent returns. Payroll data enables identity theft. Bank details enable direct financial fraud.
Seasonal pressure. Tax deadlines create periods of intense pressure where staff are working long hours and processing large volumes of data. These are exactly the conditions where phishing emails succeed - a well-crafted message impersonating HMRC or a client is more likely to be clicked when staff are under time pressure.
Client trust. The relationship between an accountant and their client is built on trust. Clients share their most sensitive financial information without hesitation. That trust is destroyed in the event of a breach, and for a profession built on relationships, the commercial damage extends far beyond the immediate incident.
Small firm vulnerability. Small practices can be exposed through compromised accounts, malicious attachments and unsupported software. Assess those risks even without a dedicated IT team; business size alone does not establish protection.
Section 04
What Cyber Essentials Covers
The five controls address the most common attack vectors that accountancy firms face:
Firewalls - protecting the boundary between your practice network and the internet. For cloud-first practices, this includes the configuration of your cloud services and the settings on your staff devices.
Secure configuration - removing default passwords, disabling unnecessary services, and hardening your systems. This applies to your accounting software (Xero, Sage, QuickBooks), your document management system, and your email platform.
Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.
Malware protection - Use an applicable supported scheme-permitted approach, such as anti-malware or application allow-listing on relevant computers, and the approved-app-store/application-signing approach where applicable to mobiles.
Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.
Section 05
Making Tax Digital and Cloud Accounting
The shift to Making Tax Digital and cloud-based accounting platforms (Xero, QuickBooks Online, FreeAgent) has changed the security landscape for practices. Data that was once stored on local servers is now in the cloud, accessible from anywhere.
This makes access control and MFA more important than ever. If your team can access client records from any device with an internet connection, the security of those access credentials is the primary barrier between a threat actor and your client data.
Cyber Essentials v3.3 addresses this directly by mandating MFA for all cloud services. If your practice uses cloud accounting software, cloud document storage, or cloud email, MFA must be enforced on every one of those services.
Section 06
The Certification Process
For accountancy practices, getting certified is straightforward:
1. Check your readiness - Use Fig Group's free readiness tool to assess your current position
2. Address common gaps - For accountancy firms, the most frequent issues are: MFA not enforced on cloud accounting platforms, shared user accounts between staff, and overdue Windows or macOS updates
3. Complete the assessment - The self-assessment questionnaire covers your actual technical configuration across the five control themes
Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.
For practices that want external verification (particularly useful when demonstrating compliance to enterprise clients), Cyber Essentials Plus adds an independent technical audit. Use a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation; successful assessment is required for issuance.
Section 07
Timing It Right
If your practice handles government contracts, public sector advisory work, or enterprise clients, you may already need Cyber Essentials. Check your existing contracts and terms of engagement for cybersecurity requirements.
For all other practices, the direction of travel is clear. Certification is moving from "nice to have" to "expected standard." Getting certified now - before it becomes a contractual requirement from a key client - puts you in a stronger position than scrambling to comply under deadline pressure.
Certificates are valid for 12 months. Many practices align their renewal with their professional indemnity insurance renewal or their annual compliance review, keeping all their governance documentation on the same cycle.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for London Criminal Barristers’ Chambers: What the BSB Does Not Require, But Everyone Is Asking For
The Bar Standards Board does not formally require Cyber Essentials. Solicitor firms, CPS counterparts, institutional lay clients, and insurers are increasingly asking for it. This guide covers how CE applies to a criminal barristers’ chambers in London and why the certification has become a practical necessity even without a formal mandate.
Read articleIndustry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleIndustry
Cyber Essentials for MSPs: Why Certification Is About to Become Non-Negotiable
The Cyber Security and Resilience Bill proposes duties for managed service providers that meet its defined scope. It does not currently impose a blanket Cyber Essentials certification duty on every MSP. Here is how to assess the proposal and prepare your service.
Read article

