Skip to content
Industry

Cyber Essentials for charities: how to budget at £299.99 + VAT

UK charities have tight budgets and specific scoping questions. This guide walks through how to certify at the £299.99 tier, the current funding position, and how to meet the v3.3 requirements without over-engineering.

clear glass jar with coins

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

10 min read

Share

Section 01

Cyber Essentials for charities: how to budget at £299.99 + VAT

UK charities face two Cyber Essentials questions that most other sectors do not:

1. Some funders and grant-giving bodies specify Cyber Essentials or another standard. Check the actual grant terms, required scope and accepted evidence rather than assuming a universal funding condition.

2. Charity budgets are tight, and every pound spent on compliance is a pound not spent on mission delivery.

This guide is for the charity CEO, COO, or finance director trying to answer: "What is the cheapest legitimate path to Cyber Essentials?"

The answer is £299.99 + VAT at the Micro tier for charities 1–9 people in the applicable scheme size count, rising to £449.99 + VAT at Medium tier. Below the standard IASME fee. Below the "consultancy-plus-certification" packages that some providers push.

Section 02

How to interpret a funder’s request

Where a funder asks for cybersecurity assurance, establish which wording applies:

  • "Cyber Essentials certification." CE at the appropriate size tier is sufficient.
  • "Cyber Essentials Plus certification." CE Plus - third-party verified - is the ask; starts at £1,499.99 + VAT for micro organisations.
  • "A recognised cybersecurity standard." CE is one recognised baseline standard; confirm that the funder accepts it for the requested scope.

If the funder lists specific frameworks (ISO 27001, NIST CSF), the charity sometimes has a genuinely harder decision. Choose CE, Plus or another standard using the actual funder wording; do not infer acceptance from a generic assurance request.

Section 03

Budgeting the Micro tier (1–9 people in the applicable scheme size count)

The Fig Group Micro tier is £299.99 + VAT - £20.01 below the standard IASME certification body fee. For a 9-person charity that is approximately £40.00 per person per year including 20% VAT, or £0.11 per day, assuming nine people in the applicable size count. Affordability depends on the charity’s budget.

What is included:

  • The full CE v3.3 self-assessment.
  • Expert review by an IASME-licensed assessor.
  • Up to three free feedback rounds to help correct the submission; this is not unlimited resubmission or a guaranteed pass.
  • The official certificate, issued via Blockmark and verifiable through the IASME Certificate search tool.
  • Dedicated support through the process.
  • Free readiness checker before you begin.

What is not included (to be honest about the full total cost):

  • Any remediation work. If your charity needs to buy Defender for Business, deploy MFA, or upgrade unsupported Windows devices, that is a separate cost.
  • VAT. £299.99 becomes £359.99 inc VAT.

A prepared 9-person charity may need no additional technology purchases if its existing supported devices and configured services meet every applicable requirement. Budget separately for actual remediation and obtain quotes for replacement kit, implementation and licensing; a staff count does not establish the remediation cost.

Section 04

The funder discount question

The NCSC Funded Cyber Essentials Programme is currently closed. Do not budget on an available free place. Any future programme will have its own eligibility, scope and terms.

Fig Group’s £299.99 + VAT Micro price is its cheapest Basic tier and a practical starting budget for 1–9 staff. Any UK-wide cheapest claim needs a dated like-for-like comparison of IASME-licensed providers, included assessment and feedback, VAT and support; it is not a guarantee that no promotion or subsidy can undercut it.

Section 05

Scoping: volunteers and trustees

Charity CE scoping has two category-specific questions:

Volunteers and trustees. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor. The v3.3 ownership table specifically includes volunteers’, trustees’ and university research assistants’ BYOD used for organisational work; do not classify these roles as excluded third-party contractors. Students’ own devices are excluded, while organisation-owned student devices are included. Organisational accounts remain in scope.

Record whether each person is an employee, office-holder or third party and confirm any ambiguous relationship with the Certification Body. Portals, prevention of local storage and virtual desktops can control exposure but do not themselves establish a device exclusion.

Section 06

Required technical controls for a charity

Under v3.3 the five control categories apply the same way regardless of sector. For a typical small charity:

  • Firewalls. Relevant device and office-network firewalls, plus the documented cloud provider/customer responsibility split. Change the default admin password.
  • Secure configuration. Remove bloatware from laptops. Disable auto-run. Disable guest accounts.
  • User access control. MFA for every user account accessing in-scope cloud services. Use M365 Business Premium's built-in MFA.
  • Malware protection. A correctly configured supported anti-malware solution such as Microsoft Defender can meet the relevant requirements; verify real-time protection, updates and malicious-file handling. Tamper protection is a useful additional safeguard.
  • Security update management. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

Two things commonly catch UK charities out:

1. Unsupported Windows devices. Windows 10 Home and Pro reached end of support on 14 October 2025. Check the exact edition and lifecycle: some LTSC editions have different dates. Where relying on ESU, verify active coverage and qualifying updates; replace or upgrade unsupported installations.

2. MFA not enforced on a small number of board or volunteer cloud accounts. Under v3.3, every user authenticating to an in-scope cloud service needs MFA.

Section 07

The straight-line 6-hour path

1. Use the free readiness checker on the Fig Group site to identify gaps before you spend any money.

2. Fix the gaps. For a typical UK charity: enable cloud-user MFA, verify the required malware-protection configuration, replace, upgrade or establish qualifying ongoing support for Windows 10 devices, verify 14-day patching.

3. Submit your Cyber Essentials assessment on the Fig Group Micro tier at £299.99 + VAT.

4. Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

5. After a successful assessment, verify the issued certificate’s entity, scope and validity before sending it to your funder. Allow separately for publication in the IASME certificate search; do not promise a fixed search-publication deadline.

Total cash out: £299.99 + VAT for the assessment, plus any remediation spend. Preparation and any remediation have their own timetable; the assessment commitment applies only to an eligible completed submission.

Section 08

Bottom line

A UK charity 1–9 people in the applicable scheme size count can certify to Cyber Essentials for £299.99 + VAT on the Fig Group Micro tier, with no mandatory consultancy, no hidden fees, and six working-hour assessment for complete, compliant Basic submissions before midday on a UK Business Day, subject to the certification terms. Scope volunteers and trustees explicitly, enforce MFA for all in-scope cloud-user accounts, retire unsupported Windows devices, and verify compliance before submission; a first-time pass is not guaranteed.

Buy CE Micro for £299.99 + VAT | Read the charity sector guide | Use the readiness checker

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.