Cyber Essentials for charities: how to budget at £299.99 + VAT
UK charities have tight budgets and specific scoping questions. This guide walks through how to certify at the £299.99 tier, the current funding position, and how to meet the v3.3 requirements without over-engineering.

Section 01
Cyber Essentials for charities: how to budget at £299.99 + VAT
UK charities face two Cyber Essentials questions that most other sectors do not:
1. Some funders and grant-giving bodies specify Cyber Essentials or another standard. Check the actual grant terms, required scope and accepted evidence rather than assuming a universal funding condition.
2. Charity budgets are tight, and every pound spent on compliance is a pound not spent on mission delivery.
This guide is for the charity CEO, COO, or finance director trying to answer: "What is the cheapest legitimate path to Cyber Essentials?"
The answer is £299.99 + VAT at the Micro tier for charities 1–9 people in the applicable scheme size count, rising to £449.99 + VAT at Medium tier. Below the standard IASME fee. Below the "consultancy-plus-certification" packages that some providers push.
Section 02
How to interpret a funder’s request
Where a funder asks for cybersecurity assurance, establish which wording applies:
- "Cyber Essentials certification." CE at the appropriate size tier is sufficient.
- "Cyber Essentials Plus certification." CE Plus - third-party verified - is the ask; starts at £1,499.99 + VAT for micro organisations.
- "A recognised cybersecurity standard." CE is one recognised baseline standard; confirm that the funder accepts it for the requested scope.
If the funder lists specific frameworks (ISO 27001, NIST CSF), the charity sometimes has a genuinely harder decision. Choose CE, Plus or another standard using the actual funder wording; do not infer acceptance from a generic assurance request.
Section 03
Budgeting the Micro tier (1–9 people in the applicable scheme size count)
The Fig Group Micro tier is £299.99 + VAT - £20.01 below the standard IASME certification body fee. For a 9-person charity that is approximately £40.00 per person per year including 20% VAT, or £0.11 per day, assuming nine people in the applicable size count. Affordability depends on the charity’s budget.
What is included:
- The full CE v3.3 self-assessment.
- Expert review by an IASME-licensed assessor.
- Up to three free feedback rounds to help correct the submission; this is not unlimited resubmission or a guaranteed pass.
- The official certificate, issued via Blockmark and verifiable through the IASME Certificate search tool.
- Dedicated support through the process.
- Free readiness checker before you begin.
What is not included (to be honest about the full total cost):
- Any remediation work. If your charity needs to buy Defender for Business, deploy MFA, or upgrade unsupported Windows devices, that is a separate cost.
- VAT. £299.99 becomes £359.99 inc VAT.
A prepared 9-person charity may need no additional technology purchases if its existing supported devices and configured services meet every applicable requirement. Budget separately for actual remediation and obtain quotes for replacement kit, implementation and licensing; a staff count does not establish the remediation cost.
Section 04
The funder discount question
The NCSC Funded Cyber Essentials Programme is currently closed. Do not budget on an available free place. Any future programme will have its own eligibility, scope and terms.
Fig Group’s £299.99 + VAT Micro price is its cheapest Basic tier and a practical starting budget for 1–9 staff. Any UK-wide cheapest claim needs a dated like-for-like comparison of IASME-licensed providers, included assessment and feedback, VAT and support; it is not a guarantee that no promotion or subsidy can undercut it.
Section 05
Scoping: volunteers and trustees
Charity CE scoping has two category-specific questions:
Volunteers and trustees. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor. The v3.3 ownership table specifically includes volunteers’, trustees’ and university research assistants’ BYOD used for organisational work; do not classify these roles as excluded third-party contractors. Students’ own devices are excluded, while organisation-owned student devices are included. Organisational accounts remain in scope.
Record whether each person is an employee, office-holder or third party and confirm any ambiguous relationship with the Certification Body. Portals, prevention of local storage and virtual desktops can control exposure but do not themselves establish a device exclusion.
Section 06
Required technical controls for a charity
Under v3.3 the five control categories apply the same way regardless of sector. For a typical small charity:
- Firewalls. Relevant device and office-network firewalls, plus the documented cloud provider/customer responsibility split. Change the default admin password.
- Secure configuration. Remove bloatware from laptops. Disable auto-run. Disable guest accounts.
- User access control. MFA for every user account accessing in-scope cloud services. Use M365 Business Premium's built-in MFA.
- Malware protection. A correctly configured supported anti-malware solution such as Microsoft Defender can meet the relevant requirements; verify real-time protection, updates and malicious-file handling. Tamper protection is a useful additional safeguard.
- Security update management. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.
Two things commonly catch UK charities out:
1. Unsupported Windows devices. Windows 10 Home and Pro reached end of support on 14 October 2025. Check the exact edition and lifecycle: some LTSC editions have different dates. Where relying on ESU, verify active coverage and qualifying updates; replace or upgrade unsupported installations.
2. MFA not enforced on a small number of board or volunteer cloud accounts. Under v3.3, every user authenticating to an in-scope cloud service needs MFA.
Section 07
The straight-line 6-hour path
1. Use the free readiness checker on the Fig Group site to identify gaps before you spend any money.
2. Fix the gaps. For a typical UK charity: enable cloud-user MFA, verify the required malware-protection configuration, replace, upgrade or establish qualifying ongoing support for Windows 10 devices, verify 14-day patching.
3. Submit your Cyber Essentials assessment on the Fig Group Micro tier at £299.99 + VAT.
4. Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.
5. After a successful assessment, verify the issued certificate’s entity, scope and validity before sending it to your funder. Allow separately for publication in the IASME certificate search; do not promise a fixed search-publication deadline.
Total cash out: £299.99 + VAT for the assessment, plus any remediation spend. Preparation and any remediation have their own timetable; the assessment commitment applies only to an eligible completed submission.
Section 08
Bottom line
A UK charity 1–9 people in the applicable scheme size count can certify to Cyber Essentials for £299.99 + VAT on the Fig Group Micro tier, with no mandatory consultancy, no hidden fees, and six working-hour assessment for complete, compliant Basic submissions before midday on a UK Business Day, subject to the certification terms. Scope volunteers and trustees explicitly, enforce MFA for all in-scope cloud-user accounts, retire unsupported Windows devices, and verify compliance before submission; a first-time pass is not guaranteed.
Buy CE Micro for £299.99 + VAT | Read the charity sector guide | Use the readiness checker
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.
Read articleIndustry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleIndustry
Cyber Essentials for UK law firms with remote counsel and counsel chambers
The hybrid working model at UK law firms and chambers creates three specific Cyber Essentials scoping questions. This guide walks through how to answer each one.
Read article

