Cyber Essentials for Estate Agents, Letting Agents, and Property Firms
Estate agents handle large volumes of personal data - IDs, bank details, AML documentation - and need appropriate safeguards. HMRC AML supervision depends on the activities and applicable legal scope. This guide covers how Cyber Essentials applies to property firms of all sizes and how it supports AML and client data compliance.

Section 01
Cyber Essentials for Estate Agents, Letting Agents, and Property Firms
Estate agencies, letting agents, property managers, and surveying firms sit on an unusually sensitive mix of personal data: IDs, passport scans, proof of address, bank details, AML documentation, tenancy references, property keys and access codes, client valuations, and confidential offer and pricing information. That combination, plus the regulatory overlay (HMRC AML supervision, CQS for property lawyers, PRS codes for letting agents), has pushed Cyber Essentials from optional to expected across much of UK property.
This guide covers what CE means for a property firm, how the controls apply to the typical estate agency or letting agency IT stack, and the specific failures that most often come up during assessment.
Section 02
Why property firms are being asked for Cyber Essentials
HMRC AML supervision. Check whether the firm’s activities fall within estate-agency or qualifying letting-agency registration requirements. Do not assume every property manager, letting agent or surveying business has identical AML supervision obligations. Cyber Essentials does not establish AML compliance or a universal HMRC certification mandate.
Property conveyancer and solicitor expectations. A solicitor may ask an agency for cybersecurity assurance. Confirm the request and accepted evidence; CQS accreditation does not itself establish a universal Cyber Essentials requirement for estate agency partners.
Corporate client due diligence. Agencies acting for corporate clients (relocation agencies, lettings handling expat clients, firms managing PRS or BTR portfolios on behalf of institutional investors) face supplier assurance packs that ask about CE.
Cyber insurance. Increasingly a renewal requirement, particularly for agencies that have had claims or that handle client money beyond a nominal threshold.
Franchise or network standards. Larger agency networks (Countrywide, LSL, Foxtons, Hamptons, regional franchise groups) sometimes cascade CE expectations to their branch operations or franchisee estate.
Section 03
What property firm infrastructure looks like
The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.
A typical UK estate or letting agency runs:
- Microsoft 365 or Google Workspace for email, calendar, documents
- A CRM (Jupix, Reapit, Alto, Dezrez, Fixflo for lettings, Vebra, Street, StreetHub)
- Property portals (Rightmove, Zoopla, OnTheMarket) with agency accounts
- A virtual tours / valuation platform (Matterport, Giraffe360)
- AML and ID verification (Credas, SmartSearch, Thirdfort, Yoti, Veriff)
- Property management (Arthur, FixFlo, Property Inspect, PropertyFile)
- Key management (digital key safes, KeyNest, Eyrus)
- Accounting (Xero, Sage, Reapit's built-in accounts, CoreLogic)
- A website with listing data integration
- Office-based staff and valuers/negotiators on the move
Every item holds some form of organisational or personal data and is in scope.
Section 04
The AML overlap
Where the property business undertakes activities within AML regulation, apply those duties alongside data-protection requirements. The documents collected for AML - passport scans, address proof, source of funds documentation - are among the most sensitive categories of personal data. Loss or unauthorised disclosure of a customer’s passport scan can be a personal-data breach and may affect AML recordkeeping. Assess the facts and applicable reporting and retention duties; certification does not settle them.
CE does not prescribe specific AML data handling, but assessors will probe:
- Where AML documents are stored (use appropriately controlled storage; a dedicated platform is one option, not a universal Cyber Essentials requirement)
- Who has access to them (restricted to compliance staff and the relevant negotiator, not every user)
- How they are transmitted to solicitors and conveyancers (encrypted channels - OneDrive/SharePoint links, dedicated portals, not open email attachments)
- How long they are retained (MLR 2017 requires five years post-transaction; you need a deletion process at the end of that window)
Firms that use dedicated AML tooling (Credas, SmartSearch, Thirdfort, Yoti) usually have a cleaner posture because the data stays inside the tool rather than being pulled into email attachments.
Section 05
The Rightmove / Zoopla / OnTheMarket accounts question
These platform accounts are in scope. They hold organisational data (listings, vendor / landlord names, pricing) and they are accessed by named users on each agency's team. MFA needs to be enforced; leaver processes need to reach these platforms; no shared accounts.
A common gap: each branch has a single "Rightmove account" that the whole branch team uses - shared login, shared password, no MFA. This fails. Each named user should have their own credentials, with MFA, and with individual accounts deprovisioned on leaver.
Check MFA and individual-account support for the actual portal product and subscription. Enforce the required cloud-user MFA; a vendor name alone is not evidence that it is available or configured.
Section 06
BYOD and the negotiator-on-the-move question
Estate agents and letting negotiators are frequently on the move between properties. Laptop use is often in hybrid mode - laptop in the office, phone in the field. Some agencies also issue tablets for valuations.
BYOD for work email is common - a negotiator checks email on a personal iPhone between viewings. Under v3.3, that phone is in scope for CE. The workable positions are the usual BYOD options:
1. Bring personal phones into MDM coverage (many negotiators will resist this)
2. Restrict email access so only managed devices (corporate iPhones enrolled in MDM) can connect
3. Ban personal-device email access, provide corporate phones to all field staff
Most progressive agencies are moving to Option 2 - corporate-issued phones with MDM for field staff, restricted email access for personal devices. This is more comfortable for staff than trying to MDM personal phones and cleaner for compliance than ignoring BYOD.
Section 07
Cash handling and client money protection
Property firms handling client money (letting agents with deposit protection, sales agents holding holding deposits, service charge accounts, deposit protection schemes) have an additional layer of regulatory expectation around protection of that money. CE does not cover client money scheme compliance (TDS, DPS, mydeposits, PRS Mediation, Property Mark CMP) but it addresses the cybersecurity risks that could lead to fraud or diversion of funds - business email compromise, invoice fraud, phishing of finance staff.
Agencies that have had fraud incidents involving bank detail changes or diverted deposit refunds are particularly likely to be asked for CE by insurers.
Section 08
Five property-sector failure patterns to check
1. Shared property portal accounts. Rightmove / Zoopla / OnTheMarket access by whole branches on shared logins. Fails user access control.
2. AML documents in email. Passport scans and proof of address attached to emails, stored in inboxes, forwarded to solicitors as open attachments. Both a CE gap and an AML risk.
3. Employee personal phones without control evidence. Work-email access generally brings them into scope. Check their actual supported software, configuration and other applicable controls; lack of MDM alone is not the failure.
4. Leaver accounts left active on the CRM. Ex-employees still in Jupix, Reapit, or Alto months after leaving. Common because the CRM is managed separately from the main IT, and the person who manages it is not always alerted to leavers.
5. Branch-level control gaps. Different management methods can meet the same requirements. Verify every in-scope branch’s actual controls; missing required controls cause a compliance gap, while the absence of a uniform MDM product does not itself establish failure.
Section 09
Practical path for a property firm
If you run an agency with 5-100 staff:
1. Eliminate shared logins. Every named user on every platform - CRM, property portals, AML tooling - has their own account.
2. Enforce MFA for every user accessing in-scope cloud services, and implement it where available elsewhere. It affects the CRM, the portals, M365/Google, AML tools, accounting, and everything else.
3. Move AML documents inside dedicated platforms. Stop attaching passport scans to emails.
4. Verify device controls. Use MDM or another evidenced management approach to meet the five scheme controls; employee BYOD accessing work data is generally included, while access restrictions must be implemented in practice.
5. Run a leaver reconciliation. Particularly on the CRM and portal accounts, which are often missed.
6. Consolidate branch posture. If you run multiple branches, enforce a consistent configuration across the estate via group policy or MDM.
7. Submit. CE micro (1-9) £299.99 + VAT; small (10-49) £399.99 + VAT; medium (50-249) £449.99 + VAT.
Section 10
Bottom line
Property is a sector where CE closes real operational risks, not just ticks a compliance box. Business email compromise, invoice fraud, and AML document leakage are all real and recent risks for UK estate and letting agencies. The controls CE asks for - MFA, leaver processes, managed devices, restricted sharing - directly address those risks.
It can also support customer assurance. Whether it speeds due diligence depends on the buyer, scope and other requested evidence; certification does not settle AML obligations or HMRC approval. For a sector where trust with clients, landlords, vendors, and insurers is the entire commercial offer, CE is a credibility artefact worth holding.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.
Read articleIndustry
Cyber Essentials for Solicitors and Law Firms: What the SRA Expects in 2026
The Legal Aid Agency now mandates Cyber Essentials for criminal legal aid contracts. The SRA expects appropriate cyber controls for all firms. Here is what solicitors and law firms need to know.
Read articleIndustry
Cyber Essentials for Construction Companies and Contractors
Construction firms bidding for government infrastructure work, MOD contracts, or public-sector framework places are increasingly required to hold Cyber Essentials. This guide covers how the controls apply to construction-specific infrastructure, including site laptops, tablets, and BIM platforms.
Read article

