Skip to content
Industry

Cyber Essentials for Financial Services and Fintech

FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.

person holding black iPhone displaying stock

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

Cyber Essentials for Financial Services and Fintech

Financial services firms need cybersecurity controls appropriate to their activities and applicable rules. The FCA Handbook contains systems-and-controls provisions with differing application; Cyber Essentials can provide evidence of baseline controls but does not by itself satisfy those obligations. The BoE operational resilience expectations go further. And the due diligence packs that institutional clients send to fund managers, wealth managers, and fintechs may ask whether the firm holds Cyber Essentials; verify the actual request.

This guide covers how Cyber Essentials fits into the UK financial services regulatory landscape, how the controls apply to the kind of cloud-first stacks that modern fintechs run, and the specific issues that most often need attention before submission.

Section 02

Who in financial services needs Cyber Essentials

Several overlapping groups have CE as a de facto requirement:

FCA-authorised firms

Wealth managers, IFAs, fund managers, discretionary fund managers. Institutional clients routinely ask for CE; trade associations (PIMFA, TISA) reference it in best-practice guidance.

Fintechs and payments firms

E-money institutions, payment service providers, and FCA-authorised fintechs. CE is asked for by enterprise customers, by banking partners during due diligence on BaaS arrangements, and by operational risk teams.

Wholesale and investment firms

Brokerages, custodians, fund administrators. Institutional counterparties run supplier assurance; CE is a standard line item.

Insurance firms and insurtech

Brokers, MGAs, Lloyd's syndicate service companies. Underwriter due diligence and compliance with Lloyd's minimum standards increasingly reference CE.

Consumer lenders and credit brokers

Particularly those operating BNPL, peer-to-peer lending, or similar fintech credit models. Partner banks require CE as part of the onboarding for lending arrangements.

Section 03

How CE fits with FCA requirements

CE does not satisfy the FCA's full cybersecurity expectations on its own - the FCA expects firms to go beyond the baseline, particularly for operational resilience. But it is a clean way to evidence baseline technical measures, and it maps to specific FCA expectations:

Systems and controls - determine which FCA Handbook provisions apply to the firm. SYSC 3 addresses systems and controls appropriate to the business; it does not prescribe Cyber Essentials as proof of compliance.

Operational Resilience (SYSC 15A) - CE supports the technical measures expectation within the broader operational resilience regime. Not a substitute but a contributor.

Consumer Duty - assess the applicable retail-customer outcomes and obligations separately. Cyber Essentials does not certify Consumer Duty compliance.

Outsourcing expectations - check applicable FCA rules and guidance and the actual buyer’s assurance request. A certificate may contribute technical-control evidence, but does not replace outsourcing due diligence or establish automatic supplier acceptance.

For fintechs applying for FCA authorisation, having CE in place at the point of submitting the authorisation pack is helpful. It does not accelerate the application but it is a data point that aligns with the FCA's expectations around tech controls.

Section 04

What a financial services / fintech stack typically looks like

A modern UK fintech or challenger financial services firm runs:

  • Microsoft 365 or Google Workspace for corporate identity and collaboration
  • AWS, Azure, or GCP for production infrastructure
  • A customer-facing web and mobile app
  • A core platform (often proprietary, or built on a vendor like Mambu, Thought Machine, 10x Banking, Mambu, Railsr, ClearBank, Modulr)
  • KYC/AML tooling (Onfido, Jumio, Veriff, ComplyAdvantage, Fenergo)
  • Payment processing (Stripe, Adyen, GoCardless, Modulr, Form3)
  • CRM and customer service (Salesforce, HubSpot, Zendesk, Intercom, Freshworks)
  • Finance and accounting (Xero, NetSuite, Sage Intacct)
  • HR and people ops (BambooHR, HiBob, Personio)
  • Internal engineering (GitHub, GitLab, Linear, Jira, PagerDuty, Datadog)
  • A data warehouse (Snowflake, BigQuery, Databricks, Redshift)

Nearly everything here is in scope. The SaaS stack is broad, the user base is technical, and the regulatory exposure is high.

Section 05

The user access control question in a high-trust environment

The single area financial services firms typically need to tighten is user access control under v3.3. The MFA requirement applies to every user on every in-scope cloud service. In fintechs, this means:

  • SSO-integrated SaaS apps where SSO itself is MFA-protected - usually fine
  • Non-SSO-integrated apps where individual user accounts exist - often the gap
  • CI/CD systems, cloud consoles, and admin platforms - all need MFA; all usually have it for humans but service accounts are a separate question
  • Production databases - admin access via IAM federation with MFA; no shared DB passwords

The specific posture assessors expect for a fintech:

  • SSO via Entra ID, Okta, Google Workspace, or similar, covering every SaaS service where it can
  • MFA enforced on the SSO itself (hardware token or WebAuthn preferred for admin users)
  • Consider privileged-access tooling for production (Just-in-Time access, approval workflow, session recording) as additional safeguards, not universal Cyber Essentials product requirements
  • Break-glass accounts documented with tight controls
  • Service accounts using short-lived tokens or managed identities rather than long-lived API keys

Fintechs that are beyond the earliest stage typically have most of this. What catches them out is the second-tier apps that someone in marketing or finance signed up for without going through IT - a Mailchimp account with its own login, a Canva team account, a SurveyMonkey, a Typeform. Each of those is in scope.

Section 06

Engineering and developer infrastructure

GitHub, GitLab, AWS consoles, Snowflake, the cloud build systems - the developer-facing infrastructure is where a fintech's most sensitive access sits. Assessors will probe:

  • MFA on every GitHub / GitLab user (organisation-wide enforcement, not per-repo)
  • SSO-gated access to the cloud consoles (no direct IAM user logins for humans; all human access via identity federation)
  • Consider production-deployment approval workflows as an additional engineering safeguard; Cyber Essentials does not mandate a universal workflow product.
  • Maintain admin-change audit trails as an additional operational safeguard
  • Separate dev, staging and production where appropriate to engineering risk; this is not a universal Cyber Essentials architecture mandate

Most of this is baseline engineering hygiene for any fintech past the earliest stage, but CE is where it gets formally assessed as a control.

Section 07

Production infrastructure and the AWS / Azure / GCP question

Cloud production infrastructure is in scope. That sounds obvious but fintechs sometimes treat it as "that is the engineering team's area and it is too technical for CE". It is not. The cloud environment is in scope and the CE controls apply:

  • Firewalls: default-deny network security groups, no management ports exposed to 0.0.0.0/0
  • Secure configuration: no default credentials, no publicly-readable S3 buckets or Azure blob containers holding non-public data
  • Patching: OS patching on any managed EC2 / VM instances; container images updated; platform services on supported versions
  • User access: IAM federation, MFA, least privilege, appropriate credential controls; short-lived credentials are an additional recommended safeguard
  • Malware protection: where managed EC2 / VMs run, antivirus or application allow-listing is in place (not strictly required for fully-managed PaaS services)

For a fintech running mostly on managed services (API Gateway, Lambda, RDS, Cognito, Stripe-as-a-service), the CE applicability is narrower than a traditional IaaS deployment, but it still applies to the admin access, the build pipeline, and any supporting EC2 / VM hosts.

Section 08

The GDPR, DSPT, and Consumer Duty overlap

For firms in the consumer-facing space (retail banking, BNPL, wealth, insurance), CE sits alongside:

  • UK GDPR Article 32 (appropriate technical and organisational measures - CE supports the evidence)
  • FCA Consumer Duty (firms must act to deliver good outcomes for retail customers - data security is implicit)
  • Operational Resilience (important business services must be protected; CE supports the baseline)
  • DPA 2018 considerations around particularly sensitive data

None of these require CE explicitly. All of them are easier to demonstrate with CE in place.

Section 09

Five financial services failure patterns to check

Second-tier SaaS without MFA

Main identity platform has MFA; Mailchimp, Typeform, Canva, HubSpot do not because they were signed up for by a non-technical team member.

Long-lived cloud access keys

Static AWS / GCP / Azure credentials in CI/CD configs or in-code. Needs to be short-lived tokens or managed identities.

Public storage buckets

Often forgotten static asset buckets or log archive buckets - public S3 buckets or Azure blob containers holding non-public data. Found instantly during a Plus technical audit.

Dev environments using real data

"We test against production data in staging" is an operational risk, a GDPR risk, and a CE risk all at once.

Lagging leaver processes for contractors

An engineer leaves on Friday; their GitHub access is removed Monday; their Snowflake access is removed the following week; their PagerDuty access is removed the month after. Remove access when no longer required across every relevant service; a one-working-day target is useful local policy, not a universal Cyber Essentials deadline.

Section 10

Practical path to CE for a fintech

If you are an FCA-authorised fintech with 20-150 staff:

1. List every SaaS and cloud platform the team uses. The engineering systems, the commercial systems, the people ops systems, and the finance systems. Include the shadow-IT items.

2. Enforce MFA across every one. SSO where possible; individual-account MFA where not.

3. Audit production cloud configuration. Run an AWS / Azure / GCP security posture check (native tools or third party). Close default-open ports, confirm no public buckets, confirm IAM federation for human access.

4. Tighten engineering hygiene. GitHub MFA enforced org-wide; consider PAM or Just-in-Time for higher-risk production access; neither is a universal Cyber Essentials product mandate; review CI credentials; short-lived keys are an additional safeguard.

5. Formalise leaver processes. Every in-scope system has a deprovisioning step. Reconcile quarterly.

6. Submit. CE small (10-49) £399.99 + VAT, medium (50-249) £449.99 + VAT, large (250 - 9,999) £549.99 + VAT. Plus from £1,499.99 to £4,499.99 + VAT. Many fintechs go straight to Plus because institutional clients ask for it.

Section 11

Bottom line

Cyber Essentials can support financial-services assurance where the client or banking partner accepts it. Check the required level and scope, evidence the controls actually implemented, and address shadow SaaS, service-account hygiene and cloud configuration. Do not assume a sector label proves readiness or a universal certificate requirement.

Holding current CE (and often Plus) is also a useful signal for funding, partner, and enterprise sales conversations. Firms that do not hold it are regularly asked why; firms that do hold it can use it as an early credibility marker.

Check your readiness | View pricing | Talk to an assessor

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.