Skip to content
Industry

Cyber Essentials for Solicitors and Law Firms: What the SRA Expects in 2026

The Legal Aid Agency now mandates Cyber Essentials for criminal legal aid contracts. The SRA expects appropriate cyber controls for all firms. Here is what solicitors and law firms need to know.

judges gavel and open book on table

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

Cyber Essentials for Solicitors and Law Firms: What the SRA Expects in 2026

The legal sector handles some of the most sensitive data in the UK economy. Client funds, privileged communications, personal injury records, property transactions, criminal case files - all of it sitting in law firm systems that are increasingly targeted by threat actors.

The regulatory landscape has shifted. From October 2025, the Legal Aid Agency requires Cyber Essentials certification for all firms holding criminal legal aid contracts. The Solicitors Regulation Authority does not yet mandate a specific certification, but its position on cyber security has hardened considerably.

This article sets out what law firms need to know, what the regulators expect, and how to get certified.

The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements.

Section 02

From 1 October 2025, any practice holding a Criminal Legal Aid contract must hold a valid Cyber Essentials certificate. This is not guidance - it is a contractual requirement. The 2025 criminal contract requires whole-organisation certification and annual renewal. Check the current Legal Aid Agency welcome-pack conditions; do not treat a limited subset as automatically sufficient.

The requirement applies to standard Cyber Essentials (not Plus), though firms handling particularly sensitive case data should consider whether Plus provides additional assurance.

If your firm holds a 2025 criminal legal aid contract, check its current certification and renewal obligations against the Legal Aid Agency conditions. Do not assume a practice-size estimate determines whether your contract is covered.

Section 03

The SRA Position: "Appropriate Systems and Controls"

The Solicitors Regulation Authority takes a principles-based approach. It does not mandate a specific certification, but its expectations are clear.

Under SRA Principle 2 and the Code of Conduct for Firms, solicitors must act in a way that upholds public trust and confidence. The SRA interprets this to include maintaining appropriate systems and controls to protect client data and client money.

The SRA’s cyber security thematic review discusses firms’ duties to protect client funds and data. Review these practical controls; this list is not a quoted regulatory test or a guarantee of compliance:

  • Not enforcing multi-factor authentication on email systems (particularly where client money is handled)
  • Failing to maintain up-to-date software and security patches
  • Not having documented procedures for handling cyber incidents
  • Inadequate access controls around client files and accounts

A cyber incident can raise professional, client-money and data-protection obligations. Assess reporting and remedial duties against the actual incident and current rules; the presence or absence of a certificate does not determine the regulatory outcome.

Cyber Essentials certification does not guarantee SRA compliance, but it demonstrates that the five foundational technical controls are in place. In the event of a breach, a current certificate records the assessed baseline and scope; the adequacy of the firm’s safeguards still depends on the facts.

Section 04

Why Law Firms Are Targeted

Law firms are attractive targets for three reasons:

Client funds

Conveyancing transactions can involve substantial client funds. The SRA’s published cybercrime case studies describe intercepted solicitor-client emails and fraudulent payment instructions. Confirm bank-detail changes through an established independent channel; certification does not replace that transaction control.

Privileged information

Legal professional privilege makes law firm data uniquely valuable for corporate espionage, insider trading, and blackmail. M&A files, litigation strategies, and regulatory submissions all carry significant value to the right buyer.

Perceived weakness

Many law firms, particularly smaller high street practices, operate with limited IT budgets and rely on consumer-grade security tools. Threat actors know this. The NCSC has published specific guidance for the legal sector precisely because the threat level is elevated.

Section 05

What Cyber Essentials Requires

The five controls map directly to the risks law firms face:

Firewalls

Protect the office boundary and relevant devices with correctly configured firewalls. Worker- or ISP-supplied home routers are excluded; organisation-supplied home routers are included. Record the provider/customer responsibility split for cloud services.

Secure configuration

Default passwords must be changed, unnecessary software removed, and auto-run disabled. For law firms, this means locking down your case management system, document management platform, and email environment.

Access control

Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.

Malware protection

Use a supported scheme-permitted malware-protection approach on relevant devices. Anti-malware and application allow-listing are implementation routes; mobiles can use the applicable approved-app-store and application-signing approach. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements.

Patch management

Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

Section 06

The MFA Question

Enable MFA for every user account accessing in-scope cloud services, including administrator and third-party accounts. Implement MFA where available on non-cloud systems and apply the separate administrative-access and password controls; do not assume v3.3 mandates MFA on every local account regardless of availability. Document non-interactive service identities separately rather than treating them as human logins.

For law firms, this means MFA on:

  • Microsoft 365 or Google Workspace (email and documents)
  • Your practice management system (if cloud-hosted)
  • Your accounts and client money system
  • Any remote access tools (VPN, remote desktop)
  • Any file sharing or collaboration platforms

If your firm has not yet rolled out MFA across all these services, address it before your Cyber Essentials assessment. Cloud-user MFA is a scheme requirement; assess the firm’s wider professional safeguards separately.

Section 07

Professional Indemnity Insurance

Cyber Essentials certification is increasingly relevant to professional indemnity insurance. Several PI insurers now ask whether firms hold Cyber Essentials as part of the renewal process. While it is not universally required, firms with certification may benefit from more favourable terms.

Separately, standalone cyber insurance policies almost universally ask about MFA, patching, and access controls - exactly the areas Cyber Essentials covers. Holding certification simplifies the application process and provides documented evidence of your security posture.

Section 08

Getting Certified

For solicitors and law firms, the certification process is straightforward:

1. Assess your position - Use Fig Group's free readiness tool to check your current compliance against the five controls

2. Address gaps - The most common gaps for law firms are MFA not being enforced on all cloud services, shared user accounts, and overdue software updates

3. Complete the assessment - The Cyber Essentials questionnaire asks about your technical controls across the five themes. Answer based on your actual configuration, not your intended configuration

Fig Group guarantees Basic assessment within six working hours for a complete, compliant submission received before midday on a UK Business Day, subject to the certification terms. Preparation, clarification and remediation are separate; certificate issuance requires a successful assessment.

For firms that need Plus certification (required by some larger clients and panel memberships), allow a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation for the technical audit.

Section 09

Maintaining Certification

Cyber Essentials certificates are valid for 12 months. Set a calendar reminder to renew 4-6 weeks before expiry. Letting certification lapse creates a gap that could affect your legal aid contract, client relationships, or insurance coverage.

If your firm's IT environment changes significantly during the year (new practice management system, office move, shift to cloud services), review your controls against the Cyber Essentials requirements to ensure you remain compliant.

Get your law firm certified today

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.