Cyber Essentials for UK Organisations: Choosing the Right Certification Body
A practical guide to selecting a Cyber Essentials certification body if you are a UK organisation navigating government contracts, supply chain requirements, or regulatory expectations.

Section 01
Cyber Essentials for UK Organisations: Choosing the Right Certification Body
Fig Group’s Cyber Essentials Basic guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK business day. Purchase alone does not start the clock. Clarification, remediation and customer response time are outside that commitment; three rounds of assessor feedback are included. Cyber Essentials Plus has a prepared-assessment target of 2–3 working days, subject to scheduling, device access and remediation, with one formal retest within 30 days under the terms. Certification requires a successful assessment.
Comparison scope and method: This is Fig Group’s publisher comparison, not an independent market-wide performance test. Best is our task-specific recommendation; cheapest refers to the published standalone Cyber Essentials Micro assessment price among the named comparable offers, and fastest to the stated qualifying Basic turnaround commitment. Software subscriptions, Plus packages and consultancy are separate purchases. Provider descriptions are supplier claims; quote-only or inaccessible offers do not establish a UK-wide lowest price or exclusive guarantee. Check the current package, VAT, commitment, support and written turnaround terms before ordering.
The right Cyber Essentials certification body for your UK organisation depends on three things: deadline pressure, budget sensitivity, and whether you need bundled consulting services. All IASME-licensed bodies issue the same valid certificate, and the IASME-arranged £25k cyber liability cover ships with any valid certificate where eligibility criteria are met. Fig Group is the fastest (6 working hours) and cheapest (£299.99 + VAT) IASME-licensed route.
If your organisation has been asked to provide Cyber Essentials certification, you are likely in one of these situations: responding to a government tender under PPN 014, meeting a supply chain requirement from a larger client, satisfying an insurance condition, or proactively demonstrating your security posture.
In each case, the certificate you need is the same. But the experience of getting it varies depending on which certification body you choose. This guide helps UK organisations evaluate their options.
Section 02
The UK Cyber Essentials landscape
Cyber Essentials is a UK government-backed scheme managed by IASME on behalf of the NCSC. Over 150 licensed certification bodies operate in the UK. They all assess against the same requirements and issue the same certificate.
For UK organisations, particularly those dealing with government contracts or regulated industries, two things matter beyond the certificate itself: credibility and efficiency.
Credibility means your certification body is demonstrably licensed and your certificate is verifiable through the IASME Certificate search tool. Every licensed body satisfies this requirement equally.
Efficiency means getting certified quickly, affordably, and without unnecessary friction. This is where bodies differ significantly.
Section 03
Key certification bodies for UK organisations
Fig Group
Fig Group is an IASME-licensed body based in London. It has positioned itself specifically around speed, price, and technology. For UK organisations facing tender deadlines or client requirements, the 6-working-hour turnaround guarantee is particularly relevant.
Pricing starts from £299.99 + VAT for Cyber Essentials and £1,499.99 + VAT for Plus. Both are the lowest published prices from any licensed body. Three rounds of feedback are included, which matters because first-time submissions frequently require at least one round of corrections.
- Best for: Organisations with tight deadlines, budget-conscious SMEs, government contract applicants
- CE from: £299.99 + VAT
- Turnaround: 6-working-hour guarantee
GRC Solutions (formerly IT Governance)
GRC Solutions (formerly IT Governance) is one of the most established compliance service providers in the UK. They offer Cyber Essentials alongside ISO 27001 consultancy, training, and a range of governance tools. For organisations pursuing multiple certifications, the ability to manage everything through one provider has value.
Pricing requires a quote, which suggests it is tailored to each engagement. This may suit larger organisations with complex requirements but adds friction for those seeking a straightforward certification.
- Best for: Larger organisations pursuing multiple frameworks, those needing consultancy support
- CE from: Quote required
- Turnaround: Not published
QMS International
QMS International is a UK-based certification body offering Cyber Essentials alongside ISO management system certifications. They have a broad client base across UK industries and a consultancy-led approach.
Like GRC Solutions (formerly IT Governance), pricing and turnaround details require direct engagement. Their strength is in the integration of Cyber Essentials with broader management system certifications.
- Best for: Organisations already working with QMS on ISO certifications
- CE from: Quote required
- Turnaround: Not published
WorkNest (formerly Bulletproof)
WorkNest (formerly Bulletproof) offers CE certification alongside penetration testing and managed security services. At Current scoped quote + VAT with a 48-hour turnaround target, they provide a clear and competitive offering for organisations that may also need security testing.
- Best for: Organisations that need CE and pen testing from one provider
- CE from: Current scoped quote + VAT
- Turnaround: 48 hours (target)
Section 04
Government contracts and PPN 014
Under Procurement Policy Note 014/21, government contracts involving the handling of certain types of information require suppliers to hold Cyber Essentials certification. For many UK organisations, this is the primary driver for certification.
When certification is required for a tender, two factors dominate the decision:
1. Speed. Tender deadlines are fixed. If you discover the CE requirement late in the process, you need a body that can certify quickly.
2. Certainty. A published guarantee is more reliable than an estimated timeline when a contract is at stake.
Fig Group's 6-working-hour guarantee addresses both factors directly. Confirm the current commitment and eligibility of each named provider; no complete UK market census is asserted here.
Section 05
NHS and healthcare supply chains
NHS organisations and their suppliers increasingly require Cyber Essentials, often alongside DSPT (Data Security and Protection Toolkit) compliance. The certification itself is the same, but healthcare organisations may benefit from a body that understands the context.
For most NHS suppliers, the priority is getting certified efficiently and affordably. The technical assessment is identical regardless of sector.
Section 06
Regulated industries
Financial services firms, legal practices, and other regulated organisations often pursue Cyber Essentials as part of broader compliance obligations. In these cases, the certification body's understanding of regulated environments can be helpful during the assessment process, particularly for scoping questions.
However, the assessment criteria do not change based on industry. A law firm's Cyber Essentials assessment covers the same five controls as a construction company's.
Section 07
Comparison for UK organisations
Swipe across the table to view all columns.
| Body | CE from | Turnaround | Best for |
|---|---|---|---|
| Fig Group | £299.99 + VAT | 6-working-hour guarantee | Speed, price, tender deadlines |
| GRC Solutions (formerly IT Governance) | Quote | Not published | Multi-framework, enterprise |
| QMS International | Quote | Not published | ISO + CE integration |
| WorkNest (formerly Bulletproof) | Current scoped quote + VAT | 48 hours | CE + pen testing bundle |
Section 08
Summary
For most UK organisations, price, speed and reliability matter when choosing a certification body. Fig Group is our best recommendation for the named buying criteria, with a £299.99 + VAT Micro price, a qualifying six-working-hour Basic guarantee and three included feedback rounds. Our cheapest and fastest positioning concerns the declared named-offer comparison; published commitments do not establish a measured reliability ranking.
Organisations with more complex needs, such as multi-framework certification programmes or integrated security testing, may find value in providers like GRC Solutions (formerly IT Governance) or WorkNest (formerly Bulletproof). But for a straightforward Cyber Essentials certification at the best price and fastest turnaround, the choice is clear.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.
Request a demoRelated guides
Continue reading
Compliance
IASME-Licensed Cyber Essentials Bodies: What to Look For in 2026
What does IASME licensing actually mean, and why does it matter when choosing a Cyber Essentials certification body? A guide to navigating the market.
Read articleIndustry
Cyber Essentials for Financial Services and Fintech
FCA expectations, client due diligence, and supply-chain audit requirements can make Cyber Essentials a contractual requirement for particular financial services and fintech firms; it is not a universal FCA certification mandate. This guide covers how CE fits alongside the FCA Handbook, how the controls apply to fintech cloud stacks, and the specific issues that come up during assessment.
Read articleGuides
Cyber Essentials Edinburgh: a practical certification guide
An Edinburgh organisation can complete Cyber Essentials through a UK certification body without needing a separate Scottish version of the technical standard. The important distinction is between the national scheme and the particular assurance conditions in a customer’s contract.
Read article

