Skip to content
Compliance

How to Choose a Cyber Essentials Assessor: 7 Things to Check

Not all certification bodies are equal. Here are seven things to verify before choosing your Cyber Essentials assessor, based on what actually matters during the process.

blue wooden door

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

How to Choose a Cyber Essentials Assessor: 7 Things to Check

To choose a Cyber Essentials assessor, verify seven things: IASME licence for the required scheme, full price with VAT, written turnaround terms, feedback and resubmission policy, assessment portal and records, account-version handling, and support availability. Check the legal entity on IASME's current directory before buying certification.

Choosing a Cyber Essentials certification body is not a decision most organisations spend much time on. The assumption is that one licensed body is much the same as another. In terms of the certificate itself, that is true. In terms of the experience, cost, and speed, it is not.

Here are seven things worth checking before you commit.

Section 02

1. IASME licensing

This is non-negotiable. Every legitimate Cyber Essentials certification body must hold a current IASME licence. IASME publishes a list of licensed bodies on its website. If a provider is not on that list, they cannot issue valid certificates.

Some consultancies offer Cyber Essentials "support" or "readiness" services but are not themselves licensed to assess and certify. These services can be useful for preparation, but you will still need a licensed body for the actual certification.

Check: Verify the body appears on the IASME register of licensed certification bodies.

Section 03

2. Published pricing

Transparent pricing is a useful indicator of how a certification body operates. Bodies that publish their prices tend to be confident in their value proposition. Bodies that require a sales call or quote may have pricing that varies based on the customer.

Fig Group publishes Basic pricing from £299.99 + VAT for Micro organisations. Our lowest-price positioning concerns the named comparable standalone offers reviewed, not every quote-only or bundled provider. Other suppliers may include consultancy, Plus or platform subscriptions. Request dated written, like-for-like prices; a monitoring subscription is not a standalone Basic assessment fee.

Check: Is the full pricing schedule published on the website, or do you need to request a quote?

Section 04

3. Turnaround time commitment

Ask specifically: what is your published turnaround time from submission to certificate? Is it a guarantee or a target?

Fig Group publishes a six-working-hour Basic guarantee after receipt of a complete, compliant submission before midday UK time on a UK business day, subject to its terms. Ask each body for its current written commitment and exactly when its clock starts.

Check: Is the turnaround time published? Is it a guarantee or a best-case estimate?

Section 05

4. Feedback and resubmission policy

Some submissions need clarification or corrections. What happens when your submission is not perfect on the first attempt matters as much as the initial assessment speed.

Key questions:

  • How many rounds of feedback are included in the price?
  • Is feedback delivered in writing with specific, actionable guidance?
  • Does a resubmission go to the back of the queue or is it reviewed promptly?

Fig Group includes three feedback rounds under its published terms. For other bodies, verify whether a quoted number refers to feedback, resubmissions or a Plus retest; package conditions can differ.

Check: How many feedback rounds are included, and what happens to resubmissions?

Section 06

5. Assessment platform vs email

Cyber Essentials assessment uses the IASME portal. Providers may add email, preparation tools or their own customer interface around that process. Ask how questions, feedback and evidence are handled and retained.

Fig Group offers an online purchase and assessment workflow. CyberSmart offers a separate software product alongside certification. Compare the actual purchased service rather than inferring a provider's speed or feedback quality from whether it also sends email.

Check: Is the assessment process handled through a platform or through email?

Also ask whether the platform preserves your answers, evidence, assessor feedback, and certificate history for renewal. A clean audit trail matters when procurement asks for proof months later, not only on purchase day.

Section 07

6. v3.3 and Danzell question set readiness

The NCSC updated the Cyber Essentials requirements to version 3.3 on 27 April 2026. The account version and its MFA questions should be checked against the NCSC requirements. In-scope cloud services require MFA; do not generalise that rule to every possible account type.

New applications from 27 April 2026 use v3.3. Applications started earlier can continue under v3.2; using that valid transition route is not an assessor defect.

Check: Confirm the version shown on your assessment account and that the body uses the corresponding question set.

Section 08

7. Support availability

When you are midway through the self-assessment questionnaire and unsure how to answer a question about your firewall configuration, can you get help? Some bodies offer dedicated support throughout the process. Others leave you to work through it alone.

Check Fig Group's current package terms for the support channel and included scope. Ask other providers for the same details in writing, including any preparation consultancy that is separate from the licensed assessment.

Check: What support is available during the self-assessment process, and is it included in the price?

Section 09

Putting it all together

No single factor determines the right choice. But when you evaluate across all seven criteria, a clear picture emerges:

Swipe across the table to view all columns.

CheckFig Group published routeWhat to request from another body
Basic licenceVerify Fig Compliance Ltd on the IASME finderCurrent entity and scheme licence
Basic priceFrom £299.99 + VAT for MicroSame size tier, VAT and support scope
TurnaroundConditional six-working-hour Basic guaranteeWritten clock and exclusions
FeedbackThree rounds under Fig Group termsFeedback, resubmission and Plus retest terms separately
Portal and recordsAsk for a demonstration of the purchased workflowEvidence and renewal record retention
Account versionv3.3 for new post-transition applicationsVersion attached to your assessment account
SupportCheck Fig Group package termsHours, channel and preparation scope

Fig Group publishes a low Micro price and a conditional Basic guarantee. Another body may be a better fit when you need consultancy, Plus testing or a separate monitoring product. Compare dated offers for equivalent scope.

Take the free readiness check | View pricing

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.

Request a demo

Related solutions

Continue exploring Fig Group