Skip to content

Cyber Essentials for UK education providers Certified by Fig Group.

Fig Group certifies UK education providers - independent schools, colleges, universities, training providers, edtech SaaS. IASME-licensed, from £299.99 + VAT, with MSP-friendly multi-tenant workflow for federations and MATs.

Sector-specific

Tailored to education providers

The scheme requirements apply across sectors; implementation and contractual context differ. These are the scope, regulatory, and supplier-cascade points Fig Group assessors check first.

  • 01DfE cybersecurity standards for schools.
  • 02MIS (Arbor, Bromcom, SIMS) and safeguarding-adjacent data.
  • 03Multi-academy trust (MAT) federated certification.
  • 04Research computing and justified technical scope boundaries.
  • 05Ownership and use of pupil or student devices.
  • 06Edtech cloud services and shared control responsibilities.

Pricing at a glance

Below the standard IASME fee at every tier

Three free rounds of Basic assessor feedback included. Published pricing - no gated forms or consultancy add-ons. If gaps remain after the included rounds or assessment period, agree any further support or new purchase before incurring a charge. Read the assessment terms.

Turnaround

6 working hours

Complete, compliant Basic submissions before midday on a UK Business Day; terms apply.

Cyber Essentials

£299.99 - £549.99

+ VAT, by organisation size.

Cyber Essentials Plus

£1,499.99 - £4,499.99

+ VAT, third-party verified.

Common questions

Frequently asked questions

Does the DfE require Cyber Essentials for schools?

DfE cyber security standards set out recommended controls and discuss certification as an assurance option. They do not establish a universal Cyber Essentials certificate requirement for every school. Check any separate funding or contractual conditions.

How do MATs handle CE across multiple academies?

Agree which legal entities, academies, networks and cloud services the certificate will cover. A central team certificate does not automatically certify every academy. A whole-trust or separate assessment route needs the correct scope and evidence for each included environment.

Is pupil/student estate in scope?

Assess ownership, use, internet connectivity and the agreed organisational boundary. A student label alone does not exclude an organisation-owned device. Any subset exclusion needs a justified, technically separated boundary accepted by the Certification Body; document the applicable scheme exceptions.

What about university research computing?

Do not exclude research systems solely because they have a separate security regime. Assess how they process organisational data and connect to services. A proposed subset exclusion needs an accepted technical boundary and clear scope description.

What is the pricing for a 500-student independent school?

Use the actual organisational staff count and assessment scope, not the number of pupils or an assumed staff-to-pupil ratio. Basic Small covers 10-49 staff at £399.99 + VAT; Medium covers 50-249 at £449.99 + VAT. Confirm the appropriate band before purchase.

Sources: NCSC requirements v3.3, PPN 014, certification terms. DfE cyber security standard.

Deep-dive articles

Long-form guidance for education providers

Technical guidance written by an IASME-licensed assessor - scope edge cases, supplier cascade, and regulatory overlap that the scheme guidance does not cover.

Next step

Ready to certify?

From £299.99 + VAT. IASME-licensed. Typically within 6 working hours. No consultancy add-ons.