Skip to content

Cyber Essentials for UK financial services firms Certified by Fig Group.

Fig Group certifies UK financial services firms - financial advisers, wealth managers, fintechs, payments firms, insurers, and other FCA or PRA-regulated organisations. IASME-licensed, from £299.99 + VAT, with a six-working-hour Basic guarantee for complete, compliant submissions before midday on a UK Business Day, subject to terms. Cyber Essentials is a practical technical baseline; it supports, but does not replace, the broader governance and resilience obligations that apply to regulated firms.

Sector-specific

Tailored to financial services firms

The scheme requirements apply across sectors; implementation and contractual context differ. These are the scope, regulatory, and supplier-cascade points Fig Group assessors check first.

  • 01FCA operational resilience (PS21/3) expectations.
  • 02DORA (Digital Operational Resilience Act) alignment for EU-facing firms.
  • 03SJP Partner Practice Cyber Essentials Plus or managed-device routes.
  • 04Financial-adviser and wealth-management device, cloud-service, and client-data scope.
  • 05Payments data handling alongside PCI DSS scoping.
  • 06Client money / client asset data protection.
  • 07Outsourced-provider oversight and proportionate supplier assurance.

Pricing at a glance

Below the standard IASME fee at every tier

Three free rounds of Basic assessor feedback included. Published pricing - no gated forms or consultancy add-ons. If gaps remain after the included rounds or assessment period, agree any further support or new purchase before incurring a charge. Read the assessment terms.

Turnaround

6 working hours

Complete, compliant Basic submissions before midday on a UK Business Day; terms apply.

Cyber Essentials

£299.99 - £549.99

+ VAT, by organisation size.

Cyber Essentials Plus

£1,499.99 - £4,499.99

+ VAT, third-party verified.

Common questions

Frequently asked questions

Is Cyber Essentials required by the FCA?

The FCA does not impose Cyber Essentials as a universal certification requirement. It expects firms to manage cyber and operational-resilience risk, and has identified Cyber Essentials as a useful baseline for smaller firms. Certification supports that work but does not replace the wider FCA rules and guidance that apply to the firm.

Does SJP require Cyber Essentials for Partner Practices?

SJP has publicly described mandatory Cyber Essentials Plus accreditation for Partner Practices or use of its Device as a Service solution. Partner Practices should confirm their current route and reporting instructions with SJP. See /blog/cyber-essentials-for-sjp-partners for practical certification guidance.

How should a wealth manager or financial adviser scope Cyber Essentials?

Start with the devices, networks, cloud services, and users that access organisational data or services. Include the CRM, back-office and financial-planning tools, document signing, client portals, remote working, administrator accounts, and any personally owned devices that fall within scope.

Does Cyber Essentials satisfy DORA?

No. DORA covers a much broader set of ICT risk and resilience obligations for entities within its scope. Cyber Essentials can support basic control evidence, but certification does not establish DORA compliance or determine whether the regulation applies to your firm.

What CE scope should a fintech SaaS use?

Include production cloud services used for organisational data or services, as well as corporate devices and accounts. ISO 27001 or SOC 2 assurance does not create an automatic Cyber Essentials exclusion. Document shared responsibilities and agree any justified subset boundary with the assessor.

What tier do most fintechs use?

It depends on staff. A typical fintech with 40 staff falls into CE Small (10-49) at £399.99 + VAT, or CE Plus Small at £1,999.99 + VAT for insurer / enterprise-client use.

Sources: NCSC requirements v3.3, PPN 014, certification terms.

Deep-dive articles

Long-form guidance for financial services firms

Technical guidance written by an IASME-licensed assessor - scope edge cases, supplier cascade, and regulatory overlap that the scheme guidance does not cover.

Next step

Ready to certify?

From £299.99 + VAT. IASME-licensed. Typically within 6 working hours. No consultancy add-ons.