6-working-hour Basic turnaround guarantee
For complete, compliant Basic submissions through the prescribed process before midday UK time on a UK business day. Clarification, remediation and Plus assessments are excluded.
IASME-licensed certification for London organisations. Cyber Essentials from £299.99 + VAT, Cyber Essentials Plus from £1,499.99 + VAT, and a six-working-hour Basic turnaround guarantee for complete, compliant submissions received before midday on a UK Business Day. The certificate is the national one; the delivery is built around how London actually works.
Direct line for London enquiries: +44 (0) 203 105 2335. Email: enquiries@figgroup.co.uk.
For complete, compliant Basic submissions through the prescribed process before midday UK time on a UK business day. Clarification, remediation and Plus assessments are excluded.
The same fixed UK-wide pricing applies whether you are in Aberdeen, Aldgate, Fitzrovia, or Canary Wharf.
Our licence and public claims register are published for procurement teams who need to verify before purchase.
Cyber Essentials is a UK national scheme run by the National Cyber Security Centre and delivered by IASME. Every certificate issued by every Certification Body uses the same Cyber Essentials v3.3 questionnaire and carries identical legal and contractual weight. There is no separate London Cyber Essentials certificate.
Location matters because of delivery fit, not certificate exclusivity. London organisations often share a cluster of operational realities: hot-desking in shared offices, regulated professional-services work, contractual cyber requirements from principals and insurers, senior people using multiple devices, and procurement teams working against a date.
We see this pattern repeatedly across London engagements. The mechanical scheme is the same; the scoping conversation is shorter when the assessor already understands what an SJP partner practice, criminal chambers, recruitment agency, or clinic typically looks like in London.
Three reasons recur in enquiry calls. The first is speed against a deadline. Most London enquiries arrive with a date attached: a tender response, a renewal lapsing soon, an SJP partner practice working towards a mandate window, or an insurer asking for evidence before they issue cover.
The second is fixed UK-wide pricing. We do not charge a London surcharge. Our prices are the same whether you are in Aberdeen or Aldgate, and each Cyber Essentials tier includes three free assessor-feedback rounds if a control answer needs work.
The third is verifiability. Our licensed status as a Certification Body is on our IASME licence page, and our public trust claims register sets out exactly what we do and do not assert about ourselves.
Across Greater London
We support organisations across all 32 London boroughs and the City of London, including distributed teams working beyond London. Your postcode does not change the scheme requirements or published organisation-size pricing. Scope follows the organisation, devices and services being certified, not an office address.
For commercial and criminal chambers, establish whether the applicant is the chambers entity, an individual practice or a defined group. Record responsibility for clerks' equipment, shared networks, case-management services and members' devices. A shared address does not establish a shared certification boundary. Check the exact client or contractual requirement rather than assuming a universal professional-body mandate.
Read the chambers scoping guideAn MSP's own certificate does not certify its customers. Keep each client's scope, evidence and authorisation separate. MSPs can complete the self-assessment on a client's behalf; the client reviews and authorises the submission and provides the required portal sign-off. Fig Group performs the certification assessment. Agree responsibility for remediation and renewal before delivery begins.
Explore MSP certification servicesLondon insurance market
Managing agents, coverholders, MGAs and service providers need a clear connection between the organisation named on a certificate and the services being supplied. Start with the requesting customer's requirements and the legal entity operating the technology. Neither a market affiliation nor a syndicate number establishes the scope of a Cyber Essentials assessment.
Identify the legal entity, trading names, locations and services included. Where a managing agent supports several syndicates, document the shared infrastructure and proposed boundary rather than assuming each syndicate needs a separate certificate. Confirm what the counterparty will accept.
Map workstations, remote access, policy and claims applications, cloud accounts and outsourced IT. Identify who administers access and configuration, and obtain evidence from responsible providers. Outsourcing a service does not remove the need to understand its role in the assessment.
Cyber Essentials is a verified self-assessment; Plus adds independent technical testing. Check the specific supplier questionnaire or contract for the required level and scope. Certification does not replace operational-resilience obligations, a wider security programme or an insurer’s underwriting decision.
Prepare an asset and cloud-service inventory, a responsibility map for outsourced controls, the requested certificate wording and your deadline. We can then confirm the assessment scope and whether you need CE, Plus or the combined package. The published CE turnaround applies to compliant self-assessments; Plus has a separately agreed technical audit schedule.
Choosing a provider
There is no separate London certificate. Any IASME-licensed UK Certification Body can assess a London organisation, so compare providers on verifiable service terms rather than postcode alone. The most useful checks are price, turnaround, re-submissions, Cyber Essentials Plus capability, and whether local support is genuinely available when the scope requires it.
| Factor | What to verify | Fig Group’s published position |
|---|---|---|
| IASME licence | Only an IASME-licensed Certification Body can assess the submission and issue the scheme certificate. | Published licence evidence and verification links |
| Cyber Essentials price | Compare the correct organisation-size tier and check whether feedback or re-submissions cost extra. | From £299.99 + VAT, with three assessor-feedback rounds included |
| Turnaround commitment | A published service level matters when certification is tied to a tender, renewal, or customer deadline. | 6-working-hour guarantee for compliant self-assessments |
| Cyber Essentials Plus | Confirm that the provider can deliver the technical audit as well as the underlying self-assessment. | Available from £1,499.99 + VAT |
| London delivery fit | Most assessments are remote, but complex estates may benefit from local scoping or justified site attendance. | Remote-first delivery from a Fitzrovia-based team |
Location matters when a complex on-premise estate needs careful scoping or a technical audit genuinely requires attendance. Confirm the delivery model and any travel charge before buying; a London address alone does not improve the certificate.
If you are comparing providers across the UK, use our national Cyber Essentials certification-body comparison. This London page remains focused on certification and delivery for London organisations.
London pricing
All Cyber Essentials and Cyber Essentials Plus pricing is fixed-fee, plus VAT, with no per-user fees and no hidden re-submission charges.
Includes the IASME-delivered questionnaire, assessor review, three free assessor-feedback rounds, and the issued 12-month certificate. Eligible holders may separately receive a cyber-liability benefit arranged by IASME and its insurance partner; Fig Group does not provide or arrange it.
| Tier | Staff | Fee (+ VAT) |
|---|---|---|
| micro | 1-9 | £299.99 |
| small | 10-49 | £399.99 |
| medium | 50-249 | £449.99 |
| large | 250 - 9,999 | £549.99 |
Independent technical verification of the Cyber Essentials controls. Check whether you need the combined CE and Plus package or a standalone Plus audit completed within three months of a same-scope Cyber Essentials certificate.
| Tier | Staff | Fee (+ VAT) |
|---|---|---|
| micro | 1-9 | £1,499.99 |
| small | 10-49 | £1,999.99 |
| medium | 50-249 | £2,799.99 |
| large | 250 - 9,999 | £4,499.99 |
Full hubs: Cyber Essentials and Cyber Essentials Plus.
Delivery model
The vast majority of London engagements run end-to-end over phone, email, and screen-share. Hybrid teams often have laptops scattered across home offices in Greenwich, Wimbledon, St Albans, and beyond; a remote audit reaches the real estate more reliably than a single office visit.
We are physically registered in Fitzrovia. Where a site visit genuinely helps, for example clinical equipment that does not lend itself to remote screen-share, we will discuss it. Treat that as the exception rather than the standard product.
London examples
These examples use public Google review evidence where a client is named. Chambers work is anonymised because legal clients generally do not want supplier marketing to identify them.
London-based recruitment agency
Luc described the process as fast, straightforward, reasonably priced, and easy to manage. Recruitment agencies often need Cyber Essentials for PSL access, framework agreements, and client onboarding.
London-based insurance claims adjusting company
Alex praised the turnaround, communication, and customer service. Claims adjusting firms typically need Cyber Essentials for panel requirements from upstream insurers and reinsurers.
London clinical practice
Simon noted out-of-hours support and that we came to look at equipment where remote evidence was not enough. Site attendance is an exception, but it is available when it genuinely de-risks the scope.
Anonymised client example
Chambers are a scoping problem because individual barristers are self-employed but share clerks, networks, and case-management systems. The useful work is a careful scope statement before the questionnaire starts.
Review source: Fig Group Google Business Profile review feed, mirrored in the site review dataset.
Related context: criminal chambers, and SJP Partner Practices.
London-specific FAQs
SJP's published reporting describes Cyber Essentials Plus or its Device as a Service solution for Partner Practices. Confirm your applicable route with SJP. A law firm's introducer or panel contract is a separate arrangement: check its exact certification level and scope before purchasing.
Document your devices, accounts, cloud services and network connections, including responsibility for shared infrastructure. A serviced-office address does not automatically exclude the building network. Agree the boundary and any evidence needed from your provider with the assessor against current scheme requirements.
Requirements differ by insurer and policy. Ask the insurer or its authorised intermediary which certification level, scope and supporting evidence it accepts. Cyber Essentials does not guarantee insurance availability, acceptance or a lower premium. Fig Group provides certification, not insurance advice or placement.
Cyber Griffin is an awareness and incident-support programme. Cyber Essentials is a baseline technical certification. They complement each other: Griffin helps with threat awareness, while Cyber Essentials provides the procurement-ready certificate and the five technical control areas.
Default delivery is remote. We are based in Fitzrovia and can meet in person where there is a clear reason, such as complex scoping for a chambers, group structure, or clinical estate. Cyber Essentials Plus audits are not sold as standard on-site London visits.
Yes. We routinely sign client-form mutual NDAs at the scoping stage, or we can provide our own short standard form. There is no fee or delay associated with NDA execution.
Scope follows organisational data and controlled devices, not the employee's physical location. Overseas employees with company laptops are in scope, and BYOD access to organisational data needs a clear scope decision.
Renewal is a new annual certification purchase at the price published for your staff band when you renew. We do not charge separately for the renewal questionnaire, renewal review, or renewal certificate.
If you have a deadline, call +44 (0) 203 105 2335. If you are still scoping, the Cyber Essentials hub has the readiness checker and full scheme detail. Procurement teams can verify our trust claims register and IASME licence record before purchase.
The Fig Group Limited is registered in England and Wales, Companies House 16845978, at 167-169 Great Portland Street, 5th Floor, London W1W 5PF.