Cyber Essentials
Certification only

One-off · no recurring fee
- Self-assessment + assessor review
- 6-hour guarantee
- Official certificate from Fig Group, on passing.
Certification from £299.99 + VAT
Micro organisations · 1–9 staff · One-off payment
Independent assessor review and three free rounds of feedback. Choose your organisation size to see your exact price.
6-working-hour guarantee for compliant Cyber Essentials submissions before midday on a UK business day. See the terms.
Choose who you’re buying for and the organisation size to see pricing.
Certification only

One-off · no recurring fee
Technical audit · CE required

One-off · no recurring fee
Both certifications


One-off · no recurring fee
Select your organisation size to see your package saving.

Cyber Essentials Plus from £1,499.99 + VAT · Compare Plus
The five things buyers ask first: from price and turnaround to the credentials behind your certificate.
The cheapest IASME-licensed CE body in the UK. Three free rounds of assessor feedback included.
Choose your certification Select your organisation size to see your price.6 working hours for compliant submissions - or a full refund. The fastest in the UK.
See the assessment processYes - Fig Group delivers certification through IASME-licensed Fig Compliance Ltd, not a reseller.
Verify our licenceVersion 3.3 applies to new assessment accounts under the April 2026 update. Check your portal for the question set assigned to your account.
Explore the five controlsYes - Companies House #16845978, ICO ZC072182, and listed in the IASME directory.
View our credentialsClear pricing, a dedicated assessor and three free rounds of feedback. Purchase your assessment and receive portal access within 15–30 minutes.
Choose your package Cyber Essentials from £299.99 + VATReturned within six working hours of a complete, compliant Basic submission before midday UK time on a UK business day, or a full refund. Clarification, remediation and Plus assessments are excluded.
View our guarantee termsSpeak to us about enterprise and multi-organisation requirements.
Discuss your requirementsOverview
Fig Group delivers certification through IASME-licensed Fig Compliance Ltd assessing organisations of every size for both Cyber Essentials and Cyber Essentials Plus under the NCSC-backed scheme.
Based in
London, UK
Turnaround
6 working hours for eligible Basic submissions
Cyber Essentials
From £299.99 + VAT
Cyber Essentials Plus
From £1,499.99 + VAT
A foundational certification scheme backed by the UK government and NCSC.
Cyber Essentials, defined
The UK government’s foundational cybersecurity certification scheme - independent validation that an organisation has implemented the controls needed to defend against the most common cyber attacks.
Use the certificate to support customer assurance and relevant procurement requirements. Check the scope and certification level your buyer asks for.
A UK government-backed scheme overseen by the NCSC, with IASME as its delivery partner.
Five core technical security controls - listed to the right.
Check the required certification and scope in your tender or customer contract.
IASME-licensed certification body approved for both Cyber Essentials and Cyber Essentials Plus.

Control inbound and outbound internet access at the boundary
Harden systems and remove unnecessary services
Implement strong authentication and privileges
Deploy and maintain anti-malware solutions
Keep software and devices updated with security patches
Choose the certification level that fits your needs.
Self-assessed
IASME questionnaire reviewed by a Fig Group assessor. Our six-working-hour guarantee covers complete, compliant Basic submissions received before midday on a UK Business Day - the fastest in the UK. See the guarantee terms.
Independent technical audit
Adds external vulnerability scanning and a sampled technical audit on top of the same five controls.
| Feature | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|
| Assessment type | Self-assessed | Third-party verified |
| External audit | - | |
| Vulnerability scan | - | |
| Certification validity | 1 year | 1 year |
| Choose when | Your buyer asks for Cyber Essentials | Technical verification or Plus is required |
Both certificates are valid for 12 months. Plus adds technical verification of the same five control areas. The Plus assessment must take place within three months of the Cyber Essentials certification, covering the same scope.
IASME-licensed, transparent, and built for modern organisations.
About Fig Group
An IASME-licensed Cyber Essentials certification body approved to assess organisations for both Cyber Essentials and Cyber Essentials Plus.
IASME-licensed for Cyber Essentials and Cyber Essentials Plus, under the NCSC-backed scheme.
Fully published. No hidden fees, no post-purchase surprises, no mandatory consultancy.
UK-wide - from micro organisations to large enterprises, across all four organisation-size tiers.
Dedicated team available throughout the process for questions and guidance.


Four clear stages from purchase to certificate, with human assessment and three free rounds of feedback.

Select your organisation size and certification. Portal access is issued automatically within 15–30 minutes of purchase.
Secure checkoutConfirm your scope, prepare accurate answers and obtain the required organisational sign-off. Your MSP can help you prepare.
Work with your IT teamSubmit your complete, compliant Basic questionnaire before midday UK time on a UK business day for Fig’s six-working-hour guarantee. Submissions needing clarification or remediation are excluded. Three rounds of assessor feedback are included if clarification is needed.
Human assessor reviewWhen you pass, Fig Group issues your official certificate, valid for 12 months. If you purchased the package, the Plus technical audit follows the CE assessment.
Certification on passingBuying through an MSP? Your organisation reviews and authorises the submission, and provides the required portal sign-off. Working with an MSP
Open the IASME certification video
Video by IASME - the delivery partner behind Cyber Essentials certification.
Three buying contexts where certification is most often required.
Public sector
Procurement Policy Note 014 explains when in-scope public bodies should require Cyber Essentials, Cyber Essentials Plus or equivalent controls. Check the tender for the required certification, scope and deadline. It is not a blanket requirement for every government contract.
Private sector
Customers may request Cyber Essentials as part of supplier due diligence. A certificate helps demonstrate baseline controls within its stated scope. Insurers set their own terms; certification does not guarantee cover or reduced premiums. Explore insurance-related evidence.
Higher value
For higher-value or higher-risk contracts, Cyber Essentials Plus is increasingly preferred because it adds third-party verification rather than self-assessment alone. If you are bidding for government work or higher-tier supply chain roles, speak to our team about the right certification level.
Use our self-assessment tool to identify gaps before formal certification.
Everything you need to know about Cyber Essentials.
Cyber Essentials is a UK government-backed certification scheme focused on five technical control areas: firewalls, secure configuration, user access control, malware protection and security update management. It addresses common internet-based threats, not every aspect of cyber security.
Fig Cyber Essentials starts at £299.99 + VAT. Select the staff count of the organisation being certified to see the correct price. Cyber Essentials Plus and the combined package are priced separately.
Fig provides a six-working-hour guarantee for complete, compliant Cyber Essentials Basic submissions through the prescribed process before midday UK time on a UK business day. Submissions requiring clarification or remediation are excluded. Preparation and any work needed to address gaps are separate from the review. Cyber Essentials Plus involves a separately scheduled technical audit.
Cyber Essentials uses an assessor-reviewed self-assessment. Plus adds technical testing against the same controls. The underlying Cyber Essentials certificate must cover the same scope, and the Plus assessment must take place within three months of achieving it.
The package includes Cyber Essentials self-assessment and assessor review, followed by the Cyber Essentials Plus technical audit. Each certification is awarded only when its assessment requirements are met.
Certification lasts 12 months. Renew annually to maintain a current certificate; controls must continue to be maintained between assessments.
Your MSP can help prepare and complete the self-assessment on your behalf. Your organisation must review and authorise the submission and provide the required sign-off in the assessment portal. Responsibility for accurate answers remains with your organisation.
Version 3.3 clarifies cloud scope and authentication requirements. Available cloud MFA must be used, including paid options. The applicable question set is tied to account creation; check your assessment portal rather than assuming every submission uses the newest version.
No. PPN 014 sets out the approach for in-scope public procurement. The tender specifies the required certification or equivalent controls, scope and timing. Other customers may set their own contractual requirements.
Fig includes three rounds of assessor feedback at no extra cost. Review the guidance, make any necessary changes to your controls and update your answers before resubmitting. Buying an assessment does not guarantee a pass.
No. ISO 27001 addresses an information security management system, while Cyber Essentials focuses on five technical control areas. Insurance cover and premiums are determined separately by insurers.
Open the topics relevant to your organisation. Pricing, assessment and the readiness checker remain above.
A key requirement: multi-factor authentication for cloud services wherever it is available, including paid options.
The April 2026 update ties the question set to when the assessment account is created, not when it is submitted. Existing accounts can continue with their assigned question set during their completion window. Check the version shown in your portal.
Where a cloud service offers MFA, it must be enabled. The requirement includes free, included and paid options. Under the updated marking criteria, failing to enable available cloud MFA causes the assessment to fail.
Define the organisation, devices and services being certified using the current requirements. Include relevant personally owned devices used for organisational work; do not assume remote working removes them from scope.
Cloud services that store or process organisational data cannot simply be excluded. Establish which security responsibilities belong to your provider and which remain with your organisation.
Cyber Essentials v3.3 requires MFA wherever it is available and always for cloud services. Here is what the rule covers, what triggers an automatic fail, and how to prepare.
The 14-day patching requirement is the single most common reason Cyber Essentials submissions fail first time. Here is what the rule actually says, when the clock starts, and how to evidence compliance when users are on holiday, vendors are slow, and legacy systems will not update.
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, what v3.3 (Danzell) actually says about home routers for remote workers, default credentials, and the cloud firewall configuration assessors expect in 2026.
Secure configuration is the control area with the broadest scope and the most room for getting details wrong. This guide covers default passwords, auto-run, unnecessary software, cloud service configuration, and the specific settings assessors check against v3.3 (effective 27 April 2026).
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
Configure Microsoft 365 MFA for Cyber Essentials v3.3: Security Defaults and Conditional Access, current number matching, administrator recovery and evidence of enforcement.
Google Workspace 2-Step Verification for Cyber Essentials v3.3: enrolment, effective enforcement, administrator recovery and current OAuth client guidance.
Review Conditional Access for Cyber Essentials v3.3: effective MFA, location exclusions, authenticated sessions, device trust and safe administrator recovery.
Guidance for your business location
Explore local business context, practical preparation examples and UK-wide assessment pricing. Fig provides online certification; these guides do not represent local offices.
UK-wide pricing
Published assessment prices by organisation size, not postcode.
Six-hour SLA
Compliant submissions return certified within six working hours.
Sector context
Financial services, legal, MSPs, and government supply chains - by city.
Start here
Five core security control categories - access control, patch management, secure configuration, malware protection, and firewalls. This work can support a broader information security programme, but Cyber Essentials is not equivalent to ISO 27001 certification.
Practical, achievable first step. Certification in 6 working hours for complete, compliant Basic submissions before midday UK time on a UK business day.
Progress to
The international standard for information security management. Reuse your Cyber Essentials evidence and controls as a foundation, reducing duplication and shortening the path to certification.
When your business requirements demand a broader ISMS, your Cyber Essentials work already counts.
Fig supports broader compliance requirements - ISO 27001, NIS2, GDPR, SOC 2, CMMC and more.
Cyber Essentials vs ISO 27001Use the official scheme guidance alongside your assessment question set. Scheme information reviewed on 8 September 2026; Fig’s prices and service commitments are separate from the scheme rules.
Choose the assessment your organisation needs, or speak to our team about scope and preparation.
5 out of 5 from 52 Google ratings, including 46 written reviews.
Customer experiences of Fig’s Cyber Essentials certification across organisation sizes. Read reviews on Google.
“An excellent assessor for those seeking Cyber Essentials certification. The company promises 6 hour turnaround time on...”
“Amazing service for CE, assessment is marked within hours.”
“Very efficient”
“We engaged FIG Group for the Cyber Essentials assessment and certification. We found the process to be very efficient...”
“Used Fig Group for Cyber Essentials Certification for Acuity AI Education Ltd. - The process was smooth, quick and had...”
“Very fast, professional and supportive of our company through the Cyber Essentials application.”
“Very straightforward! Easy to access, very fast response times! Very happy, will go to Fig Group for my renewal, that's for sure!”
“Great provider, very clear and easy to use. Incredibly quick service too. We will definitely use Fig again when the need arrises”
“Excellent service throughout the Cyber Essentials process. The assessor was professional, responsive and helpful, and the assessment was completed smoothly. I would definitely recommend Fig Group.”
“Very fast and thorough Cyber Essentials audit, even completed on a Sunday. Really lived up to the advertised promise.”
“2-hour turnaround - excellent service!!!”
“We recently used Fig Group to support our business in achieving Cyber Essentials accreditation and were extremely impressed with the service we received. The whole process was straightforward and easy to follow, with excellent support throughout. The assessment was completed quickly, and the turnaround time was fantastic. We would highly recommend Fig Group to any business looking for support with their cybersecurity requirements.”
“Good support and response. The questionnaire could do with an update.”
“We had a great experience working with the Fig Group. They were prompt, professional and supportive all the way. Highly recommended. Will work with them again!!!”
“I never expected that fast service, highly recommend”
“Such a fantastic service. Jay was super quick but very thorough in the feedback. Super clear, really friendly and got my application done within the same afternoon! 100%”
“Very slick and expedient assessment process and at a very reasonable cost”
“Our assessor from Fig Group was super responsive (minutes, not hours or days as we've experienced previously when certifying) - this made the whole process much more efficient and fluid. Thank you. Recommended.”
“Once I submitted our first draft, I got feedback within minutes, and after I amended some answers following that feedback, we immediately received our Cyber Essentials certificate. Genuinely impressed!”
“Very straight forward and easy to complete the assessment.”
“As a first-time applicant I wasn't sure what to expect from Cyber Essentials, but Fig Group made it genuinely straightforward. The self-assessment was clearly structured and the questions were well framed and easy to follow, even without a deep security background. Denzel, who assessed our submission, was thorough and clear about what was needed, and the turnaround was quick. The website is clear and easy to navigate too. Highly recommend Fig Group to anyone going through CE for the first time. Thank you!”
“Efficient service and competitive pricing. Can recommend 100%”
“The Rate at which the Cyber Essential Certification Process was completed was exceptional , Fig Group promised to review and complete CE Assessment within 6 Hours, Low and Behold, When I registered on their website for my Company's Cyber Essential Application, the whole process for Assessment review and Certification was Done exactly as Promised. I will now enrol my Company for the Cyber Essential Plus within the next Two Weeks”
“Great service from Jay and the team at Fig Group. The Cyber Essentials process was simple, well organised, and easy to complete. Communication was excellent throughout, and we received prompt support whenever needed. Highly recommended.”
“Fantastic service. Will recommend to our clients who are looking for Cyber Essentials support and certification.”
“An excellent service Jay is outstanding not only to suggest that the service would be quicker than anybody else but cheaper he delivered”
“We had a very positive experience with Fig Group while completing our Cyber Essentials certification. The team was professional, knowledgeable and supportive throughout the process. They explained the requirements clearly, responded promptly to our questions and helped us understand what was needed to meet the assessment standards. Their guidance made the process much easier to manage, and we are grateful for their patience and support. I would highly recommend Fig Group to any organisation looking for reliable support with Cyber Essentials certification.”
“Excellent service and a very fast turnaround. I'm very happy to recommend them and will definitely use their services again next year.”
“We recently needed to obtain Cyber Essentials certification for our technology company, which operates across the United States, the United Kingdom, and Europe. After evaluating a number of providers, we chose FIG Group, and the experience was outstanding from start to finish. The onboarding process was straightforward. Payment was quick, and the online assessment questions were clear and easy to understand. Whenever additional information or clarification was required, the feedback process was very good. Our certificate was issued promptly, and we received both a digital certificate and confirmation documentation immediately. A special mention goes to Jay Hopkins, Managing Director of FIG Group, who was extremely helpful throughout the process. In addition to guiding us through Cyber Essentials certification, he also provided valuable advice regarding other certifications we are considering. If you are looking for a responsive provider for Cyber Essentials or Cyber Essentials Plus certification, I would highly recommend FIG Group. Based on our experience, they are one of the best providers we encountered during our search.”
“Great experience using Fig Group to attain my Cyber Essentials certification. Everything was completed within a working day and response was super fast. Very competitive pricing too! Highly recommend. Kev Park, Director @ KP Kreative”
“Easy, fast. Great experience.”
“Jay and the team at Fig Group were great - nice simple but thorough process and well digitised as you would hope! Would recommend.”
“Jay couldn't have been more helpful. As a total novice, I was very grateful for his thorough and responsive support. Would not hesitate to recommend to others. 5 star service.”
“We recently worked with the FIG Group to secure our Cyber Essentials certification for the Breakthrough Transformation Trust, and the experience was excellent. We recommend FIG Group to any organization looking for a professional, efficient, and reliable cybersecurity partner.”
“They managed my cyber essentials accreditation quickly and efficiently providing clear advice and feedback.”
“I have no hesitation in recommending this company. They were excellent in assisting with Cyber Essentials Accreditation procedure. Some really helpful feedback on the application that helped to being it home. I wouldn't hesitate to (and will) use them again in the future.”
“Amazing service and process, automated, quick and easy! They have mastered the automation and in return excellent service ! thank you ! see you next year and keep the price competitive !”
“Recently completed Cyber Essentials certification through Fig Group. The process was straightforward, communication was clear throughout, and the process was completed quickly. I found the guidance practical and easy to follow. Would recommend for SMEs looking to obtain Cyber Essentials certification without unnecessary complexity.”
“Fast, well supported service and excellent value. Would absolutely recommend.”
“We recently completed our Cyber Essentials certification with Fig Group and had a great experience from start to finish. The process was fast, straightforward, and very reasonably priced. Jay was particularly professional and helpful throughout, making everything clear and easy to manage. I would definitely recommend Fig Group to any business.”
“Great service and fast turnaround. Working with the Fig Group to achieve our Cyber Essentials accreditation was a really positive experience. A process I have previously found long-winded and difficult was made straightforward and simple from start to finish. Communication was clear, the turnaround time was excellent, and the customer service from Jay was outstanding throughout. I would highly recommend them to anyone looking to get Cyber Essentials accreditation without the usual hassle.”
“Jay at the Fig group was very helpful in helping my small business though our certification process. He got straight in contact even though it was out of hours and supported me in answering the questions. He even came and looked at some of our equipment when I wasn't sure (can't guarantee that kind of service for everyone!). He went above and beyond and I cannot recommend him enough.”
“The process was extremely efficient: short phone call, submission, pass. Highly recommended.”
“Excellent Service, Professional handling and support, the best for fast track”
“Genuinely impressed with the Cyber Essentials experience via Fig Group. As a two-director UK tech company, we wanted certification done properly rather than superficially. The assessor, Jay Hopkins, was precise, fair, and constructive throughout, the feedback we received on our first submission was proportionate and gave us a clear path to remediation rather than a blanket rejection. The whole process from registration to certificate took under a week, and the end result is a real uplift in our security posture, not just a box-ticking exercise. The free cyber liability insurance included for businesses under £20m turnover is a meaningful additional benefit. Highly recommended for any UK SME looking to take cyber security seriously.”
“Purchased a cyber essentials self assessment. Turned it around in under 2 hours. Great team.”