Cyber Essentials FAQ
Find answers about certification, pricing, technical requirements and the assessment process. Search for a topic or browse the questions below.
67 answers available
Quick answers
The five things buyers ask first.
- How much does Cyber Essentials cost?
- From £299.99 + VAT for Micro (1-9 staff). The cheapest IASME-licensed CE body in the UK.
- How fast is certification?
- 6 working hours for compliant submissions - or a full refund. The fastest in the UK.
- Is Fig Group IASME-licensed?
- Yes - Fig Group is an IASME-licensed Cyber Essentials certification body, not a reseller.
- Which scheme version is in effect?
- Cyber Essentials v3.3, effective 27 April 2026.
- Is Fig Group independently verifiable?
- Yes - Companies House #16845978, ICO ZC072182, and listed in the IASME directory.
The Cyber Essentials scheme
8 answers
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme that validates five technical cyber controls: firewalls, secure configuration, user access control, malware protection, and security update management. It is delivered by IASME on behalf of the NCSC.
Open this answer on its own pageWhat is Cyber Essentials Plus?
Cyber Essentials Plus independently tests the same five control areas after the Cyber Essentials verified self-assessment. It includes specified internal and external tests, rather than only an external scan. A buyer may require Plus for a particular contract or risk profile; it is not a universal requirement for all large supply chains.
Open this answer on its own pageWho administers Cyber Essentials?
IASME (Information Assurance for Small and Medium Enterprises) delivers the scheme on behalf of the NCSC. IASME licenses Certification Bodies - Fig Group among them - to assess organisations.
Open this answer on its own pageIs Cyber Essentials UK-only?
Cyber Essentials is a UK government-backed scheme, but organisations outside the UK can apply. A UK legal entity is not a universal eligibility requirement. Agree the applicant organisation and assessment scope with an IASME-licensed Certification Body; any scheme-arranged insurance has separate eligibility conditions.
Open this answer on its own pageWhat is the difference between Cyber Essentials and ISO 27001?
Cyber Essentials tests five technical control areas. ISO/IEC 27001 certifies an information security management system against its selected scope, risk treatment and applicable Annex A controls, documented in a Statement of Applicability. They answer different buyer requirements; use the written contract to choose the right assurance. See our Cyber Essentials versus ISO 27001 guide for a comparison.
Open this answer on its own pageWhat is Cyber Essentials v3.3?
Version 3.3 is the NCSC Cyber Essentials Requirements for IT Infrastructure used for assessments opened from 27 April 2026, alongside the Danzell question set. It clarifies cloud scope and passwordless authentication. Enable MFA where available; cloud authentication must use MFA. It does not introduce a universal requirement for a fresh MFA prompt on every sign-in. Follow the version assigned to your assessment.
Open this answer on its own pageHow do I pass Cyber Essentials first time?
Use Fig Group’s self-reported readiness checker, then verify the actual controls across the agreed scope; the checker does not inspect devices or award certification. The six-working-hour Basic guarantee requires a complete, compliant submission before midday on a UK business day under the terms. Three free re-submissions support corrections. The recorded 100% completed-assessment pass rate is historical; certification still depends on meeting every applicable control.
Open this answer on its own pageWho can certify me for Cyber Essentials?
Use the IASME Certification Body directory to verify a provider and the licensed scheme before buying. Fig Group is the cheapest IASME-licensed Cyber Essentials Certification Body in the UK at every published staff tier, based on the dated comparison on our claims evidence page, and the fastest under its six-working-hour Basic guarantee requires a complete, compliant submission before midday on a UK business day under the terms. The 100% pass rate describes recorded completed assessments; every applicant must still meet the controls.
Open this answer on its own pagePricing and payment
6 answers
How much does Cyber Essentials cost in the UK?
Fig Group is the cheapest IASME-licensed Cyber Essentials Certification Body in the UK. Prices excluding VAT are £299.99 Micro, £399.99 Small, £449.99 Medium and £549.99 Large; our Enterprise route for 10,000+ staff is quoted separately. These are below IASME's published direct-purchase fees. The six-working-hour guarantee applies to complete, compliant Basic submissions before midday on a UK business day, subject to the terms. Three free re-submissions are included. Any scheme-arranged insurance has separate eligibility and is not supplied by Fig Group.
Open this answer on its own pageHow much does Cyber Essentials Plus cost?
Fig Group Cyber Essentials Plus prices excluding VAT are £1,499.99 Micro, £1,999.99 Small, £2,799.99 Medium and £4,499.99 Large. Check whether you are purchasing Plus only or a combined Basic and Plus path and confirm the matching-scope Basic prerequisite. The published audit price does not imply unlimited remediation consultancy or continuous scanning; agree any additional work before purchase.
Open this answer on its own pageIs there a charge for re-submissions?
Fig Group includes three free Cyber Essentials re-submissions to respond to assessor feedback within the applicable assessment period. They do not waive controls, create unlimited attempts or purchase a fresh assessment. If gaps remain after the included rounds or the assessment time limit, discuss any further support, extension or new purchase under the published terms before incurring a charge.
Open this answer on its own pageDoes Fig Group offer charity discounts?
Fig Group does not currently publish a separate charity discount. The Micro tier is £299.99 + VAT, subject to the correct staff band. The previous NCSC funded programme is closed; check a newly announced official funding scheme and its eligibility before budgeting for a grant.
Open this answer on its own pageIs the price VAT-inclusive?
No. Fig Group publishes prices excluding VAT. UK VAT is added at checkout for UK-based organisations.
Open this answer on its own pageCan I pay by invoice?
Stripe card checkout is the standard Cyber Essentials purchase route. For Cyber Essentials Plus or larger corporate engagements, request invoice approval through the contact form before purchasing; invoicing and any payment timetable must be agreed in writing. Enterprise invoicing is available on request.
Open this answer on its own pageTimelines and turnaround
6 answers
How fast is Fig Group Cyber Essentials certification?
Fig Group guarantees six working hours for complete, compliant Cyber Essentials Basic submissions received before midday on a UK business day, subject to the certification terms. Preparation, clarification, remediation and third-party delays are outside the guarantee. It does not apply to Cyber Essentials Plus or DCC.
Open this answer on its own pageIs same-day Cyber Essentials possible?
Yes. Fig Group's six-working-hour guarantee applies to complete, compliant Cyber Essentials Basic submissions before midday on a UK business day, subject to the terms. Required corrections or missing evidence can prevent same-day issue. Purchasing an assessment does not start an unconditional certification clock.
Open this answer on its own pageHow long does Cyber Essentials Plus take?
Fig Group targets two to three working days for the Plus assessment of a prepared organisation. That is an assessment planning estimate, subject to assessor scheduling, device sampling under the current specification, access and remediation or retesting. Preparation can take longer; certification follows a successful audit. The six-working-hour Basic guarantee does not apply.
Open this answer on its own pageHow long is a Cyber Essentials certificate valid?
Cyber Essentials certification is renewed annually. Use the validity and expiry details on the issued certificate when planning continuity; an assessment start date is not a substitute for the certificate record. Arrange renewal early enough to complete any required remediation before expiry.
Open this answer on its own pageWhat happens if my Cyber Essentials lapses?
An expired certificate no longer demonstrates current certification. Check the certificate validity and the buyer's requirement, and complete a new assessment against the applicable requirements. Do not assume that an expired certificate disappears from every record, that a buyer allows a grace period, or that a renewal has fewer required questions.
Open this answer on its own pageWhat happens if I fail the Cyber Essentials assessment?
Fig Group provides assessor feedback and three included re-submissions so you can correct gaps before a compliant decision. The published terms govern the available advisor support, assessment time limit and any further paid work or new assessment. Unresolved controls cannot be marked as a pass. The 100% pass rate covers recorded completed assessments, not a guarantee for every unprepared applicant.
Open this answer on its own pageScoping and devices
6 answers
What is in scope for Cyber Essentials?
Agree the organisation and scope boundary with your Certification Body before assessment. Include the devices and services used to access organisational data or services, including end-user devices and relevant cloud services. A separately managed subset needs an accepted technical boundary and a justified exclusion; a device is not automatically excluded because it stores no files locally.
Open this answer on its own pageIs BYOD in scope under v3.3?
Personal devices accessing organisational data or services are generally in scope, including devices used to access a virtual desktop. VDI, MDM or Conditional Access does not automatically remove an endpoint from scope. Agree any separately managed, network-segregated subset with your assessor. Devices used only for native voice, native text or MFA applications have a specific exception.
Open this answer on its own pageAre home routers in scope?
A home router supplied by the worker or their internet provider is outside the assessment scope. A router supplied by the organisation is in scope and must meet the applicable controls. Protect remote-working devices with the required firewall controls; using home broadband does not exclude the endpoint itself.
Open this answer on its own pageAre cloud services in scope?
Yes. Include cloud services used for organisational data or services. For SaaS, you normally manage user access, MFA and tenant settings while the provider manages its infrastructure. For IaaS, you also manage your guest operating systems and their security updates. Document the shared-responsibility boundary and actual service scope with the assessor.
Open this answer on its own pageIs our AWS production account in scope?
Do not exclude production AWS by default. Cloud services used for organisational data or services belong in the agreed scope, and a SOC 2 report or ISO certificate does not substitute for that decision. Discuss the actual service, responsibilities and any proposed separately managed subset with your Cyber Essentials assessor.
Open this answer on its own pageAre contractors in scope?
Assess accounts and endpoints separately. An organisation-owned device loaned to a contractor is in scope; a device owned by that third party is outside your device assessment, while the account accessing your service remains under your access controls. Employee BYOD and VDI follow their own scope rules. List device owner, user relationship and authentication path for each arrangement.
Open this answer on its own pageMulti-factor authentication
5 answers
Is MFA mandatory under v3.3?
Implement MFA wherever it is available, and for authentication to cloud services. IASME treats available MFA as including paid or connected options; a licence cost does not create an exemption. Document genuinely unsupported services with the assessor. Check user, administrator and third-party access; registration without enforcement is insufficient, while a new MFA prompt on every session is not universally required.
Open this answer on its own pageWhich MFA methods are acceptable?
Use an implementation that provides the required independent authentication factors. FIDO2 passkeys with user verification can satisfy MFA. Authenticator codes, appropriately secured push flows and SMS-based combinations can also be relevant; SMS is not universally banned by the scheme. Prefer phishing-resistant methods for higher-risk access and verify the actual configuration.
Open this answer on its own pageCan we exempt some accounts from MFA?
Use MFA wherever it is available and for authentication to cloud services. Offered MFA includes paid or connected options; a licence cost is not itself an exemption. Document a service that genuinely has no compatible MFA and agree treatment with the assessor. Do not treat an administrator, contractor, emergency or service account as a blanket cloud-MFA exception; identify interactive and non-interactive paths separately.
Open this answer on its own pageDoes conditional-access MFA pass v3.3?
Conditional Access can enforce MFA if every applicable cloud authentication path actually receives it. A trusted-location rule that bypasses cloud MFA is insufficient. Supported passkeys with user verification can meet the requirement, and a valid authenticated session does not require a fresh prompt on every request. Check the effective policies, exclusions, legacy paths and session settings with the assessor.
Open this answer on its own pageDoes MFA apply to admin accounts?
Apply the same availability and mandatory cloud-authentication rules to administrator accounts, and keep administration separate from everyday work. Phishing-resistant methods such as FIDO2 security keys are strong recommendations for privileged access; Cyber Essentials does not universally prescribe a particular brand or hardware key.
Open this answer on its own pageTechnical controls and assessment
6 answers
What is the 14-day patching rule?
Apply qualifying fixes within 14 days of vendor release: those addressing vendor-rated high or critical vulnerabilities, a CVSS v3 base score of at least 7, or vulnerabilities whose severity the vendor does not describe. A bundled update inherits that deadline if it contains a qualifying fix. A monthly maintenance window is insufficient whenever it misses that deadline; plan an expedited route.
Open this answer on its own pageIs Windows Defender acceptable for CE?
Microsoft Defender can form part of a compliant Windows malware-protection configuration. Check its active protection, updates, malicious-code prevention and protection against malicious websites against the requirements. A product name or a green status alone does not demonstrate every required control. Tamper protection is useful hardening, rather than a separately named universal scheme requirement.
Open this answer on its own pageCan we use a Mac for Cyber Essentials?
Yes. A supported macOS version can meet Cyber Essentials when the device is correctly configured, updated and protected by an accepted malware-control option. Verify the actual protection settings and other applicable controls against the v3.3 requirements; the presence of XProtect or Gatekeeper alone is not proof. FileVault encryption is useful hardening, not a universal requirement of the five-control scheme.
Open this answer on its own pageIs Linux in scope?
Linux systems are in scope when they fall within the agreed assessment boundary. Meet the applicable firewall, configuration, access and update controls. Under v3.3, application allow listing is the malware-protection option available across all platforms; do not assume installing ClamAV alone establishes the required Linux control.
Open this answer on its own pageDo we need an EDR tool?
No EDR subscription is prescribed. Configure supported endpoint malware protection, enabled updates and applicable malicious-code and website protections, then verify it operates across in-scope devices. Vulnerability scanning and advanced EDR detection may improve assurance, but buying EDR alone does not establish Cyber Essentials compliance.
Open this answer on its own pageHow often do you run vulnerability scans for CE Plus?
Cyber Essentials Plus includes the specified initial technical tests, including external and representative internal testing; remediation can require retesting before a compliant result. These audit checks are distinct from optional continuous vulnerability scanning between annual assessments. Agree the current test specification, asset sample, access and any retest schedule with your assessor.
Open this answer on its own pageGovernment, procurement, and supply chain
5 answers
Is Cyber Essentials mandatory for UK government contracts?
PPN 014 applies to specified central-government and NHS bodies and relevant procurements, with proportionate assurance and equivalent-control provisions. Check the tender for the required certification or accepted equivalent, scope and award timing. Transitional procurements may refer to PPN 09/23. It is not a blanket rule for every public-sector supplier.
Open this answer on its own pageWhat is PPN 014?
PPN 014 is the central-government procurement policy on Cyber Essentials. In-scope organisations identify relevant contracts and apply the policy proportionately, with the specified equivalent-control provisions. Check the tender for the required assurance, scope and award timing. It is not a universal rule for every public-sector contract or every supplier handling sensitive information.
Open this answer on its own pageDo private-sector buyers require Cyber Essentials?
Some private-sector buyers require Cyber Essentials or Cyber Essentials Plus through supplier contracts. The required level, organisational scope and any accepted alternative depend on the buyer and engagement. Ask for the current written requirement rather than assuming a universal rule for a sector or every Tier 1 supplier.
Open this answer on its own pageDoes Cyber Essentials reduce cyber insurance premiums?
Fig Group does not promise a premium reduction. A customer may share its CE or CE Plus certificate and supporting evidence with an insurer, broker, or underwriter, but the recipient makes its own independent pricing, terms, and coverage decisions.
Open this answer on its own pageCan our MSP get Cyber Essentials on our behalf?
Cyber Essentials is certified per organisation, not per MSP. Your MSP can manage the assessment and remediation, but your organisation signs the attestation and holds the certificate.
Open this answer on its own pageDefence Cyber Certification (DCC)
18 answers
What is Defence Cyber Certification?
DCC provides independent assurance against the MOD Cyber Security Model and is delivered by IASME. The current scheme has numeric Levels 0 to 3. It supports, rather than replaces, contract-specific supplier assurance: the full Supplier Assurance Questionnaire remains required under current MOD guidance.
Open this answer on its own pageDoes DCC replace the DCPP Supplier Assurance Questionnaire?
No. Current MOD guidance requires the full contract-specific Supplier Assurance Questionnaire through the Supplier Cyber Protection Service, including for DCC certificate holders. DCC independently evidences organisational assurance against Def Stan 05-138 Issue 4; the buyer-assigned risk profile and contractual process still apply.
Open this answer on its own pageIs DCC mandatory?
Check the written MOD or prime-contractor requirement and its transition date. IASME guidance says DCC is not currently mandatory across all contracts; the MOD’s published 8 May 2026 request for industry partners to reach Level 0 by 31 December 2026 is a separate request, not a universal legal rule. Ask the contracting authority to confirm the numeric Cyber Risk Profile, Risk Assessment Reference and applicable tender clause.
Open this answer on its own pageHow do I know which DCC level I need?
Use the numeric Cyber Risk Profile assigned by the MOD or contracting customer, its Risk Assessment Reference and the current contract version. CSM v4 uses Levels 0 to 3; older Very Low, Low, Moderate and High labels do not convert automatically. If a tender still uses verbal wording or two buyers require different levels, obtain written authority clarification before selecting an assessment scope or package.
Open this answer on its own pageDoes Fig Group offer L2 and L3 assessment?
Fig Group delivers DCC Level 0 and Level 1 through its licensed certification body. For Level 2 or Level 3, use the IASME DCC Certification Body directory to find a body licensed for the required level; Fig Group can refer you to an appropriately authorised provider. Check the assigned level and licence before buying.
Open this answer on its own pageDo I need Cyber Essentials before DCC?
Current Cyber Essentials is a prerequisite for DCC Levels 0 and 1, with Plus required at Levels 2 and 3. Arrange Cyber Essentials certification separately if you do not hold a current, same-scope certificate before formal assessment. Maintaining the underlying annual certification remains your responsibility during DCC validity.
Open this answer on its own pageHow much does DCC cost with Fig Group?
Published Level 0 prices run from £499.99 + VAT for Micro to £799.99 + VAT for Large. Level 1 published ranges run from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large, depending on agreed scope. Years 1 and 2 include annual attestation support within the package; Year 3 reassessment is separately priced. Arrange Cyber Essentials certification and annual renewal separately, and check any work outside the Order Form before purchase.
Open this answer on its own pageWhy is DCC L1 priced as a range and L0 is flat?
Level 0 has a published staff-band price from £499.99 to £799.99 + VAT. Level 1 ranges from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large because scope, evidence gaps and assessor effort vary. The published package includes scoped consultancy and assessment; optional work outside the accepted Order Form may cost extra. Request a written Level 1 quote rather than treating a range endpoint as a fixed checkout price.
Open this answer on its own pageIs the consultant really included in DCC L1 pricing?
The published Level 1 package includes consultant support for the agreed scoping, evidence preparation and assessment programme. The applicant implements required controls and supplies accurate evidence. Confirm deliverables, feedback and remediation rounds, any extension charges and separately requested work in the accepted written Order Form; the package is not unlimited consultancy.
Open this answer on its own pageIs the technology platform extra for DCC L1?
The published Level 1 offer includes scoped platform support for evidence mapping and annual attestations. Confirm the actual access duration, included integrations and functionality, support, post-certification charges and any separate consultancy retainer in a written Order Form. Evidence mapping alone does not prove an unconditional three-year platform entitlement. Year 3 reassessment is separately purchased.
Open this answer on its own pageHow long does DCC L0 take?
As at 29 September 2026, Fig Group estimates two to three weeks end to end for a prepared Level 0 applicant and four to eight weeks where prerequisite certification, governance documents or scope need work. These are indicative supplier estimates, not an IASME deadline. Confirm the numeric level, current Cyber Essentials, three-control evidence, written assessment schedule and buyer deadline before relying on a target date.
Open this answer on its own pageHow long does DCC L1 take?
As at 29 September 2026, Fig Group estimates six to ten weeks end to end for a prepared Level 1 applicant and twelve to twenty weeks from a lower baseline. Scope, 101-control evidence, remediation, assessor availability and current prerequisite certification affect timing. Obtain a written scope and schedule against the tender deadline; neither estimate guarantees certificate issue.
Open this answer on its own pageAre there annual fees during the three-year DCC certificate period?
The published DCC package includes annual attestation support for Years 1 and 2. Year-three reassessment is separate. Underlying Cyber Essentials needs annual renewal, and additional work outside the accepted scope may be chargeable under your Order Form. Existing signed terms continue to apply.
Open this answer on its own pageCan I accelerate the DCC timeline for a specific MOD tender deadline?
Share the written tender deadline and required numeric level with Fig Group at quote stage. Check current Cyber Essentials, assessment scope, evidence readiness and whether an assessor can agree a written schedule. Preparation may be shortened, but assessment findings and remediation still determine certification; no deadline guarantee applies.
Open this answer on its own pageWhat does the Fig Group DCC platform actually do?
Fig Group’s platform can organise scoped DCC evidence and highlight gaps from supported data sources such as connected identity, endpoint and cloud systems. Available checks depend on the agreed integrations, permissions and data quality; a detected issue is reviewed by the applicant and assessor, not automatically certified. Confirm included Level 1 access and functionality in the Order Form.
Open this answer on its own pageCan my existing SAQ evidence be reused for DCC?
Some dated SAQ policies and technical records can be reused if they cover the same organisation, systems and control period. For example, map an access-control policy dated June to the applicable DCC control, note missing MFA enforcement evidence, then arrange independent review of the gap. The contract-specific SAQ still remains due; reuse does not replace the DCC assessment.
Open this answer on its own pageIs Fig Group IASME-accredited for DCC?
Fig Compliance Ltd holds separate IASME licences for DCC Level 0 and Level 1, and Cyber Essentials and Plus. Verify each scheme and authorised level through the relevant registry and IASME DCC directory; a Cyber Essentials badge alone does not prove a DCC licence. Fig Group does not assess DCC Levels 2 or 3.
Open this answer on its own pageWho can issue Defence Cyber Certification at Level 0 and Level 1?
An IASME-licensed DCC Certification Body authorised for the required level can issue a certificate following a successful assessment. Fig Group delivers Levels 0 and 1 through its licensed body; see the IASME DCC directory for level-specific verification and other providers. Cyber Essentials certification and annual renewal are arranged separately. For Levels 2 and 3, use a body authorised for those levels.
Open this answer on its own pageAbout Fig Group
7 answers
Is Fig Group IASME-licensed?
Yes. Fig Compliance Ltd holds separate IASME certification-body licences for Cyber Essentials, Cyber Essentials Plus, DCC Level 0 and DCC Level 1. Verify each scheme, licensed entity and current scope through the relevant IASME directory and registry record on our licence evidence page; one badge is not proof of all four authorisations.
Open this answer on its own pageWhere is Fig Group based?
London. Our registered office is at 167-169 Great Portland Street, 5th Floor, London W1W 5PF. Fig Group is registered in England and Wales as The Fig Group Limited, Company No. 16845978.
Open this answer on its own pageWhat is Fig Group's Companies House number?
The Fig Group Limited, the group parent, is registered at Companies House under number 16845978. Check its public company record for current details. Certification contracts identify the delivering legal entity, Fig Compliance Ltd, in the applicable terms; the group registration alone does not establish a scheme licence.
Open this answer on its own pageWho is Fig Group's Managing Director?
Jay Hopkins is Fig Group’s Managing Director and an IASME assessor. His public professional profile supports role and experience; verify the organisation’s current scheme licences separately through the relevant IASME directory and registry records.
Open this answer on its own pageDoes Fig Group only do Cyber Essentials?
No. Fig Group brings together cybersecurity software, specialist security testing and compliance certification. We help MSPs deliver security services to their clients, and businesses manage their own security and compliance.
Open this answer on its own pageDoes Fig Group resell the platform to MSPs?
Yes. Offer Fig Group’s platform, security testing and certification services under your brand while keeping the client relationship. We agree branding, delivery responsibilities and client communications with you. Certification remains subject to scheme rules: required certification-body details, scheme marks and client declarations are retained. We work with MSPs to certify their clients through Fig Compliance Ltd. Explore the partner offering at /msp.
Open this answer on its own pageDoes Fig Group support DCC (Defence Cyber Certification)?
Yes. Fig Group supports Defence Cyber Certification Levels 0 and 1 through the relevant IASME-licensed Certification Body. Check the IASME DCC directory for the authorised level and the DCC service page for scope, prerequisite certification, pricing and terms.
Open this answer on its own pageNeed help with your assessment?
Speak to the Fig Group team about your organisation’s scope, requirements or next step.