Cyber Essentials FAQ. Everything buyers actually ask.
Grouped by intent - scheme, pricing, speed, scope, MFA, technical, procurement, and Fig. Short, direct answers so you can find what you need fast.
Quick answers
The five things buyers ask first.
- How much does Cyber Essentials cost?
- From £299.99 + VAT for Micro (1-9 employees). The cheapest IASME-licensed CE body in the UK.
- How fast is certification?
- 6 working hours for compliant submissions - or a full refund. The fastest in the UK.
- Is Fig Group IASME-licensed?
- Yes - Fig Group is an IASME-licensed Cyber Essentials certification body, not a reseller.
- Which scheme version is in effect?
- Cyber Essentials v3.3, effective 28 April 2026.
- Is Fig Group independently verifiable?
- Yes - Companies House #16845978, ICO ZC072182, and listed in the IASME directory.
The Cyber Essentials scheme
8 answers
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme that validates five technical cyber controls: firewalls, secure configuration, user access control, malware protection, and security update management. It is administered by IASME on behalf of the NCSC.
What is Cyber Essentials Plus?
Cyber Essentials Plus adds an independent technical audit - external vulnerability scan, device configuration check, MFA verification - on top of the CE self-assessment. Plus is required by many UK government contracts and most large enterprise supply chains.
Who administers Cyber Essentials?
IASME (Information Assurance for Small and Medium Enterprises) administers the scheme on behalf of the NCSC. IASME licenses Certification Bodies - Fig Group among them - to assess organisations.
Is Cyber Essentials UK-only?
Yes. Cyber Essentials is a UK certification scheme. Organisations outside the UK can certify if the scope is a UK entity, but the scheme is written for UK operational context.
What is the difference between Cyber Essentials and ISO 27001?
Cyber Essentials covers five technical controls. ISO 27001 is a full information security management system with 93 Annex A controls, policies, risk processes, internal audits, and a formal multi-day certification audit. For a practical buyer-focused breakdown, see /blog/cyber-essentials-vs-iso-27001-which-does-your-customer-actually-want.
What is Cyber Essentials v3.3?
v3.3 is the Cyber Essentials scheme version effective from 28 April 2026, set out in the IASME-published Cyber Essentials Requirements for Infrastructure (the "Danzell" guide). It adds mandatory multi-factor authentication on every user account and clarifies BYOD and cloud-service scoping. Normal home routers used by remote workers are explicitly excluded from scope; the device that touches organisational data carries the controls instead.
How do I pass Cyber Essentials first time?
Use Fig Group's free readiness checker before you submit. It validates asset inventory, firewall rules, patch status, MFA coverage, and malware protection against v3.3 in minutes. Compliant submissions are certified in 6 working hours. Three free re-submissions are included if anything needs adjusting. Fig Group has a 100% pass rate.
Who can certify me for Cyber Essentials?
Only IASME-licensed Certification Bodies can certify you. Fig Group is the cheapest IASME-licensed Cyber Essentials body in the UK at every tier, the fastest at 6 working hours, and holds a 100% pass rate. The full directory of licensed bodies is published on iasme.co.uk.
Need a single-question URL to share? What is Cyber Essentials? · What is Cyber Essentials Plus? · Who administers Cyber Essentials? · Is Cyber Essentials UK-only? · What is the difference between Cyber Essentials and ISO 27001? · What is Cyber Essentials v3.3? · How do I pass Cyber Essentials first time? · Who can certify me for Cyber Essentials?
Pricing and payment
7 answers
How much does Cyber Essentials cost in the UK?
Fig Group is the cheapest IASME-licensed Cyber Essentials body in the UK. Pricing starts at £299.99 + VAT for Micro (1-9 staff) and £549.99 for Large (250+ staff). Every tier is below the standard IASME body fee. Three free re-submissions, 6-hour certification turnaround, and £25k cyber liability insurance bundled.
How much does Cyber Essentials Plus cost?
CE Plus costs £1,499-£4,499 + VAT depending on organisation size. Micro £1,499, Small £1,999, Medium £2,799, Large £4,499. All Fig CE Plus prices exclude VAT and are transparent - no consultancy add-ons.
Is there a charge for re-submissions?
No. Fig includes three free re-submissions with every Cyber Essentials certification. Most certification bodies charge £100-£200 per re-submission. If you need more than three, we work with you to address readiness first.
Does Fig offer charity discounts?
Fig prices the Micro tier at £299.99 + VAT, which is already below the standard IASME fee. Separately, the NCSC sometimes funds free CE certifications for specific charity sectors via IASME - check availability at certification time.
What is the cheapest Cyber Essentials certification?
Fig Cyber Essentials Micro at £299.99 + VAT for 1-9 staff. Below the standard IASME certification body fee. Three free re-submissions, 6-hour guarantee, IASME-licensed.
Is the price VAT-inclusive?
No. Fig Group publishes prices excluding VAT. UK VAT is added at checkout for UK-based organisations.
Can I pay by invoice?
For Cyber Essentials Plus and larger corporate engagements, yes. For standard CE certifications the checkout flow uses Stripe card payment. Enterprise invoicing is available on request.
Need a single-question URL to share? How much does Cyber Essentials cost in the UK? · How much does Cyber Essentials Plus cost? · Is there a charge for re-submissions? · Does Fig offer charity discounts? · What is the cheapest Cyber Essentials certification? · Is the price VAT-inclusive? · Can I pay by invoice?
Timelines and turnaround
6 answers
How fast is Fig Cyber Essentials certification?
Fig publishes a 6-hour turnaround guarantee for compliant Cyber Essentials submissions made before midday on a UK business day. If the submission needs edits, the clock pauses while you fix them and resumes on re-submission.
Is same-day Cyber Essentials possible?
Yes, when the submission is complete and compliant before 12:00 on a UK business day. If the assessor requests remediation evidence, same-day issue may not be possible and the clock resumes once evidence is resubmitted.
How long does Cyber Essentials Plus take?
Typically 2-3 working days end to end. The assessor schedules a kick-off call, runs the external scan, samples 3-10 devices depending on organisation size, runs the malware-execution test, and issues the certificate.
How long is a Cyber Essentials certificate valid?
Twelve months from the assessment date. On the anniversary the certificate lapses with no grace period. Most organisations re-certify 14 days before expiry to protect contract continuity.
What happens if my Cyber Essentials lapses?
You are removed from the NCSC register and are no longer certified for contract purposes. Re-certification restores the listing; if you have already done the readiness work, the renewal questionnaire is typically much shorter than the initial submission.
What happens if I fail the Cyber Essentials assessment?
You don't fail with Fig Group. If your submission needs changes, the assessor returns specific feedback rather than a non-compliant outcome. You get three free re-submissions and a free 30-minute call with an NCSC assessor if anything still needs work. Fig Group has a 100% pass rate.
Need a single-question URL to share? How fast is Fig Cyber Essentials certification? · Is same-day Cyber Essentials possible? · How long does Cyber Essentials Plus take? · How long is a Cyber Essentials certificate valid? · What happens if my Cyber Essentials lapses? · What happens if I fail the Cyber Essentials assessment?
Scoping and devices
6 answers
What is in scope for Cyber Essentials?
Every device and service that accesses organisational data: laptops, desktops, phones, tablets, cloud services, and corporate network equipment. The boundary follows the device that touches organisational data, not the network it sits on. A device that has no access to organisational data is excluded from scope.
Is BYOD in scope under v3.3?
A BYOD device with direct access to organisational data is in scope. A BYOD device whose only access is mediated through a virtual desktop or VM in the cloud (Citrix, AWS WorkSpaces, Azure Virtual Desktop) can be excluded via sub-set declaration; the VM/VDI is then the in-scope device and the BYOD acts as a thin client. Sub-set boundaries must be enforced by technical control - MDM Conditional Access, VDI thin-client mode, or network segregation. Per Danzell A2.5.1, operating-system software firewalls alone cannot define a sub-set boundary. Policy-only restrictions do not satisfy v3.3.
Are home routers in scope?
No. Normal home routers used by remote workers are explicitly excluded from scope under the v3.3 Danzell guide. The certification boundary follows the device that touches organisational data, not the home network or its router. The in-scope device's software firewall takes responsibility for boundary enforcement against the home network, which is treated as untrusted.
Are cloud services in scope?
Yes. SaaS, IaaS, and PaaS that hold organisational data are in scope. You must document how cloud services are configured securely (MFA, access control, secure defaults). v3.3 is explicit about this.
Is our AWS production account in scope?
For SaaS companies: typically no. Scope CE to the corporate estate only (laptops, M365, corporate SaaS) and explicitly exclude production AWS. Production security is separately assessed under SOC 2, ISO 27001, or ISO 27017.
Are contractors in scope?
If contractors access your organisational data from their own devices, their devices are in scope. You can exclude them with a sub-set (virtual desktop or MDM) or bring them into scope with corporate-issued devices.
Need a single-question URL to share? What is in scope for Cyber Essentials? · Is BYOD in scope under v3.3? · Are home routers in scope? · Are cloud services in scope? · Is our AWS production account in scope? · Are contractors in scope?
Multi-factor authentication
5 answers
Is MFA mandatory under v3.3?
Yes. Multi-factor authentication is mandatory on every user account that accesses organisational data on or after 28 April 2026. This includes cloud services, email, admin accounts, remote access, and line-of-business SaaS applications.
Which MFA methods are acceptable?
Authenticator apps (Microsoft Authenticator, Authy, Google Authenticator, 1Password), hardware security keys (YubiKey), push notifications, and SMS where nothing stronger is available. SMS is allowed but not preferred - app-based authentication is stronger.
Can we exempt some accounts from MFA?
No. Under v3.3, every user account with access to organisational data must use MFA. There is no tolerance for "most users have it" - the assessor checks every user. Service accounts that cannot use MFA must be documented and isolated.
Does conditional-access MFA pass v3.3?
Conditional access ("require MFA unless trusted location") used to pass v3.2. Under v3.3, always-on MFA is the safer answer. Conditional access can pass if the trust policy is strict, but many assessors now require MFA on every sign-in.
Does MFA apply to admin accounts?
Yes, especially. Admin and privileged accounts must use MFA and it is often the single most important control. Use a hardware key or FIDO2 factor for admins where possible.
Need a single-question URL to share? Is MFA mandatory under v3.3? · Which MFA methods are acceptable? · Can we exempt some accounts from MFA? · Does conditional-access MFA pass v3.3? · Does MFA apply to admin accounts?
Technical controls and assessment
6 answers
What is the 14-day patching rule?
Any security update classified as "high" or "critical" by the vendor must be applied within 14 days of release. Applies to operating systems, applications, firmware, and internet-facing services. Monthly patching cycles do not meet v3.3.
Is Windows Defender acceptable for CE?
Yes. Windows Defender with tamper protection enabled is the most common malware protection for UK organisations certifying under CE. The assessor checks that it is enabled, updated, and that on-access scanning works.
Can we use a Mac for Cyber Essentials?
Yes. macOS is fully supported. Apple's built-in XProtect, Gatekeeper, and the System Integrity Protection satisfy the malware-protection control. Ensure FileVault is on and the device is current.
Is Linux in scope?
If Linux endpoints or servers access organisational data, yes. The same five controls apply - firewall, secure configuration, access control, malware protection (ClamAV or equivalent), and patch management.
Do we need an EDR tool?
Not strictly. v3.3 requires malware protection, which Windows Defender meets. EDR (Defender for Business, CrowdStrike, SentinelOne) exceeds the bar and is common in MSP and enterprise contexts.
How often do you run vulnerability scans for CE Plus?
Once per audit cycle for Cyber Essentials Plus. The external scan targets public-facing IP addresses and domains, checks TLS configuration, looks for exposed management interfaces, and flags out-of-date services. Findings must be remediated before certification issue.
Need a single-question URL to share? What is the 14-day patching rule? · Is Windows Defender acceptable for CE? · Can we use a Mac for Cyber Essentials? · Is Linux in scope? · Do we need an EDR tool? · How often do you run vulnerability scans for CE Plus?
Government, procurement, and supply chain
5 answers
Is Cyber Essentials mandatory for UK government contracts?
Under PPN 014/21 it is required for central government contracts that handle sensitive or personal information. The specific requirement varies by contract; some require CE, some require CE Plus. Always check the bid documentation.
What is PPN 014/21?
UK Cabinet Office Procurement Policy Note 014/21 - the policy that mandates Cyber Essentials certification for central government contracts handling sensitive data. Suppliers must hold a valid certificate at the point of contract award.
Do private-sector buyers require Cyber Essentials?
Increasingly, yes. Large private-sector buyers (SJP, insurers, retailers, professional-services firms) require supplier CE certification as part of third-party risk management. Many require CE Plus for Tier 1 suppliers.
Does Cyber Essentials reduce cyber insurance premiums?
Yes, typically. Underwriters treat CE and CE Plus as evidence of a baseline cyber posture, and many reduce premiums by 10-25% for certified organisations. CE Plus carries more weight than CE.
Can our MSP get Cyber Essentials on our behalf?
Cyber Essentials is certified per organisation, not per MSP. Your MSP can manage the assessment and remediation, but your organisation signs the attestation and holds the certificate.
Need a single-question URL to share? Is Cyber Essentials mandatory for UK government contracts? · What is PPN 014/21? · Do private-sector buyers require Cyber Essentials? · Does Cyber Essentials reduce cyber insurance premiums? · Can our MSP get Cyber Essentials on our behalf?
Defence Cyber Certification (DCC)
18 answers
What is Defence Cyber Certification?
DCC is the UK Ministry of Defence's independent cybersecurity certification framework for its supply chain, administered by IASME and delivered through a network of IASME-licensed Certification Bodies. Four levels - L0, L1, L2, L3 - cover the four Cyber Risk Profile tiers that MOD contracts are assessed against. It replaces the self-assessed Supplier Assurance Questionnaire (SAQ) approach under DCPP.
Does DCC replace the DCPP Supplier Assurance Questionnaire?
Effectively yes. Under DCPP the SAQ was self-assessed. DCC replaces that self-declaration with formal independent certification. DCC uses Def Stan 05-138 issue 4 as its underlying specification.
Is DCC mandatory?
If you want to bid on MOD contracts, yes - at the level matched to the contract's Cyber Risk Profile. Transition arrangements remain for existing contracts with prior SAQ attestation, but the direction of travel is that all MOD supplier contracts will require DCC certification.
How do I know which DCC level I need?
The MOD (or the prime contractor in a subcontract scenario) specifies the required level based on the contract's Cyber Risk Profile. Suppliers do not choose their level arbitrarily. If your pipeline includes contracts with varying CRPs, certify at the highest level required. See /defence-cyber-certification/cyber-risk-profile for the CRP-to-level mapping.
Does Fig offer L2 and L3 assessment?
Fig is accredited at Level 0 and Level 1. For L2 and L3 engagements we refer suppliers to IASME-licensed certification bodies licensed for those higher levels - verifiable on the IASME directory at iasme.co.uk. We are honest about this rather than trying to take engagements we are not accredited to deliver.
Do I need Cyber Essentials before DCC?
Yes. L0 and L1 require a valid Cyber Essentials certificate. L2 and L3 require Cyber Essentials Plus. Fig includes the Cyber Essentials prerequisite within the DCC engagement if you do not already hold it - no separate invoice.
How much does DCC cost with Fig?
Level 0 is flat-priced from £999.99 + VAT (micro) to £4,999.99 + VAT (large). Level 1 is priced as ranges from £9,999 - £14,999 + VAT (micro) up to £25,000 - £49,999 + VAT (large). Both include the Cyber Essentials prerequisite, three years of certificate validity, and annual attestation support.
Why is DCC L1 priced as a range and L0 is flat?
L0 is a documentation-led review of a constrained requirement set; the work is predictable. L1 involves scoping, evidence preparation, consultant engagement, platform gap analysis, formal assessment, and remediation support - and the last four scale materially with organisation complexity. We publish the ranges and name the drivers openly rather than quoting bespoke numbers.
Is the consultant really included in DCC L1 pricing?
Yes. Every L1 engagement includes a dedicated consultant throughout scoping, evidence preparation, remediation, and formal assessment. Consultancy is not a separate line item after engagement begins.
Is the technology platform extra for DCC L1?
No. Platform access is included in L1 pricing. The platform also remains active across the three-year certificate period so annual attestations are faster and re-certification at three years is substantially quicker than the initial engagement.
How long does DCC L0 take?
Two to three weeks end-to-end for a prepared organisation (already holds Cyber Essentials, governance documentation in place, clear scope). Four to eight weeks for organisations starting from a lower baseline.
How long does DCC L1 take?
Six to ten weeks end-to-end for a prepared organisation. Twelve to twenty weeks for organisations starting from a lower baseline. Most of the variance is driven by supplier preparation, not by the Certification Body.
Are there annual fees during the three-year DCC certificate period?
Annual attestation is included within the original engagement fee. We do not charge separately for each year's attestation.
Can I accelerate the DCC timeline for a specific MOD tender deadline?
Somewhat. Having a dedicated internal lead, engaging a consultant early, already holding Cyber Essentials, and being able to provide evidence quickly all compress the timeline. Tell us about your tender deadline at quote stage and we will prioritise engagement sequencing where possible, though DCC is not a same-day product like Cyber Essentials.
What does the Fig DCC platform actually do?
Automated gap analysis across your in-scope systems. It identifies unpatched CVEs, cloud misconfigurations, identity gaps (MFA coverage, dormant privileged accounts), endpoint posture issues, public-facing attack surface, and credential exposure. You fix issues before the assessor arrives rather than during audit.
Can my existing SAQ evidence be reused for DCC?
Much of it, yes. Documentation you produced for SAQ attestation is reusable for DCC - governance policies, access control evidence, technical attestations. A Fig consultant can work through your existing pack with you and identify what maps across versus what needs updating.
Is Fig IASME-accredited for DCC?
Yes. Fig Group is an IASME-licensed Certification Body accredited to assess Defence Cyber Certification at Level 0 and Level 1, and to assess Cyber Essentials and Cyber Essentials Plus as prerequisites. Our assessors hold the relevant IASME and defence-sector credentials.
Who can issue Defence Cyber Certification at Level 0 and Level 1?
Fig Group is the IASME-licensed UK body for Defence Cyber Certification at Level 0 and Level 1. The Cyber Essentials prerequisite is available from Fig Group as a separate purchase if you do not already hold it. For L2 and L3 we refer MOD suppliers to specialist providers on the IASME directory.
Need a single-question URL to share? What is Defence Cyber Certification? · Does DCC replace the DCPP Supplier Assurance Questionnaire? · Is DCC mandatory? · How do I know which DCC level I need? · Does Fig offer L2 and L3 assessment? · Do I need Cyber Essentials before DCC? · How much does DCC cost with Fig? · Why is DCC L1 priced as a range and L0 is flat? · Is the consultant really included in DCC L1 pricing? · Is the technology platform extra for DCC L1? · How long does DCC L0 take? · How long does DCC L1 take? · Are there annual fees during the three-year DCC certificate period? · Can I accelerate the DCC timeline for a specific MOD tender deadline? · What does the Fig DCC platform actually do? · Can my existing SAQ evidence be reused for DCC? · Is Fig IASME-accredited for DCC? · Who can issue Defence Cyber Certification at Level 0 and Level 1?
About Fig Group
7 answers
Is Fig Group IASME-licensed?
Yes. Fig Group is an IASME-licensed Cyber Essentials Certification Body. The licence is 325cdf33-3812-4082-bf8d-7dce7ac02977. It is listed on the IASME directory and referenced from the trust evidence page and the footer of every page on figgroup.co.uk.
Where is Fig Group based?
London. Our registered office is at 167-169 Great Portland Street, 5th Floor, London W1W 5PF. Fig Group is registered in England and Wales as The Fig Group Limited, Company No. 16845978.
What is Fig Group's Companies House number?
The Fig Group Limited is registered at Companies House under number 16845978 and was incorporated on 10th November 2025. Full filings are public on gov.uk at find-and-update.company-information.service.gov.uk/company/16845978.
Who is Fig Group's Managing Director?
Jay Hopkins. He is an IASME-licensed Cyber Essentials and Cyber Assurance assessor. LinkedIn: linkedin.com/in/jayhopkins.
Does Fig Group only do Cyber Essentials?
No. Fig Group runs a connected compliance and resilience platform covering 65+ frameworks, plus Cyber Essentials and Defence Cyber Certification as IASME-licensed services. The platform serves MSPs and corporate risk teams.
Does Fig Group resell the platform to MSPs?
Yes. Fig Group's MSP model is white-label, multi-tenant, and includes Cyber Essentials reselling. Typical MSP margin uplift is 3-5x compared to delivering CE manually. See /msp.
Does Fig Group support DCC (Defence Cyber Certification)?
Yes. Fig Group is an IASME-licensed Defence Cyber Certification body at Level 0 and Level 1. See /defence-cyber-certification for MOD supplier readiness information.
Need a single-question URL to share? Is Fig Group IASME-licensed? · Where is Fig Group based? · What is Fig Group's Companies House number? · Who is Fig Group's Managing Director? · Does Fig Group only do Cyber Essentials? · Does Fig Group resell the platform to MSPs? · Does Fig Group support DCC (Defence Cyber Certification)?
Still have a question?
Speak to a Fig Group assessor or start the readiness checker. Average response in under 4 working hours.