Short answer
Use Fig Group’s self-reported readiness checker, then verify the actual controls across the agreed scope; the checker does not inspect devices or award certification. The six-working-hour Basic guarantee requires a complete, compliant submission before midday on a UK business day under the terms. Three free re-submissions support corrections. The recorded 100% completed-assessment pass rate is historical; certification still depends on meeting every applicable control.
Why this matters
This question affects how buyers compare Cyber Essentials with broader assurance schemes. Cyber Essentials is a baseline technical certification, so the useful answer is not only what the scheme is called, but what it proves, who administers it, and when a buyer should ask for Cyber Essentials Plus or a wider framework such as ISO 27001.
For procurement teams, the practical test is whether the certificate covers the organisation and scope named in the contract. For applicants, the practical test is whether the five technical controls are implemented across the devices, users, networks, and cloud services that access organisational data.
What to check next
- Confirm the certificate holder and scope match the buyer requirement.
- Check whether the contract asks for Cyber Essentials or Cyber Essentials Plus.
- Use the IASME Certificate search tool to verify a certificate before relying on it.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.