Can we white-label all of Fig Group’s services?
Offer Fig Group’s platform, security testing and certification services under your brand while keeping the client relationship. We agree branding, delivery responsibilities and client communications with you. Certification remains subject to scheme rules: required certification-body details, scheme marks and client declarations are retained.
Can Fig Group work with us to certify our clients?
We work with MSPs to certify their clients. Your team can complete the Cyber Essentials self-assessment on the client’s behalf, provided the organisation reviews and authorises the submission and its board-level representative or equivalent provides the required sign-off in the Cyber Essentials portal. Fig Compliance Ltd carries out the certification assessment; the client organisation holds the certificate.
Do we keep the customer relationship?
Yes. You remain the client’s service partner. We agree how Fig Group supports you, how reports are branded and when assessors or testers need to engage with the client. Required scheme declarations and testing permissions still apply.
Does Fig Group help us become an MSSP without buying fragmented tooling?
Yes. Fig Group brings the platform, specialist security testing and certification services together so you can build a managed security service provider (MSSP) offering through one partner. It connects to your existing environment; it is not a claim to replace every RMM, PSA, endpoint protection or specialist detection tool.
What is monitored, and how often does it update?
Depending on connected systems and agreed scope, monitoring can cover asset inventory, vulnerabilities, configuration and control evidence. Data refresh depends on the integration and check schedule. We confirm supported sources, monitoring intervals and coverage during scoping; not every check is real-time.
Who fixes the issues that monitoring or testing finds?
The agreed owner, usually your team or the client’s technical team, approves and implements changes. Fig Group supports prioritisation, remediation workflows and evidence tracking. Any additional hands-on remediation is separately agreed; a finding does not automatically authorise a change.
Which frameworks and certifications are supported?
The platform supports compliance workflows across frameworks including ISO 27001, SOC 2, Cyber Essentials and DCC. Framework support does not mean Fig Group issues every associated certification. Fig Compliance Ltd delivers Cyber Essentials, Cyber Essentials Plus and DCC Level 0 and Level 1 certification services under the relevant licences.
Are security testing and certification included in the platform price?
They are distinct services. We can agree a combined partner package or scope them separately. Your quote identifies the platform subscription, any testing, certification assessments and delivery responsibilities.
Is a staffed 24/7 SOC, incident response retainer or insurance included?
No. The current offering described here is the platform, security testing and certification services. A staffed 24/7 security operations centre, incident response retainers and Fig Group’s own insurance capabilities are planned services, not included in this offering. Monitoring does not guarantee security or certification.
Can we keep our existing tools?
Yes. Fig Group connects with supported RMM, PSA, cloud, identity and security tools. We confirm the integrations relevant to your clients before onboarding. You can run Fig Group alongside your existing tools during evaluation.
What are the platform contract and support options?
MSP platform packages have an annual contract with monthly or annual payments, no multi-year lock-in, no onboarding fees and no integration surcharges. Give at least 60 days’ written notice before the end of the current annual term to cancel renewal. Cross-customer integrations are included as standard, subject to the required customer permissions. The Master Services Agreement applies alongside your Order Form and MSP terms. Support includes a named onboarding lead, technical support and quarterly business reviews. Confirm scope and the applicable SLAs in your agreement.
Where is client data hosted, and can it be exported?
We confirm the hosting model, data location, access permissions and responsibilities for your deployment before you sign. Clients retain ownership of their data and can export it in standard formats. Your proposal identifies the arrangements that apply to your service.