Skip to content
Financial Services

Cyber Essentials for Financial Services: FCA, PRA and Client Expectations

Financial services firms face unique scrutiny on cyber controls. Where does Cyber Essentials fit alongside FCA SYSC, PRA SS1/21, and client due-diligence expectations?

grey concrete building

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

8 min read

Share

Section 01

Cyber Essentials for Financial Services: FCA, PRA and Client Expectations

UK financial-services firms may face regulator, principal-firm, network, client and insurer expectations for cyber controls. Which ones apply depends on the firm's permissions, activities and contracts. Cyber Essentials can provide baseline evidence where requested, but it does not satisfy every relevant duty.

This guide is for IFAs, wealth managers, principal firm networks, fund-management houses, and the long tail of FCA-authorised firms that are being asked for a Cyber Essentials certificate by a client, an insurer, or a regulator-adjacent due-diligence questionnaire.

Section 02

Does Cyber Essentials satisfy the FCA?

Cyber Essentials may provide useful baseline evidence, but no general FCA rule makes it compulsory for every firm. The FCA does not endorse a single cybersecurity standard. Its Senior Management Arrangements, Systems and Controls sourcebook (SYSC) sets proportionate expectations. For firms in scope of the operational-resilience rules, those rules began on 31 March 2022 and had a 31 March 2025 transition deadline.

For an FCA-authorised firm, the right controls and evidence depend on its activities, systems, customer data and any applicable operational-resilience rules. Cyber Essentials can help demonstrate assessed technical measures such as security updates, malware protection, access control, secure configuration and firewalls. It does not establish that every relevant control remains effective or that every regulatory duty is met.

Cyber Essentials does not cover the full operational-resilience requirements for firms to which those rules apply, including identifying important business services, setting impact tolerances and testing severe-but-plausible disruption. Cyber Essentials Plus and additional records may help, but a firm must assess the full applicable rules and its own evidence.

Section 03

Does it satisfy the PRA?

For PRA-regulated firms, Supervisory Statement SS1/21 on operational resilience and SS2/21 on outsourcing and third-party risk management cover materially more than Cyber Essentials. A PRA firm may ask some suppliers for Cyber Essentials or Plus under its own risk and contract approach. Check the actual firm and contract rather than assuming a universal Plus requirement.

If you are a PRA firm or its supplier, check the firm's own controls, supplier-risk process, questionnaire and contract. Neither role implies a universal Plus requirement.

Section 04

The principal firm and network case

A large share of UK retail financial advice is delivered through principal firm networks - St James's Place, Quilter, True Potential, and others. Network appointed representatives may receive their own cyber-security instructions from a principal firm. This is not an FCA requirement; it is a network-level supervision tool. For St. James's Place Partner practices, published material describes Cyber Essentials Plus or the approved Device-as-a-Service route; other networks must be checked separately.

For an appointed representative or Partner Practice, confirm the principal's current written instructions for the legal entity, device scope, accepted route, deadline and evidence upload. SJP's published Plus-or-approved Device-as-a-Service route should not be generalised to Quilter, True Potential or other networks.

Check the selected supplier's tier price and approved package; the £315 figure is not a verified market tariff. Preparation and the assessment clock are separate. The work and cost depend on the actual devices, cloud services and gaps.

Section 05

Wealth managers and the institutional client case

Wealth managers and discretionary fund managers may receive institutional-client due-diligence requests. A pension trustee, family office or corporate client may ask for Basic, Plus, equivalent evidence or another standard; check its actual questionnaire and contract. Do not infer a universal insurer or Pensions Regulator mandate for Plus.

Where a client specifies Plus, the difference is independent technical testing of the same controls. Ask the client why that level is needed and confirm the entity and scope it expects.

Section 06

Common scoping pitfalls in FS

Three scoping mistakes recur in financial services certifications.

The "back-office only" trap. Some firms try to scope out their client-facing front-office systems on the grounds that they are run by a third party. This is not how the scheme works. If you log into the system from a corporate device, that device is in scope. If your firm's data is in that system, the access controls protecting it are in scope.

Bring-your-own-device gaps. Adviser-owned mobile phones used for business email are a recurring blind spot. The 2026 scheme is unambiguous: a personally-owned device used to access organisational data is in-scope, and must meet the configuration baseline.

Cloud app sprawl. Inventory any CRM, planning tool, back-office system, client portal and research subscription that stores or processes organisational data. Check each service's scope and MFA for all human cloud-service users, including administrators. No firm-wide tool count or most-common failure rate is assumed.

Section 07

Fig Group's financial-services track

Fig Group can discuss certification scope with financial-services firms. Scope may include devices, Microsoft 365, CRM, planning tools and other cloud services according to the firm's actual estate. Ask what preparation support is available for those systems and the applicable principal or network requirement; no pre-populated answer establishes compliance.

The published Basic guarantee applies after receipt of a complete, compliant submission before midday UK time on a UK Business Day, subject to certification terms. Kick-off, remediation and Plus testing have separate timelines. The cost is the same as for any other small business - published on the pricing page - with no FS premium.

Section 08

Next steps

If your network, insurer or client has asked for Cyber Essentials, start with its written requirement and the free readiness check, then confirm the assessment scope and current offer. Contact Fig Group to discuss the firm-specific route.

Talk to an FS specialist assessor → | Start the readiness check → | View pricing →

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group