Cyber Essentials Plus for St. James's Place (SJP) Partners
A practical guide for St. James's Place Partner Practices covering the Cyber Essentials Plus route, common audit failures, renewal timing, serviced offices, BYOD, and certification preparation.
Section 01
Cyber Essentials Plus for St. James's Place (SJP) Partners
St. James's Place uses Cyber Essentials Plus as a security baseline across its Partner Practice network. SJP's published reporting has described the control as mandatory Cyber Essentials Plus accreditation for Partner Practices or use of an SJP Device as a Service solution. If you are unsure which route applies to your practice, confirm that with your SJP contact before buying certification.
Cyber Essentials alone is the prerequisite, not the end point, when the Plus route applies. You must pass the verified self-assessment before completing the independent Cyber Essentials Plus technical audit.
This guide explains the Plus route, the problems that commonly delay financial-advice practices, and the practical considerations for serviced offices, travelling advisers, shared networks, and personally owned devices.
Section 02
The short answer for SJP Partner Practices
Confirm your required route
Check whether your practice is expected to hold Cyber Essentials Plus or use SJP's managed Device as a Service route. Do not assume that base-level Cyber Essentials alone satisfies the Partner Practice requirement.
Define the practice scope
Record the people, devices, networks, cloud services, and office locations used to access organisational data and services. Include home and mobile working where it falls within the Cyber Essentials scope.
Pass Cyber Essentials first
Cyber Essentials Plus verifies the same five technical control themes through an independent audit, but a current Cyber Essentials certificate is required before the Plus assessment.
Plan for annual renewal
Cyber Essentials certificates last 12 months. Start reviewing the scope and controls well before expiry so device changes, new cloud services, and leavers do not create a last-minute problem.
Section 03
What SJP has published
During the original rollout, the SJP Partnership comprised more than 2,800 individual businesses. IASME's SJP case study reports that SJP associated the programme and its underlying controls with an approximately 80% reduction in cyber security incidents.
The network size has since changed. SJP reports more than 2,500 local Partner Practices as at 31 December 2025, so the original 2,800 figure should be understood as rollout context rather than a current practice count.
SJP's public reporting describes Cyber Essentials Plus accreditation or its Device as a Service solution as a control used to protect the Partnership. Partner Practices should use current instructions from SJP as the authority for their individual compliance route, deadlines, and reporting process.
Section 04
Cyber Essentials and Cyber Essentials Plus
Cyber Essentials is a verified self-assessment against five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection.
Cyber Essentials Plus uses the same requirements and adds an independent technical audit of a representative sample of the in-scope systems. The assessor tests whether the controls described in the self-assessment are working in practice.
The difference matters for planning. A practice can have a well-written self-assessment and still encounter Plus audit issues if its sampled devices are out of date, user privileges are excessive, malware protection is not active, or required multi-factor authentication is not enforced.
Section 05
The technology a Partner Practice needs to scope
An SJP Partner Practice may use a combination of:
- Microsoft 365 or Google Workspace
- SJP-provided systems and identity services
- Financial-planning and back-office platforms
- Customer relationship management software
- Portfolio review and illustration tools
- Document-signing services
- Client portals and file-sharing platforms
- Practice-owned laptops and phones
- Personally owned devices used for organisational data or services
- Office, home, and mobile internet connections
Do not copy a generic asset list into the assessment. Build the scope around the technology the practice actually owns, controls, and uses. Record who administers each service and whether authentication is handled directly by the service or through single sign-on.
Section 06
Common audit problems for SJP Partner Practices
MFA gaps outside the main email tenant
Practices often protect Microsoft 365 or Google Workspace but overlook the CRM, financial-planning platform, file-sharing service, client portal, or document-signing tool. Review every in-scope cloud service and every account type, including administrators.
An informal device estate
Laptops bought and configured individually are harder to evidence and keep consistent. Mobile device management is not itself a Cyber Essentials requirement, but tools such as Intune or Jamf can make supported software, firewall settings, malware protection, and update status easier to manage.
Personally owned devices
A personal phone or laptop can enter scope when it is used for organisational data or services. Decide whether to manage it to the required standard or restrict access to practice-managed devices. Document the decision and enforce it technically.
Unsupported or overdue software
The audit sample can expose an unsupported operating system, browser, PDF reader, or other application. Maintain an inventory and check update status before the assessment rather than relying on each user to notice updates.
Shared and excessive access
Each user should have an individual account, and administrative privileges should be limited to the people and tasks that require them. Reconcile leavers and dormant accounts across the whole cloud stack, not only email.
Scope that does not match reality
Problems arise when the questionnaire describes a tidy central environment but advisers also use unmanaged devices, secondary cloud platforms, or another office location. Resolve the mismatch before submitting.
Section 07
Serviced offices, shared networks, and travelling advisers
The issues often described as "London-specific" also affect Partner Practices throughout the UK.
Serviced offices and shared Wi-Fi
Treat the building network as a connection you do not administer. Confirm how the practice's devices are protected and which firewalls are within your control. A software firewall on each in-scope laptop is a practical safeguard, but the final assessment scope should be agreed with the certification body.
Shared printers and scanners
Shared printing is primarily a wider information-security and confidentiality issue rather than a standalone Cyber Essentials control. Avoid sending client material to an uncontrolled print queue, retrieve sensitive documents promptly, and use practice-controlled scanning and storage workflows.
Meetings away from the office
The scope does not disappear when an adviser works from a hotel, client site, home office, or shared workspace. Keep in-scope devices supported, patched, protected, and configured consistently wherever they connect.
BYOD
Choose a clear model: manage personally owned devices that are in scope, or block organisational access from them. Conditional-access policies can support the second approach. Whatever model you choose, make sure the documented answer matches the access users actually have.
Section 08
A practical remediation sequence
1. Confirm the SJP route and deadline. Establish whether CE Plus certification or the SJP-managed device route applies.
2. Inventory the real environment. List in-scope users, devices, networks, software, cloud services, and locations.
3. Sweep cloud authentication. Check MFA, administrator accounts, shared accounts, dormant accounts, and leavers across every in-scope service.
4. Standardise devices. Remove unsupported software, apply updates, verify firewalls and malware protection, and restrict unnecessary administrative privileges.
5. Resolve BYOD. Manage in-scope personal devices or prevent them from accessing organisational services.
6. Complete Cyber Essentials. Submit the verified self-assessment and resolve any assessor feedback.
7. Schedule the Plus audit. Allow time to correct a failed sample or evidence gap before the SJP deadline.
8. Record the renewal date. Review the environment before the 12-month expiry, especially after staff, device, service, or office changes.
Section 09
Cost and timing
Fig's published Cyber Essentials Plus prices start at £1,499 + VAT for a micro organisation with 1-9 employees and £1,999 + VAT for a small organisation with 10-49 employees. The underlying Cyber Essentials stage is included in Fig's Plus packages.
The audit timetable depends on scope, assessor availability, and whether remediation is required. A well-managed small practice may move quickly, but an unmanaged device estate, incomplete MFA, or unclear BYOD position can add time. Work backwards from the SJP deadline rather than treating the fastest possible turnaround as the plan.
Section 10
Renewal checklist
Before renewal, check:
- new and retired laptops and phones
- staff, contractor, and administrator accounts
- new CRM, planning, signing, portal, and file-sharing services
- supported operating systems and applications
- update status across the proposed audit sample
- MFA coverage and exceptions
- changes to office, home-working, or shared-network arrangements
- whether the SJP route or reporting instructions have changed
Section 11
Bottom line
For Partner Practices using the certification route, the reliable path is to confirm SJP's current requirement, scope the real working environment, pass Cyber Essentials, and prepare the sampled systems for the Plus audit. The biggest avoidable delays usually come from secondary cloud services, inconsistent devices, BYOD, and scope answers that do not reflect day-to-day working.
Check your readiness | View Cyber Essentials Plus | Financial-services guidance | Cyber Essentials in London | Talk to an assessor
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials certified with Fig. Same-day certification available when you purchase before 12:00 midday. IASME-licensed with transparent pricing from £299.99 + VAT.
Related solutions