Skip to contentAbout Fig Group

Cyber Essentials for UK financial services firms Certified by Fig.

Fig Group certifies UK financial services firms - financial advisers, wealth managers, fintechs, payments firms, insurers, and other FCA or PRA-regulated organisations. IASME-licensed, from £299.99 + VAT, typically within 6 working hours. Cyber Essentials is a practical technical baseline; it supports, but does not replace, the broader governance and resilience obligations that apply to regulated firms.

Sector-specific

Tailored to financial services firms

The standard scheme guidance does not address the operational reality of this sector. These are the scope, regulatory, and supplier-cascade points Fig assessors check first.

  • 01FCA operational resilience (PS21/3) expectations.
  • 02DORA (Digital Operational Resilience Act) alignment for EU-facing firms.
  • 03SJP Partner Practice Cyber Essentials Plus or managed-device routes.
  • 04Financial-adviser and wealth-management device, cloud-service, and client-data scope.
  • 05Payments data handling alongside PCI DSS scoping.
  • 06Client money / client asset data protection.
  • 07Outsourced-provider oversight - you will require CE of your vendors too.

Pricing at a glance

Below the standard IASME fee at every tier

No re-submission charges. Three free re-submissions included. Published pricing - no gated forms or consultancy add-ons.

Turnaround

6 hours

For compliant submissions before midday.

Cyber Essentials

£299.99 - £549.99

+ VAT, by organisation size.

Cyber Essentials Plus

£1,499 - £4,499

+ VAT, third-party verified.

Common questions

Frequently asked questions

Is Cyber Essentials required by the FCA?

The FCA does not impose Cyber Essentials as a universal certification requirement. It expects firms to manage cyber and operational-resilience risk, and has identified Cyber Essentials as a useful baseline for smaller firms. Certification supports that work but does not replace the wider FCA rules and guidance that apply to the firm.

Does SJP require Cyber Essentials for Partner Practices?

SJP has publicly described mandatory Cyber Essentials Plus accreditation for Partner Practices or use of its Device as a Service solution. Partner Practices should confirm their current route and reporting instructions with SJP. See /blog/cyber-essentials-for-sjp-partners for practical certification guidance.

How should a wealth manager or financial adviser scope Cyber Essentials?

Start with the devices, networks, cloud services, and users that access organisational data or services. Include the CRM, back-office and financial-planning tools, document signing, client portals, remote working, administrator accounts, and any personally owned devices that fall within scope.

Does Cyber Essentials satisfy DORA?

DORA is a broader regime than CE. CE satisfies parts of DORA's ICT risk management and supply chain expectations but is not a substitute for the full regulation. Most UK firms serving EU counterparties treat CE as foundational and layer DORA-specific controls on top.

What CE scope should a fintech SaaS use?

Corporate estate only (laptops, M365/Google Workspace, corporate SSO). Home routers used by remote workers are out of scope under v3.3. Production fintech infrastructure is separately assessed under ISO 27001, SOC 2 Type II, or the equivalent. Split scopes deliberately.

What tier do most fintechs use?

Depends on UK headcount. A typical 40-person fintech falls into CE Small (10-49) at £399.99 + VAT, or CE Plus Small at £1,999 + VAT for insurer / enterprise-client use.

Deep-dive articles

Long-form guidance for financial services firms

Technical guidance written by an IASME-licensed assessor - scope edge cases, supplier cascade, and regulatory overlap that the scheme guidance does not cover.

Next step

Ready to certify?

From £299.99 + VAT. IASME-licensed. Typically within 6 working hours. No consultancy add-ons.