Skip to contentAbout Fig Group

Cyber Essentials for UK solicitors and law firms Certified by Fig.

Fig Group certifies UK law firms - from sole practitioners to 200-lawyer regional practices - for Cyber Essentials and Cyber Essentials Plus. IASME-licensed, from £299.99 + VAT, typically within 6 working hours for compliant submissions. Tailored to the hybrid working, practice-management, and SRA context that the standard scheme guidance does not address.

Sector-specific

Tailored to solicitors and law firms

The standard scheme guidance does not address the operational reality of this sector. These are the scope, regulatory, and supplier-cascade points Fig assessors check first.

  • 01SRA Code of Conduct expectations around client confidentiality and IT systems.
  • 02LexisNexis, Clio, Leap, Actionstep, DPS and other practice-management platforms.
  • 03Hybrid and remote working, including home-router scope under v3.3.
  • 04Counsel chambers and counsel-facing practice management.
  • 05AML supervision data handling.
  • 06Legal-aid and SFA-framework supplier requirements.

Pricing at a glance

Below the standard IASME fee at every tier

No re-submission charges. Three free re-submissions included. Published pricing - no gated forms or consultancy add-ons.

Turnaround

6 hours

For compliant submissions before midday.

Cyber Essentials

£299.99 – £549.99

+ VAT, by organisation size.

Cyber Essentials Plus

£1,499 – £4,499

+ VAT, third-party verified.

Common questions

Frequently asked questions

Is Cyber Essentials required for solicitors?

Not by the SRA directly, but increasingly by insurers, clients, and legal frameworks. Many UK firms now hold CE or CE Plus as a supplier / DDQ requirement. Under PPN 014/21, firms bidding on public-sector legal work may need CE for sensitive-data contracts.

What scope should a 25-person law firm use?

Corporate estate only - laptops, mobile, M365 or Google Workspace, practice management accessed via browser / corporate SSO, home routers via corporate VPN. Exclude personal devices with Conditional Access. Fig can help scope this in under 30 minutes.

Which tier do we buy?

Pick by UK headcount including part-time and contractors. For a 25-person firm: Cyber Essentials Small at £399.99 + VAT, or CE Plus Small at £1,999 + VAT if an insurer or client requires third-party audit.

How fast can we certify?

For compliant submissions before 12:00 midday on a UK business day, Fig issues the CE certificate within 6 working hours. CE Plus is typically 2–3 working days. Enough time for tender deadlines.

Do we need CE Plus or is CE enough?

Many UK solicitor clients accept CE for supplier onboarding. Insurers and public-sector frameworks increasingly want CE Plus. If you handle Crown Commercial Service work or SJP Partner Practice work, budget for Plus.

Deep-dive articles

Long-form guidance for solicitors and law firms

Technical guidance written by an IASME-licensed assessor - scope edge cases, supplier cascade, and regulatory overlap that the scheme guidance does not cover.

Next step

Ready to certify?

From £299.99 + VAT. IASME-licensed. Typically within 6 working hours. No consultancy add-ons.