Micro
1-9 employees
One-off · no recurring fee
- IASME-licensed certificate
- 6-hour SLA on compliant submissions
- 3 free re-submissions
- £25k cyber liability insurance
The fastest Cyber Essentials certification in the UK - guaranteed within 6 hours for compliant submissions, three free feedback rounds if you need them, and a 100% pass rate for buyers who use our free readiness checker. IASME-licensed. From £299.99 + VAT.
Quick answers
Choose your organisation size and certification level
Self-assessed · 6-hour SLA
Micro
1-9 employees
One-off · no recurring fee
Small
10-49 employees
One-off · no recurring fee
Medium
50-249 employees
One-off · no recurring fee
Large
250+ employees
One-off · no recurring fee
Third-party verified · 1-3 days
Micro
1-9 employees
One-off · no recurring fee
Small
10-49 employees
One-off · no recurring fee
Medium
50-249 employees
One-off · no recurring fee
Large
250+ employees
One-off · no recurring fee
No hidden assessment fees, surprise consultancy charges, or mandatory add-ons.
Named human assessor support throughout every certification.
Free pre-assessment readiness checker included with every package.
6 hours or your money back. Cyber Essentials returned in 6 working hours of compliant submission, or a full refund. The standard IASME certification fee starts at £320 + VAT; Fig Group’s Cyber Essentials Micro starts at £299.99 + VAT - below the standard rate.
Terms, evidence and claim qualification: /trust/claims
Need custom enterprise pricing or a multi-organisation package?
Talk to the teamOverview
Fig Group is an IASME-licensed Cyber Essentials certification body assessing organisations of every size for both Cyber Essentials and Cyber Essentials Plus under the NCSC-backed scheme.
Based in
London, UK
Turnaround
6 hours, guaranteed
Cyber Essentials
From £299.99 + VAT
Cyber Essentials Plus
From £1,499 + VAT
From our Google reviews
“The process was extremely efficient: short phone call, submission, pass. Highly recommended.”
“We recently completed our Cyber Essentials certification with Fig Group and had a great experience from start to finish....”
“Excellent Service, Professional handling and support, the best for fast track”
“Purchased a cyber essentials self assessment. Turned it around in under 2 hours. Great team.”
“Great service and fast turnaround. Working with the Fig Group to achieve our Cyber Essentials accreditation was a really positive experience. A process I have previously found long-winded and difficult was made straightforward and simple from start to finish. Communication was clear, the turnaround time was excellent, and the customer service from Jay was outstanding throughout. I would highly recommend them to anyone looking to get Cyber Essentials accreditation without the usual hassle.”
“Jay at the Fig group was very helpful in helping my small business though our certification process. He got straight in contact even though it was out of hours and supported me in answering the questions. He even came and looked at some of our equipment when I wasn't sure (can't guarantee that kind of service for everyone!). He went above and beyond and I cannot recommend him enough.”
“Genuinely impressed with the Cyber Essentials experience via Fig Group. As a two-director UK tech company, we wanted certification done properly rather than superficially. The assessor, Jay Hopkins, was precise, fair, and constructive throughout, the feedback we received on our first submission was proportionate and gave us a clear path to remediation rather than a blanket rejection. The whole process from registration to certificate took under a week, and the end result is a real uplift in our security posture, not just a box-ticking exercise. The free cyber liability insurance included for businesses under £20m turnover is a meaningful additional benefit. Highly recommended for any UK SME looking to take cyber security seriously.”
The fastest Cyber Essentials certification in the UK - guaranteed within 6 hours for compliant submissions
Fig Group
6 hours
guaranteed on compliant submissions
Rest of UK industry
24-72 hrs
typical published turnaround
Speed matters most in four situations:
Use case 01
Tender deadlines
Meet urgent bid requirements.
Use case 02
Client requirements
Satisfy supply-chain obligations.
Use case 03
Insurance prerequisites
Unlock better cyber insurance.
Use case 04
Contract preparation
Prove controls before signing.
Under 6 hours from self-assessment submission - The fastest Cyber Essentials certification in the UK for compliant submissions.
Structured feedback - Fig provides structured feedback up to 3x on your self-assessment submission, helping you pass and receive your certificate within hours.
Competitively priced - With pricing from £299.99 + VAT, Fig is among the most competitive IASME-licensed certification bodies in the UK.
A foundational certification scheme backed by the UK government and NCSC
Cyber Essentials, defined
The UK government's foundational cybersecurity certification scheme - independent validation that an organisation has implemented the controls needed to defend against the most common cyber attacks.
Required by many UK government contracts handling sensitive data, and increasingly expected across private-sector supply chains.
Developed by
IASME, in partnership with the UK government and the National Cyber Security Centre (NCSC).
What it validates
Five core technical security controls - listed to the right.
Required for
UK government contracts handling sensitive data; increasingly required by private-sector buyers.
Fig accreditation
IASME-licensed certification body authorised for both Cyber Essentials and Cyber Essentials Plus.
Firewalls and internet gateways
Control inbound and outbound internet access at the boundary
Secure configuration
Harden systems and remove unnecessary services
User access control
Implement strong authentication and privileges
Malware protection
Deploy and maintain anti-malware solutions
Security update management
Keep software and devices updated with security patches
Choose the certification level that fits your needs
Self-assessed
IASME questionnaire reviewed by a Fig assessor. Six-hour SLA on compliant submissions - the fastest in the UK.
Turnaround: within 6 hours for compliant submissions
Independent technical audit
Adds external vulnerability scanning and a sampled technical audit on top of the same five controls.
Turnaround: 1-3 working days
Both certificates are valid for 12 months and carry the same NCSC badge.
| Feature | Cyber Essentials | CE Plus |
|---|---|---|
| Assessment type | Self-assessed | Third-party verified |
| External audit | - | |
| Vulnerability scan | - | |
| Certification validity | 1 year | 1 year |
| Best for | Quick, foundational proof | Enterprise & government bids |
IASME-licensed, transparent, and built for modern organisations
About Fig Group
An IASME-licensed Cyber Essentials certification body authorised to assess organisations for both Cyber Essentials and Cyber Essentials Plus.
Accreditation
IASME-licensed for Cyber Essentials and Cyber Essentials Plus, under the NCSC-backed scheme.
Pricing
Fully published. No hidden fees, no post-purchase surprises, no mandatory consultancy.
Coverage
UK-wide - from micro organisations to large enterprises, across all four organisation-size tiers.
Support
Dedicated team available throughout the process for questions and guidance.


Key updates effective 28 April 2026 under the NCSC requirements
The headline change: mandatory multi-factor authentication on every user account with access to organisational data or services.
Applies to cloud services, remote access, and administrative accounts without exception. All assessments completed from 28 April 2026 onwards must meet the v3.3 requirements.
Multi-factor authentication is required for all user accounts accessing organisational data, cloud services, and remote systems. Applies to assessments from 28 April 2026.
Clearer guidance on which devices and services are in scope, including personal devices used for work (BYOD) and home routers for remote workers.
Organisations must now demonstrate that cloud services are configured securely, with explicit requirements for SaaS, IaaS, and PaaS providers.
What to expect when you certify with Fig
How certification works
Three steps from purchase to certificate, certified within six hours of a compliant submission.
Step 1 · ~5 minutes
Select Cyber Essentials (self-assessed) or Cyber Essentials Plus (third-party verified), choose your organisation size band, and check out securely. Confirmation and access details land in your inbox immediately.
Step 2 · Under 6 hours
For Cyber Essentials, submit the questionnaire and an IASME-licensed assessor reviews it - compliant submissions return within 6 working hours. For Plus, an external auditor runs a technical audit including vulnerability scanning and control verification, typically 1-3 days.
Step 3 · 12-month validity
Once approved, your Cyber Essentials certificate is issued and listed on the official NCSC register. If any controls need remediation, you'll get clear, actionable feedback and can resubmit at no extra cost.
Video by IASME - the accreditation body behind Cyber Essentials certification.
Three buying contexts where certification is most often required
Public sector
Under Procurement Policy Note 014/21, Cyber Essentials may be required for UK central government contracts involving sensitive or personal information. The requirement applies contract by contract. If you need certification to meet a tender deadline, Fig certifies in under 6 hours from compliant self-assessment submission.
Private sector
Private-sector buyers increasingly require Cyber Essentials as part of supply chain risk management. Certification can also improve terms on cyber insurance policies. If clients ask whether you meet basic cybersecurity standards, Cyber Essentials provides independently verified proof.
Higher value
For higher-value or higher-risk contracts, Cyber Essentials Plus is increasingly preferred because it adds third-party verification rather than self-assessment alone. If you are bidding for government work or higher-tier supply chain roles, speak to our team about the right certification level.
In-depth guides written by our IASME-licensed assessor to help you prepare
The v3.3 update to Cyber Essentials makes multi-factor authentication mandatory for all user accounts. Here is what changed, who is affected, and how to comply.
The 14-day patching requirement is the single most common reason Cyber Essentials submissions fail first time. Here is what the rule actually says, when the clock starts, and how to evidence compliance when users are on holiday, vendors are slow, and legacy systems will not update.
The firewall question looks simple but fails more submissions than people expect. This guide covers boundary firewalls, software firewalls, home routers for remote workers (now in scope under v3.3), default credentials, and the cloud firewall configuration assessors expect in 2026.
Secure configuration is the control area with the broadest scope and the most room for getting details wrong. This guide covers default passwords, auto-run, unnecessary software, cloud service configuration, and the specific settings assessors check against v3.3 (effective 28 April 2026).
Malware protection looks simple - "we have antivirus" - but the question set asks specifically about configuration, coverage, and fallback approaches. This guide covers what qualifies under v3.3, including the application allow-listing alternative and the most common mistakes during assessment.
The step-by-step Microsoft 365 MFA configuration that passes Cyber Essentials v3.3 first time. Security Defaults vs Conditional Access, number-matching, admin hardening, and the legacy-auth question.
Google Workspace 2-Step Verification (2SV) configuration that passes Cyber Essentials v3.3: user rollout, admin hardening, and closing the "less secure app access" loophole.
Conditional-access policies that pass v3.3 vs those that fail. Trusted IP exemptions, device-based trust, Intune compliance, and why "require MFA unless trusted network" now fails most assessments.
Sector-specific guides covering how Cyber Essentials applies to your industry
Local guidance for the cities and regions Fig Group certifies most often.
Find your nearest location
Pick the city closest to your organisation. Each page covers local pricing, the six-hour turnaround, and the sector context for that region.
Local pricing
Same published flat fee, regardless of city or postcode.
Six-hour SLA
Compliant submissions return certified within six working hours.
Sector context
Financial services, legal, MSPs, and government supply chains - by city.
Use our self-assessment tool to identify gaps before formal certification
Use your Cyber Essentials evidence as a foundation for broader compliance
Start here
Five core security control categories - access control, patch management, secure configuration, malware protection, and firewalls - all mapped directly to ISO 27001 controls.
Practical, achievable first step. Certification in 6 hours for compliant submissions.
Progress to
The international standard for information security management. Reuse your CE evidence and controls as a foundation, reducing duplication and shortening the path to certification.
When your business requirements demand a broader ISMS, your CE work already counts.
Fig supports 65+ compliance frameworks - ISO 27001, NIS2, GDPR, SOC 2, CMMC and more.
Cyber Essentials vs ISO 27001Cyber Essentials is just the beginning
Fig supports 65+ compliance frameworks including ISO 27001, NIS2, GDPR, SOC 2, CMMC, and more.
Once certified with Cyber Essentials, use your evidence and controls to accelerate compliance with other frameworks. MSPs can offer Cyber Essentials at scale.
Explore All SolutionsEverything you need to know about Cyber Essentials
Cyber Essentials is a UK government-backed certification scheme that validates five technical cyber controls: firewalls, secure configuration, user access control, malware protection, and security update management. It is administered by IASME on behalf of the NCSC.
Cyber Essentials Plus adds an independent technical audit - external vulnerability scan, device configuration check, MFA verification - on top of the CE self-assessment. Plus is required by many UK government contracts and most large enterprise supply chains.
UK Cyber Essentials fees are set by each IASME-licensed Certification Body within the IASME-published headcount tiers (Micro 1-9, Small 10-49, Medium 50-249, Large 250+). Fig Group prices Cyber Essentials from £299.99 + VAT for Micro, rising to £399.99 (Small), £449.99 (Medium), and £549.99 (Large), with all tiers set below the standard IASME certification body fee.
Fig publishes a 6-hour turnaround guarantee for compliant Cyber Essentials submissions made before midday on a UK business day. If the submission needs edits, the clock pauses while you fix them and resumes on re-submission.
v3.3 is the Cyber Essentials scheme version effective from 28 April 2026. It adds mandatory multi-factor authentication on every user account, clearer BYOD and cloud-service scoping, and tightens remote-worker home-router expectations.
Yes. Multi-factor authentication is mandatory on every user account that accesses organisational data on or after 28 April 2026. This includes cloud services, email, admin accounts, remote access, and line-of-business SaaS applications.
Every device and service used to access organisational data: laptops, desktops, phones, tablets, cloud services, home routers for remote workers (under v3.3), and corporate network equipment. Anything that does not access organisational data is not in scope.
Twelve months from the assessment date. On the anniversary the certificate lapses with no grace period. Most organisations re-certify 14 days before expiry to protect contract continuity.
You are removed from the NCSC register and are no longer certified for contract purposes. Re-certification restores the listing; if you have already done the readiness work, the renewal questionnaire is typically much shorter than the initial submission.
Under PPN 014/21 it is required for central government contracts that handle sensitive or personal information. The specific requirement varies by contract; some require CE, some require CE Plus. Always check the bid documentation.
Cyber Essentials covers five technical controls. ISO 27001 is a full information security management system with 93 Annex A controls, policies, risk processes, internal audits, and a formal multi-day certification audit. For a practical buyer-focused breakdown, see /blog/cyber-essentials-vs-iso-27001-which-does-your-customer-actually-want.
Cyber Essentials is certified per organisation, not per MSP. Your MSP can manage the assessment and remediation, but your organisation signs the attestation and holds the certificate.
Three buyer contexts drive most CE certification: UK suppliers covered by PPN 014/21 government procurement; supply-chain vendors where a tier-one customer mandates CE in contract; and regulated firms (SJP partner practices, FCA-regulated firms, NHS suppliers) where certification is contractually expected. Insurers also increasingly request CE evidence at PI quote and renewal.
Every article we've written on the scheme, grouped by topic. Written by Jay Hopkins, IASME-licensed Cyber Essentials assessor.
Cyber Essentials trust evidence
This block keeps the commercial claims close to the final decision point: licence, speed, pricing, reviews, and the important difference between Cyber Essentials and Cyber Essentials Plus.
Licence
Fig Group publishes its IASME licence evidence, operating entity, and external verification route so buyers can check the certification body before purchase.
Verify IASME licenceSpeed
The 6-hour assessor turnaround applies to eligible Cyber Essentials submissions received before midday on a UK business day. It does not apply to Cyber Essentials Plus.
Review speed evidencePricing
Cyber Essentials pricing is published by tier and mapped against the standard IASME certification body fee, with no mandatory consultancy add-on.
Review price evidenceReviews
Google review signals and Fig claim evidence are separated from sales copy so procurement teams can verify trust claims independently.
Review rating evidencePractical rule: buy Cyber Essentials when the requirement asks for baseline certification. Buy Cyber Essentials Plus only when the buyer, insurer, or framework specifically asks for the audited technical verification layer.
Get certified, protect your business, and prove your security controls.
We only load non-essential analytics and advertising tags after explicit consent. You can review our cookie register in the cookie policy section and update your choice at any time via “Cookie settings” in the footer.