Skip to content

Manage security.
Automate compliance.
Get certified.

Fig brings cybersecurity and compliance automation together with certification and specialist security testing. For businesses managing their own operations and MSPs delivering services to clients.

Inside the Fig platform

Review control strength and evidence

See Cyber Essentials controls alongside declared, enforced and evidenced status.

Explore this capability
Fig Cyber Essentials control table showing declared, enforced and evidenced control strength
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Fig platform · Compliance controls
Platform pricing

Clear pricing.For corporates and MSPs.

Step 1Start with your details

Step 2Choose your package

Corporate package

Know your security health

From£13.50+ VAT / month

Per corporate organisation · retail list price

  • Monthly cloud security scanning
  • External-facing asset vulnerability scans
  • Mobile device security scanning
  • Computer and laptop endpoint scanning
  • Month-end reports by email with remediation guidance
  • Scanning and reports only; no platform access
See sample reports

Corporate package

Manage your Cyber Essentials compliance

From£27+ VAT / month

Per corporate organisation · retail list price

  • Everything in Fig Pulse, with daily security scanning
  • Access to the Fig platform
  • Controls mapped against the Cyber Essentials framework
  • Policy generation
  • Asset and Risk register

Corporate package

Cover your core compliance requirements

From£115+ VAT / month

Per corporate organisation · retail list price

  • Everything in the Cyber Essentials package
  • Full staff training modules
  • EDR across mobile devices, computers and laptops
  • Staff lifecycle management
  • Supplier and buyer third-party risk management
  • Coverage across all 15 Basic frameworks
Framework coverageExplore what’s includedCompare Basic and Advanced coverage by package.Compare frameworks

Basic frameworks

Core cybersecurity, privacy and business requirements.

Included inCompliance Plus & Compliance Pro

Cybersecurity and defence

  • IASME Cyber Essentials
  • NIST CSF
  • ASD Essential Eight
  • DCC Level 0

Privacy and data protection

  • UK GDPR
  • Data Protection Act 2018
  • PECR / ICO Marketing
  • FTC Safeguards Rule
  • GLBA (Gramm-Leach-Bliley)
  • CCPA / CPRA
  • PIPEDA (Canada)
  • LGPD (Brazil)
  • POPIA (South Africa)

Business obligations

  • UK Procurement Act 2023
  • UK Modern Slavery Act

Advanced frameworks

Additional coverage for complex compliance requirements.

Included inCompliance Pro

ISO management standards

  • ISO 27001
  • ISO 27701
  • ISO 27017
  • ISO 27018
  • ISO 27034
  • ISO 22301
  • ISO 20000
  • ISO 42001
  • ISO 9001

Assurance and industry requirements

  • IASME Cyber Assurance L1 & L2
  • PCI DSS
  • SOC 2
  • HIPAA
  • NHS DSPT
  • NYDFS Cybersecurity Regulation
  • SOX (Sarbanes-Oxley)
  • FCA Obligations
  • PRA Obligations
  • MAS TRM
  • NCA ECC
  • NERC CIP
  • UK NIS Regulations 2018

Government and defence

  • EU NIS2 Directive
  • UK Cyber Security & Resilience Bill
  • DCC Level 1
  • DCC Level 2
  • DCC Level 3
  • CMMC Level 2 (NIST SP 800-171)
  • NIST SP 800-53
  • FedRAMP
  • FISMA
  • BSI IT-Grundschutz
One team

Software and services.
From the same team.

Use Fig for day-to-day security and compliance work, then bring in our specialists for testing and certification.

Assessed certification

Compliance certification

Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification Level 0 and Level 1, assessed by Fig Compliance Ltd. Buy certification on its own or alongside the platform.

Platform software

Compliance automation

Map controls to frameworks, collect evidence and manage policies, audits and staff training. Keep track of outstanding work between assessments, not just at renewal.

Platform software

Cybersecurity automation

Monitor assets and security findings, prioritise vulnerabilities and manage remediation. Configure workflows around your policies, with approvals, assigned owners and a record of the actions taken.

Specialist services

Security testing and specialist services

Vulnerability scanning, code scanning and security reviews, penetration testing, and device, cloud and public exposure checks. Agree the scope with our team and get findings and remediation guidance.

Scoped to what you need. We agree which platform capabilities and services you need. Specialist testing and certification have their own scope; using the platform does not automatically confer certification.

Talk to the team
The platform

Explore the capabilities

Every capability below is a working part of the platform with its own page - what it does, how teams use it and the evidence it produces.

For MSPs

Your client relationship.
A wider security service.

White-label Fig’s platform and services to build your MSSP offering without buying a fragmented tool stack. Manage client security and compliance, offer specialist testing and work with us to certify your clients.

You keep the customer relationship. We agree delivery and branding with you, while retaining required certification-body details and client sign-off.

Explore the MSP partnership

See how Fig would work for your team.

Tell us about your systems, clients and certification requirements. We’ll tailor the demo to what you need.

Arrange a demo