

Cyber Essentials and Plus
Support clients through Cyber Essentials and Cyber Essentials Plus, with certification assessment delivered by Fig Compliance Ltd.
Explore Cyber EssentialsBring compliance certification, cybersecurity software and specialist security services into your portfolio. Work with Fig to deliver a broader client offering, with commercial terms and responsibilities agreed around your business.
Referral, resale and white-label structures available · see published pricing
Offer an individual service or combine the platform, certification and specialist assessments around each client’s requirements. Delivery scope and responsibilities are confirmed for every engagement.


Support clients through Cyber Essentials and Cyber Essentials Plus, with certification assessment delivered by Fig Compliance Ltd.
Explore Cyber Essentials

Offer Level 0 and Level 1 certification engagements. Confirm the applicable requirements, prerequisites and scope for each client.
Explore DCCVulnerability scanning, penetration testing, device and cloud security reviews, public exposure checks and source code reviews, scoped to each client’s requirements.
Explore all six servicesBring client oversight, compliance and cybersecurity monitoring, policies, risks, remediation tasks and reporting together in one platform.
Explore the platformChoose the level of client involvement and branding you need. We will confirm the appropriate commercial and delivery arrangements together.

Introduce clients
Connect clients with Fig for a defined certification, software or security requirement. Agree referral arrangements and the client handover before making an introduction.
Professional advisers, consultancies and introducers.

Extend your portfolio
Add Fig services to your portfolio while managing the commercial relationship with your client. Partner pricing, invoicing and delivery responsibilities are agreed in your terms.
IT resellers, value-added resellers and channel businesses.

Deliver under your brand
Combine your client management with Fig’s platform and specialist delivery to offer a broader security and compliance service under your own brand. Branding and communications are agreed in advance.
MSPs and MSSPs developing a branded managed service.
Pricing, referral arrangements and delivery responsibilities are confirmed in your partner terms before the first client engagement.
Discuss partner termsTell us about your business, the clients you support and the services you want to offer. We identify the appropriate partner model and initial scope.
Confirm pricing, branding, contracts, client communications and support responsibilities. Establish how your team and Fig will coordinate delivery.
Agree the client scope and authorisations. Your team manages the relationship under the chosen model; Fig delivers the contracted assessment, software or specialist service.
Review findings, assign remediation responsibilities and discuss renewals or additional services where relevant to the client.
We work with MSPs to certify their clients. Your team can complete the Cyber Essentials self-assessment on the client’s behalf, provided the organisation reviews and authorises the submission and its board-level representative or equivalent provides the required sign-off in the Cyber Essentials portal. Fig Compliance Ltd carries out the certification assessment; the client organisation holds the certificate.
White-labelling does not remove required certification-body details, scheme marks or client declarations.
Verify our IASME licenceDiscuss the standards your client is working towards and the support they require. We’ll confirm the proposed scope, delivery responsibilities and commercial terms.
Discuss an ISO requirementHelp clients organise security and compliance evidence for conversations with their insurance adviser. Explore how the Fig platform supports that preparation.
Explore insurance-related evidence Fig does not provide insurance advice, placement or underwriting.
Plan certification renewals, monitoring and further assessments around the client’s requirements, rather than treating each engagement in isolation.

Agree scope, timescales, reporting and handovers before work begins, so your team can set clear expectations with the client.

Bring your knowledge of the client’s environment together with Fig’s certification assessment and specialist security capabilities.

Access certification, software and security reviews through one partner relationship, with responsibilities confirmed for each service.
Agree how your team and Fig will work together before the first engagement. The operating model reflects the services and partnership structure you select.
Commercial arrangements, branding and certification responsibilities.
IT resellers, value-added resellers, MSPs, MSSPs and professional advisers. The model depends on whether you introduce clients, manage the commercial relationship or deliver a branded managed service.
Offer Fig’s platform, security testing and certification services under your brand while keeping the client relationship. We agree branding, delivery responsibilities and client communications with you. Certification remains subject to scheme rules: required certification-body details, scheme marks and client declarations are retained.
We work with MSPs to certify their clients. Your team can complete the Cyber Essentials self-assessment on the client’s behalf, provided the organisation reviews and authorises the submission and its board-level representative or equivalent provides the required sign-off in the Cyber Essentials portal. Fig Compliance Ltd carries out the certification assessment; the client organisation holds the certificate.
No. Certification can be purchased separately. The platform and specialist services can complement an engagement, but they do not replace the required assessment or guarantee certification.
Partner rates, billing, referral arrangements where applicable, delivery scope and support responsibilities are confirmed in your terms. We discuss intended services and expected volumes before proposing a commercial structure.
Yes. Combine the Fig platform with certification and scoped specialist security services to broaden your client offering. We agree which activities Fig delivers and which remain with your team. The partnership does not imply that every security operation or incident-response service is included.
Yes. Include these requirements in your enquiry so we can confirm an appropriate scope. ISO engagements require a specific proposal. Fig’s insurance-related offering concerns security and compliance evidence, not insurance advice, placement or underwriting.
Tell us which services interest you and a little about the clients you support. We’ll discuss the delivery model and commercial arrangements with you.
Not sure which model fits? We can work through the options together.