Inner London · City of London

Cyber Essentials Certification City of London 6-Hour Guarantee · From £299.99 + VAT

Fig Group is an IASME-licensed Cyber Essentials and Cyber Essentials Plus certification body serving organisations across City of London. We deliver certification on a published flat fee - never quoted on revenue - and guarantee turnaround within six hours of a compliant self-assessment submission.

“Fig certified us the same morning we submitted. We had an NHS framework question deadline that afternoon and genuinely would not have made it with any other body.”
P.R.·Head of IT, professional-services firm

City of London Cyber Essentials pricing

Fig Group publishes a flat fee for every organisation size, applied identically whether your business is in Bank or elsewhere in City of London. Cyber Essentials starts at £299.99 + VAT for micro organisations (1-9 employees). Cyber Essentials Plus starts at £1,499 + VAT. Both products include the latest Cyber Essentials v3.3 requirements, including the mandatory MFA control.

Cyber Essentials

OrganisationPrice
Micro1-9 employees£299.99+ VATGet certified
Small10-49 employees£399.99+ VATGet certified
Medium50-249 employees£449.99+ VATGet certified
Large250+ employees£549.99+ VATGet certified

Self-assessed certification. Includes assessment, up to three feedback rounds, certificate issuance, and IASME registration.

Cyber Essentials Plus

OrganisationPrice
Micro1-9 employees£1,499+ VATGet certified
Small10-49 employees£1,999+ VATGet certified
Medium50-249 employees£2,799+ VATGet certified
Large250+ employees£4,499+ VATGet certified

Third-party verified with external vulnerability scan. 1-3 working days.

Why City of London businesses choose Fig Group

The City of London is the most commercially demanding jurisdiction in the UK for supplier cyber compliance. Lloyd's syndicates, London Market insurers, Magic Circle law firms, commodities clearing members at the LME and ICE Futures Europe, and the asset-management firms concentrated across the Square Mile almost universally require Cyber Essentials - and frequently Cyber Essentials Plus - from their suppliers. The FCA and PRA both expect operational resilience evidence that typically includes Cyber Essentials at minimum. Commercial barristers' chambers around the Temple, criminal chambers near the Old Bailey, and SJP Partner Practices operating from Mayfair and the Square Mile face the same pressure from instructing solicitors, lay clients, and insurance underwriters. Fig Group certifies City of London organisations within six hours of a compliant submission, on a published flat fee, and our office at 167-169 Great Portland Street is a short walk or a single Central line stop from the Square Mile for in-person scoping sessions.

Areas covered

Bank, Moorgate, Liverpool Street, Aldgate, Barbican, Fleet Street, Farringdon, Cannon Street, Blackfriars, Monument

Postcode coverage

EC1, EC2, EC3, EC4

Notable sectors in City of London

Banking and capital markets, insurance (Lloyd's syndicates and London Market), legal services (Magic Circle and commercial barristers' chambers), commodities clearing (LME, ICE), asset management, professional services.

Top three compliance triggers for City of London businesses

1. Local-authority and public-sector procurement in City of London

Tenders published by City of London Council (and by the NHS trusts whose catchment covers the borough) routinely name Cyber Essentials as a baseline supplier requirement under PPN 014/21 and the corresponding council standing orders. Any business in City of London bidding on council framework agreements, social-value-weighted contracts, or health-and-care services via the local ICB will see Cyber Essentials listed on the cover page of the DDQ. Fig Group certifies City of London suppliers within six hours of a compliant submission, which matters when a council mini-competition window is short.

2. Enterprise and regulated-customer pressure in City of London

Beyond the public sector, the private-sector customers of City of London businesses increasingly treat Cyber Essentials as a baseline on supplier onboarding. In City of London the concentrations are in banking and capital markets, insurance (Lloyd's syndicates and London Market), legal services (Magic Circle and commercial barristers' chambers), each of which carries its own supplier cyber expectation set (FCA operational resilience for financial counterparties, SRA data-handling requirements for legal work, NHS DSPT alignment for health, ICO reasonableness for any processor of personal data). A self-assessed Cyber Essentials certificate typically clears stage-one of the DDQ; Cyber Essentials Plus is what wins the stage-two competition.

3. Professional indemnity and cyber insurance in City of London

Professional-indemnity and cyber insurance underwriters now apply higher retention loadings (or decline altogether) to City of London businesses that cannot demonstrate baseline cyber hygiene. Cyber Essentials is the lowest-friction evidence that most brokers accept at renewal. Some underwriters now treat Cyber Essentials Plus as a precondition for writing certain cyber sub-limits at all. Fig Group's Plus certification includes the external vulnerability scan and sampled endpoint audit as standard - no separate scanning fee, no mandatory consultancy day.

What we certify for City of London organisations

Scope on a City of London Cyber Essentials engagement typically covers every device used for business purposes - laptops, desktops, mobile phones, tablets - that can access organisational data or cloud services. It covers the network perimeter (router, firewall, WiFi access points) that the devices sit behind. It covers the identity platform (Microsoft 365, Google Workspace, Okta, or the Active Directory forest) that authenticates each user. It covers the security-relevant SaaS applications in use - email, file storage, collaboration, CRM, any line-of-business application with authentication.

For a typical City of London organisation in banking and capital markets, the five NCSC control categories translate as follows. Firewalls and internet gateways: the border router and any WiFi access points must have non-default admin credentials and published patches applied within fourteen days. Secure configuration: all in-scope devices must have an MDM baseline applied, unused accounts disabled, and auto-lock enforced. Security update management: operating-system and application patches must land within fourteen days of release. User access control: multi-factor authentication is mandatory under v3.3 for every user account accessing organisational data. Malware protection: endpoint protection (Defender, CrowdStrike, SentinelOne or equivalent) must be active on every in-scope endpoint.

The Cyber Essentials Plus assessment adds an external vulnerability scan of internet-facing assets and a sampled technical audit of end-user devices - for a City of London organisation that is typically a short set of video calls plus a remote screen-share of a sample laptop, spread across one to three working days.

Getting to Fig Group's office from City of London

Our office at 167-169 Great Portland Street, W1W 5PF, is the closest IASME-licensed certification body to City of London for any scoping session you would prefer to run in person. The nearest Underground stations are Great Portland Street (Circle, Hammersmith & City, Metropolitan - two minutes' walk) and Regent's Park (Bakerloo - five minutes' walk). Warren Street (Victoria, Northern) is ten minutes' walk via Fitzrovia. For most City of London organisations the straightforward route is a single Central, Northern or Circle line change onto the short Fitzrovia / Marylebone corridor. The vast majority of our engagements run remotely - we mention the office only because several City of London clients have asked for in-person scoping calls for Plus assessments where the head of IT and the CRO both want to be in the room.

Map centred on City of London (51.516, -0.092)Open in OpenStreetMap

6-hour guarantee

Guaranteed within six hours of a compliant submission.

From £299.99 + VAT

Published flat fee - never quoted on revenue.

IASME licensed

Authorised certification body for CE and CE Plus.

3 free reviews

Structured feedback if remediation is needed.

How certification works for City of London businesses

The process is the same for every City of London organisation, regardless of sector or size. We have refined it across hundreds of London certifications to keep elapsed time as short as possible.

  1. Step 1

    Scope your assessment

    Tell us which devices, accounts, and locations are in scope. We confirm pricing on the published flat fee - no revenue-based quotes.

  2. Step 2

    Submit your evidence

    Use our portal to provide answers against the five NCSC controls. Our readiness checker pre-flags anything that needs work.

  3. Step 3

    Receive feedback (if needed)

    If anything needs adjusting, we send structured, plain-English feedback within hours. Three review rounds are included free.

  4. Step 4

    Get certified

    Once compliant, your certificate is issued within six hours. Cyber Essentials Plus adds a remote technical audit (1-3 working days).

Frequently asked questions - Cyber Essentials in City of London

Ready to get certified in City of London?

Book your Cyber Essentials assessment today. Six-hour guarantee for compliant submissions, three free review rounds, and a published flat fee from £299.99 + VAT.

Nearby London boroughs

Fig Group also certifies organisations in the boroughs that neighbour City of London. Each page lists sector-specific context and local postcode coverage.

Speak to the team

Tell us about your City of London business and we will come back with a fixed price and a target certification date.