Fig Group

Cyber Essentials for MSPs and the Supply Chain Enterprise, NHS and Central-Government Procurement

Fig Group certifies Managed Service Providers and supply-chain suppliers selling into enterprise, NHS and central-government buyers across London. Whether you are responding to a framework mini-competition, a Crown Commercial Service DDQ or an NHS trust's DSPT submission, Cyber Essentials is the baseline control-demonstrating artefact on the cover sheet. Certification is delivered on a published flat fee with six-hour turnaround for compliant submissions.

The scoping challenge

Shared infrastructure means a sharp boundary

MSPs run infrastructure that overlaps with their customers' estates, so the Cyber Essentials scope has to be drawn deliberately - the MSP's own devices and admin controls sit firmly in scope, customer estates do not.

The commercial gate

A de-facto procurement requirement

Cyber Essentials (and increasingly Cyber Essentials Plus) is now the baseline gate for MSPs selling into enterprise, NHS, and central-government accounts - explicit under PPN 014/21 for central-government contracts handling sensitive or personal information.

Why MSPs need Cyber Essentials differently

An MSP's Cyber Essentials scope is genuinely harder to draw than a typical end-customer's. Much of the infrastructure an MSP touches is shared with - or owned by - its customers, so the boundary needs to be set explicitly. Our approach: the MSP's own estate is in scope; customer estates are not.

MSP's own estate (in scope)

Engineer laptops, MSP corporate email, the ticketing system, RMM tooling, and the monitoring stack - unambiguously in scope.

Customer estates (out of scope)

Customer infrastructure is excluded from the MSP's own certificate, unless the MSP owns the customer's devices outright.

Admin access controls (in scope)

Privileged access management, MFA on admin accounts, just-in-time access, and tiered engineer access - all sit on the MSP's own devices and accounts.

Enterprise, NHS and central-government procurement

Cyber Essentials is the quickest line item to clear on a DDQ. Across UK-listed enterprises, NHS trusts, and central-government departments, it is now a near-universal procurement requirement.

Enterprise DDQs

Almost universally list Cyber Essentials - and increasingly Cyber Essentials Plus - as an explicit requirement on the cover sheet of the due-diligence questionnaire.

NHS DSPT

The Data Security and Protection Toolkit maps many of its evidence requirements to Cyber Essentials, even though the toolkit does not formally require it directly.

Central government PPN 014/21

Makes Cyber Essentials explicit for central-government contracts handling sensitive or personal information.

The commercial implication

Disqualified at stage one without it

An MSP that cannot evidence Cyber Essentials on a DDQ cover sheet is typically disqualified at stage one of the bid - before any technical response is read. Cyber Essentials Plus is the upgrade that wins (not just passes) stage-two competition, because it demonstrates external verification rather than a self-assessment.

Working with Fig Group as an MSP

Fig Group has certified MSPs of every size - from two-person managed-service shops in north London to multi-site operations. Same published flat fee, regardless of MSP revenue or customer count.

Published flat fee

Same price across every MSP, every revenue band, every customer count. No volume-based or revenue-based quoting.

Six-hour SLA

Compliant Cyber Essentials submissions are returned certified within six hours - valuable when you are under tender-deadline pressure on a customer bid.

Cyber Essentials Plus

External vulnerability scan of internet-facing infrastructure plus a sampled endpoint audit on engineer workstations. Plus certificates complete in 1-3 working days.

MSP partnerships

Partnership arrangements for MSPs wanting to offer Cyber Essentials to their own customers - reach out via the contact form below.

6-hour guarantee

Issued within six hours of a compliant submission.

From £299.99 + VAT

Published flat fee. Never quoted on revenue.

IASME licensed

Authorised certification body for CE and CE Plus.

3 free reviews

Included if remediation is needed.

Where MSPs & Supply Chain concentrate in London

Fig Group certifies organisations across every London borough. These boroughs are the main clusters for msps & supply chain:

MSPs & Supply Chain: Frequently asked questions

How quickly can I get Cyber Essentials certified?

Fig Group guarantees Cyber Essentials certification within 6 hours of self-assessment submission for orders placed before midday, provided the submission is compliant. If corrections are needed, up to three rounds of structured feedback are included at no extra cost. Cyber Essentials Plus takes 1-3 working days due to the external technical verification requirement.

How much does Cyber Essentials cost?

Cyber Essentials costs from £299.99 + VAT (micro, 1-9 employees) to £549.99 + VAT (large, 250+ employees). Cyber Essentials Plus costs from £1,499 + VAT to £4,499 + VAT. Fig Group pricing is fully inclusive - no hidden fees, no revenue-based quoting, no mandatory add-ons.

Is Cyber Essentials mandatory?

Cyber Essentials is required under PPN 014/21 for certain UK central-government contracts handling sensitive or personal data. It is also increasingly required by NHS supplier frameworks, local authorities, regulated financial-services counterparties and private-sector enterprise procurement teams as the baseline evidence of foundational cybersecurity.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessed questionnaire reviewed by an IASME-licensed assessor. Cyber Essentials Plus adds an external vulnerability scan and a sampled technical audit of end-user devices, independently verifying that the five controls are operating in practice. Both certifications are valid for 12 months and carry the same NCSC badge.

Ready to certify your msps & supply chain organisation?

Six-hour guarantee for compliant submissions. Three free review rounds. Published flat fee from £299.99 + VAT.

Speak to the team

Tell us about your msps & supply chain organisation and we will come back with a fixed price and a target certification date.