Skip to main content
    NixInfinity-AI
    Sector

    Cyber Essentials for Financial Services Firms

    Published 17 June 2026

    Why CE fits the FCA model

    The FCA expects firms to have appropriate technical and organisational measures, defined important business services and known impact tolerances. CE doesn't satisfy all of that – it satisfies the technical hygiene layer, which is where most enforcement actions actually find gaps. It's a small certificate that closes a disproportionately large risk band.

    Where CE evidence sits in the regulatory file

    • SYSC 4.1 (organisation requirements) – CE evidences technical controls.
    • SYSC 13/15 (operational risk) – CE controls map to common operational-cyber failures.
    • PS21/3 (operational resilience) – CE underpins the technical-controls leg of impact-tolerance work.
    • Consumer Duty – CE supports the "act in good faith" expectation around protecting client data.

    Recommended scope

    For a typical FCA-regulated firm, scope should include:

    • All staff laptops and phones touching client data.
    • The CRM (Salesforce, Intelliflo, Plannr, Curo).
    • The trading or custody platform admin interface.
    • Client-portal admin and document-storage tenancies.
    • Email tenant (M365 or Google Workspace) including any shared mailboxes.

    Marketing micro-sites and unrelated subsidiaries can typically be excluded with a written rationale.

    The four areas regulated firms most often slip on

    1. Third-party SaaS MFA. The CRM has MFA, but the marketing email tool doesn't. Under the Danzell question set, every cloud account needs MFA.
    2. Leavers process. Adviser leaves on Friday, account still active Monday. CE expects same/next-working-day disablement.
    3. Patching cadence. The 14-day high-risk patching rule catches firms that batch updates monthly.
    4. Admin separation. A founding partner using the same account for daily email and platform administration is a common fail.

    CE vs CE Plus for FCA firms

    Standard CE is sufficient for most appointed representatives and small advice firms. CE Plus is the right level once you hold client money, run a custody platform integration, or operate as a wholesale firm. Insurers and PI underwriters increasingly price CE Plus into renewals.

    What this looks like in practice

    • Year 1: standard CE during the annual operational-resilience review.
    • Year 2: upgrade to CE Plus 60 days before CE renewal so certificates align.
    • Year 3+: CE Plus annually, audited alongside the firm's resilience self-assessment.

    For an IFA-specific walkthrough, see our IFA cyber-certification page. To start, head to Cyber Essentials.

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions