<15 min Response

20+ Years Experience

Cyber Essentials Certified

Check IT & Cyber Score

Remote SOS Support

Does the SRA Require Cyber Essentials? What Law Firms Actually Need to Do

Solicitor reviewing Cyber Essentials compliance requirements for a law firm

No. The SRA does not require law firms to hold Cyber Essentials certification, and there is no rule that says you must.

What the SRA does require is that you take appropriate steps to protect client data against loss, damage or unauthorised access. That obligation is outcome-based rather than prescriptive: the regulator tells you what must be true, not which certificate to buy. Cyber Essentials is simply the most common way UK firms demonstrate they have met it.

The Law Society recommends Cyber Essentials as one of three routes to demonstrating cyber competence, alongside Lexcel and ISO 27001. It is government-backed and overseen by the National Cyber Security Centre, which is why it carries weight with clients, insurers and panel managers even though no regulator mandates it.

So the honest position is this: not required, widely expected.

What the SRA actually asks of you

Three obligations matter here, and none of them mentions a certificate. We cover these in more detail in our guide to SRA IT requirements for solicitors.

Protect client data. You must take appropriate steps to protect client information against loss, damage or unauthorised access. “Appropriate” scales with your firm. A three-partner practice handling conveyancing is not held to the same technical standard as a 200-fee-earner commercial firm, but both are expected to have thought about it and be able to show their reasoning.

Report serious breaches. A serious breach of the SRA’s Standards and Regulations must be reported to the SRA under Rule 3.9 of the Code of Conduct. Firms sometimes assume this only applies to money. It does not.

Report personal data breaches within 72 hours. Under UK GDPR, a reportable personal data breach must reach the ICO within 72 hours of you first finding out. Seventy-two hours is not long if nobody has agreed in advance who makes that call, who gathers the facts, and who writes the notification.

Where firms get caught out is not usually the technology. It is that nobody can answer “what happened, when, and to whose data” quickly enough to make a decision inside the window.

Where Cyber Essentials fits

Cyber Essentials is a certification against five technical controls. It is deliberately narrow: it does not cover policies, training, or governance. It checks that the basics are actually in place. Our Cyber Essentials certification guide walks through the process in full.

The five controls are:

  1. Boundary firewalls and internet gateways. What sits between your network and the internet, and how it is configured.
  2. Secure configuration. Devices and software set up deliberately, with defaults changed and anything unnecessary removed.
  3. Access control. Who can reach what, administrator rights kept to those who genuinely need them, and accounts removed when people leave.
  4. Malware protection. Endpoint protection in place and actually running everywhere, not just on the machines someone remembered.
  5. Patch management. Operating systems and applications kept up to date within defined timescales.

None of that is exotic. That is rather the point. Cyber Essentials exists because the majority of successful attacks exploit failures in these five areas rather than anything sophisticated.

Cyber Essentials or Cyber Essentials Plus?

Cyber Essentials is a self-assessment. You complete an online questionnaire, it is reviewed, and you certify. There is no independent testing of your systems.

Cyber Essentials Plus covers the same five controls, but an accredited assessor independently tests your systems to verify the answers.

For most law firms, standard Cyber Essentials is the sensible starting point. Move to Plus when a client, insurer or panel requires it, or when you want assurance that what you believe is in place actually is. Both need renewing annually.

Certification is priced in bands based on organisation size, so a small practice pays considerably less than a large one. We break the current figures down in our guide to Cyber Essentials cost. The larger cost for most firms is not the certificate itself. It is the remediation work needed to pass it.

Why law firms fail their first assessment

Across the practices we take through this, the same handful of issues come up.

Unsupported software still in use. A legacy application that only runs on an old operating system, kept alive because replacing it is disruptive. This fails the assessment outright and is a genuine risk regardless.

Administrator rights handed out too widely. Often historical, often to people who no longer need them, sometimes to accounts belonging to people who have left.

Leavers not fully removed. The Windows account is disabled but the Microsoft 365 licence, the case management login and the shared mailbox access are still live.

Patching that is assumed rather than verified. Nobody can produce evidence that updates are being applied within the required timescales, because nothing is reporting on it.

Personal devices in scope and nobody realised. Fee-earners reading matter email on their own phones brings those devices into scope. If they are not managed, that is a problem for the assessment and for the firm.

Most of these are fixable in weeks rather than months, but they are much easier to fix before you start the assessment than during it.

The insurance angle

Cyber insurance can supplement your professional indemnity cover rather than replace it, and insurers may offer reduced PII premiums where a firm can demonstrate its security measures.

This is worth raising with your broker before renewal rather than after. Firms often discover at renewal that they could have evidenced controls they already had, had anyone asked them for it in time.

What to do next

If you are starting from nothing, the order that works is:

  1. Find out what is actually in scope. Devices, cloud services, personal phones with work email, home working setups. Most firms are surprised by the answer.
  2. Fix the five controls properly before you fill in any assessment. Certifying a poorly configured environment is a paperwork exercise, not a security improvement.
  3. Certify, then treat the annual renewal as a genuine review rather than a form-filling job.
  4. Write down who does what if something goes wrong, because the 72-hour clock does not care how good your firewall is.

Cyber Essentials will not make your firm secure on its own. What it does is force the basics to be true and give you something defensible to show a client, an insurer or the SRA.

ATS Connection is Cyber Essentials certified and provides IT support for solicitors and law firms, including readiness work for firms going through certification for the first time.

Frequently asked questions

Does the SRA require law firms to have Cyber Essentials?

No. The SRA does not mandate Cyber Essentials. It requires firms to take appropriate steps to protect client data against loss, damage or unauthorised access. Cyber Essentials is one recognised way of demonstrating that, and is recommended by the Law Society alongside Lexcel and ISO 27001.

Is Cyber Essentials worth it for a small law firm?

For most firms, yes. Certification is banded by organisation size so smaller practices pay less, and it forces the five basic technical controls to be genuinely in place rather than assumed. It also gives you something concrete to show clients, panel managers and insurers.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Cyber Essentials is a self-assessment reviewed by a certification body. Cyber Essentials Plus covers the same five controls but adds independent technical testing by an accredited assessor. Plus is usually driven by a client or insurer requirement.

How long does Cyber Essentials certification last?

Certification is renewed annually. Firms that treat renewal as a genuine review rather than a form-filling exercise tend to find problems before an assessor or an attacker does.

Do we have to report a cyber incident to the SRA?

A serious breach of the SRA’s Standards and Regulations must be reported under Rule 3.9 of the Code of Conduct. Separately, a reportable personal data breach must be notified to the ICO within 72 hours of the firm becoming aware of it. Those are two different duties with two different thresholds.

Will Cyber Essentials reduce our professional indemnity premium?

It may help. Cyber insurance supplements PII rather than replacing it, and insurers may offer reduced premiums where a firm can evidence its security measures. Raise it with your broker before renewal rather than after.