What is a legal entity?
A legal entity refers to an organisation or entity that is recognised by law as having its own legal rights and responsibilities. This includes the ability to enter into contracts, own property, sue or be sued, and comply with regulatory requirements. A legal entity is distinct from the individuals who manage or work for it, and it is typically registered with a government authority.
Examples of legal entities include:
Private and public limited companies
Partnerships
Sole traders
Nonprofit organisations
Government agencies
A cyber security certification is typically issued to the legal entity that owns and operates the systems, processes, and infrastructure being assessed. The legal entity is responsible for ensuring compliance with the certification requirements and maintaining the necessary controls to protect its information assets.
Network infrastructure
Multiple legal entities may be grouped under a single Cyber Essentials certification if they share the same network infrastructure, with a consistency in security policies and operational oversight across the shared infrastructure.
The presence of firewall separation within the network does not automatically require separate certifications. If the firewalls are managed by the same administrative team under the authority of a single legally responsible individual, and the underlying network infrastructure is shared and centrally governed, the legal entities may qualify for a single certification.
However, if the firewalls represent a true separation—such as being managed by different teams or if the legal entities operate under distinct legal or governance structures—separate certifications will be required. The key consideration is whether the network is centrally managed and governed under a unified framework. This approach ensures that shared infrastructure meets the necessary standards while avoiding unnecessary duplication of certification efforts.
Legally responsible person
Legal entities sharing a certificate must have the same legally responsible person (e.g. a director or board member) who can sign off on the assessment for all legal entities within the scope of the certificate.
If legal entities do not share the same legally responsible person, they require separate certifications.
Example: A director cannot sign off on a certificate for a legal entity for which they do not hold legal responsibility. This ensures clear accountability and effective oversight.
Scenarios requiring separate certifications
Legal entities require separate certifications in the following cases:
Different legally responsible persons: If the legal entities do not share the same director or board-level member who can sign off on the assessment.
Different network infrastructure: If the legal entities do not share the same network infrastructure.
Separate legal entities: If the legal entities are separate companies with no shared governance or oversight.
Examples:
Correct: A parent company and its subsidiaries sharing the same network infrastructure and legally responsible person can share a certificate.
Incorrect: Two separate companies sharing office space and network but with different directors cannot share a certificate.
Examples of certification scenarios
Example 1:
Scenario: Joe Bloggs owns three separate companies that run on the same network infrastructure.
Outcome: These companies can share the same certificate because they share the same network infrastructure and legally responsible person.
Example 2:
Scenario: Acme Stationary Supplies owns a subsidiary, Stand Staples, but they run on different networks and infrastructure.
Outcome: These legal entities require separate certifications because they do not share the same network infrastructure.
Example 3:
Scenario: Joe Bloggs and Sam Brown run separate companies from the same office and share the same network.
Outcome: They require separate certifications because they are separate companies with different directors.
Certification process
All legal entities within the scope of a single certification must be included in the assessment process from the beginning, as legal entities cannot be added after the assessment is completed. If individual certificates are needed for included legal entities within a group (these must be listed in Question A1.6.1), they will be invited by email to purchase a separate certificate under their own name for a minimal cost after the main certificate is issued.
For example, a group of companies sharing a network can request individual certificates for each legal entity, but all legal entities must be processed through the assessment together.
Legal entity scope and terminology
Primary legal entity: The legal entity named in Question A1.1, which will appear on the certificate. This organisation is responsible for the assessment and certification process, including the shared IT infrastructure and network.
Included legal entities: Other legal entities included within the scope of the assessment, as listed in Question A1.6.1. These legal entities share the same IT infrastructure and network as the primary legal entity and can request their own certificates under their sole name if needed at a cost of £10 per certificate.
Scope of certification: Refers to the collective IT infrastructure, network, and entities covered by the assessment, including the primary legal entity and any included legal entities.
Example explanation
The primary legal entity is the legal entity named in Question A1.1 and will appear on the certificate. If the scope of the assessment incorporates other included legal entities, these must be listed in Question A1.6.1. While the certificate will primarily reference the primary legal entity, the included legal entities will be listed on the digital certificate and can request separate certificates under their own name for a minimal cost.
Please note: The names of the included legal entities will automatically get added to the Cyber Essentials certificate search and be discoverable in the Cyber Essentials Supply Check Tool regardless of whether or not they apply for their own individual certificate.
