Skip to content
All posts

Cyber Essentials and Government Contracts: What UK Suppliers Need to Know

Under Procurement Policy Note 014 (PPN 014), UK government and NHS buyers must require suppliers to meet Cyber Essentials-level technical security controls whenever a contract handles personal data, OFFICIAL-level systems, or other risk-flagged work. This is normally satisfied by holding Cyber Essentials or Cyber Essentials Plus certification, or by demonstrating independently verified equivalent controls.

If you sell into central government, the NHS, or the wider public sector, you have probably already been asked the question: do you hold Cyber Essentials? Increasingly, the answer needs to be yes before you can even be considered for a tender, let alone win one.

This has been government policy since 2014, but the rules have tightened, not loosened, over time, most recently with significant changes to the Cyber Essentials scheme in April 2026. Here is what suppliers actually need to know.

The Policy Behind the Requirement

Cyber Essentials became part of UK government procurement to manage cyber security risk in the public sector supply chain. The current version of this policy is set out in Procurement Policy Note 014 (PPN 014), issued by the Cabinet Office, which applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies.

The rule is straightforward in principle: in-scope organisations must ensure suppliers demonstrate either Cyber Essentials or Cyber Essentials Plus certification, or equivalent controls, wherever a contract carries certain risk characteristics.

When Certification Is Required

PPN 014 sets out the contract characteristics that trigger the requirement. It applies where:

  • Personal information of citizens (addresses, bank details, payment information) is handled by the supplier
  • Personal information of government employees, ministers, or special advisors is handled (payroll, travel, expenses)
  • ICT systems or services are supplied that store or process data at the OFFICIAL level of the Government Security Classifications Policy
  • The contract deals with the day-to-day business of government, service delivery, public finances, criminal justice, defence, security and resilience, or commercial interests including confidential information and intellectual property

In practice, this covers a wide range of contracts: contact centre and CV-writing services handling citizens' personal data, car hire services for civil servants, IT managed service providers, and professional services firms handling anything above "Official" classification data. It also explicitly covers most NHS service delivery, given NHS bodies sit within PPN 014's scope.

Government guidance is equally clear about where it should not apply. Low-risk, low-data contracts, a sole trader delivering driving lessons to ten people, for example, should not be burdened with a Cyber Essentials requirement that is disproportionate to the actual risk. Buyers are explicitly told not to take a blanket approach.

Cyber Essentials or Cyber Essentials Plus?

The two tiers matter, and buyers are expected to choose the right one for the risk involved:

  • Cyber Essentials is a self-assessed questionnaire, verified by an independent certification body. It offers a basic level of assurance and is the default expectation for most in-scope contracts.
  • Cyber Essentials Plus adds independent, hands-on technical verification, remote and on-site vulnerability testing that checks the controls actually work. It is expected for higher-risk contracts, access to government systems or networks, or work involving OFFICIAL-SENSITIVE data.

If a supplier does not hold either certificate, they must be able to demonstrate equivalent controls, normally verified by a technically competent, independent third party, self-declaration alone is not accepted, particularly for the Plus-equivalent standard.

What Changed in April 2026

The Cyber Essentials scheme itself was updated, with changes taking effect from 27 April 2026 (the "Danzell" version, replacing "Willow"). If your assessment account was created before that date, you can still complete it under the previous version until 27 October 2026, after which any outstanding assessment must restart under the new requirements. The key tightening points are:

  • Multi-factor authentication is now mandatory for all cloud services where it is available, not just for administrator accounts. Organisations that fail to implement MFA for cloud services will automatically fail the assessment.
  • No excluding cloud services from scope. The definition of what counts as a cloud service has been clarified, and if your organisation's data or services are hosted in the cloud, that infrastructure must be included in the assessment, this closes a loophole some suppliers previously used to keep cloud systems out of scope.
  • Scoping language has been tightened elsewhere too, including the removal of qualifiers like "untrusted" and "user-initiated" that some suppliers had previously leaned on to narrow their assessment boundary, and a renaming of the "home working" and "web application" categories to reflect how organisations actually work today.

Separately from the April 2026 changes, it's worth remembering that Cyber Essentials has long required critical and high-severity security updates to be applied within 14 days across all in-scope devices, including firmware on routers, firewalls, and managed switches. This is not new for 2026, but it remains one of the most common reasons suppliers fail on reassessment, so it is worth checking alongside the newer cloud and scoping changes above.

For suppliers who have previously certified under looser scoping rules, this is worth treating as a genuine gap analysis exercise, not a rubber-stamp renewal.

When You Need to Have It in Place

Evidence of Cyber Essentials, basic or Plus, is required before contract award, and applicable requirements must be specified in the tender notice itself. Buyers are encouraged to flag the requirement even earlier, at the preliminary market engagement stage, to give suppliers the longest possible runway to certify.

Once certified, Cyber Essentials must be renewed every 12 months for the life of the contract. A lapsed certificate mid-contract is a compliance failure, not a paperwork inconvenience.

Cost and Timeline

Cyber Essentials (basic) typically costs from around £300–£500+VAT depending on organisation size, while Cyber Essentials Plus is priced according to the size and complexity of your network, given the additional independent audit involved. Realistically, you should start the certification process at least three months ahead of when you expect to need it, longer if you have significant remediation to do first, particularly under the tightened 2026 requirements.

Beyond the Bid: Why It's Worth Doing Anyway

Even where a specific contract does not mandate it, Cyber Essentials is increasingly treated as table stakes for credibility in public sector procurement, and it carries real commercial value beyond the tender itself, including cyber liability insurance of up to £25,000 for smaller organisations that certify their whole business. If you are actively pursuing government, NHS, or defence-adjacent work, getting certified ahead of a live procurement, rather than in reaction to one, puts you ahead of competitors who are still scrambling when the requirement lands in a tender document.

Frequently Asked Questions

Do all government contracts require Cyber Essentials?

No. PPN 014 only requires buyers to impose Cyber Essentials-level technical security controls where a contract carries certain risk characteristics, handling citizens' or government employees' personal data, ICT systems processing OFFICIAL-level data, or work touching public finances, criminal justice, defence, or confidential commercial information. Low-risk, low-data contracts shouldn't be burdened with the requirement.

Is it mandatory to hold a Cyber Essentials certificate for these contracts?

Not strictly. PPN 014 makes it mandatory for in-scope buyers to require suppliers to meet Cyber Essentials-level controls on qualifying contracts, and holding a Cyber Essentials or Cyber Essentials Plus certificate is the standard way to satisfy that. But a supplier can instead demonstrate equivalent controls, normally verified by an independent, technically competent third party — self-declaration alone isn't accepted.

Cyber Essentials or Cyber Essentials Plus — which do I need?

Standard Cyber Essentials is the default expectation for most in-scope contracts. Cyber Essentials Plus is expected for higher-risk contracts, access to government systems or networks, or work involving OFFICIAL-SENSITIVE data.

When do I need to have Cyber Essentials in place by?

Evidence of certification, or of equivalent controls, is required before contract award, and the requirement should be stated in the tender notice itself. Buyers are encouraged to flag it even earlier, at the preliminary market engagement stage, so start certifying well before you expect to bid.

What changed in the Cyber Essentials scheme in April 2026?

MFA became a mandatory, auto-fail requirement for all cloud services where it's available, the definition of in-scope cloud services was tightened so none can be excluded, and scoping language was clarified to remove loopholes some suppliers used to narrow their assessment boundary.

How much does Cyber Essentials cost, and how long does it take?

Cyber Essentials (basic) typically costs from around £300–£500+VAT depending on organisation size; Cyber Essentials Plus is priced by company size and complexity. Start the process at least three months ahead of when you need it, longer if you have remediation work to do.

How Periculo Helps

We support suppliers across government, NHS, and defence supply chains with:

  • Cyber Essentials and Cyber Essentials Plus certification, scoped correctly to your contract requirements
  • Gap analysis against the 2026 scheme changes for organisations recertifying under the new rules
  • CREST-accredited penetration testing where higher-assurance evidence is needed
  • Ongoing managed assurance, so certification renewal never becomes a risk to a live contract

Contact Us