Under Procurement Policy Note 014 (PPN 014), UK government and NHS buyers must require suppliers to meet Cyber Essentials-level technical security controls whenever a contract handles personal data, OFFICIAL-level systems, or other risk-flagged work. This is normally satisfied by holding Cyber Essentials or Cyber Essentials Plus certification, or by demonstrating independently verified equivalent controls.
If you sell into central government, the NHS, or the wider public sector, you have probably already been asked the question: do you hold Cyber Essentials? Increasingly, the answer needs to be yes before you can even be considered for a tender, let alone win one.
This has been government policy since 2014, but the rules have tightened, not loosened, over time, most recently with significant changes to the Cyber Essentials scheme in April 2026. Here is what suppliers actually need to know.
Cyber Essentials became part of UK government procurement to manage cyber security risk in the public sector supply chain. The current version of this policy is set out in Procurement Policy Note 014 (PPN 014), issued by the Cabinet Office, which applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies.
The rule is straightforward in principle: in-scope organisations must ensure suppliers demonstrate either Cyber Essentials or Cyber Essentials Plus certification, or equivalent controls, wherever a contract carries certain risk characteristics.
PPN 014 sets out the contract characteristics that trigger the requirement. It applies where:
In practice, this covers a wide range of contracts: contact centre and CV-writing services handling citizens' personal data, car hire services for civil servants, IT managed service providers, and professional services firms handling anything above "Official" classification data. It also explicitly covers most NHS service delivery, given NHS bodies sit within PPN 014's scope.
Government guidance is equally clear about where it should not apply. Low-risk, low-data contracts, a sole trader delivering driving lessons to ten people, for example, should not be burdened with a Cyber Essentials requirement that is disproportionate to the actual risk. Buyers are explicitly told not to take a blanket approach.
The two tiers matter, and buyers are expected to choose the right one for the risk involved:
If a supplier does not hold either certificate, they must be able to demonstrate equivalent controls, normally verified by a technically competent, independent third party, self-declaration alone is not accepted, particularly for the Plus-equivalent standard.
The Cyber Essentials scheme itself was updated, with changes taking effect from 27 April 2026 (the "Danzell" version, replacing "Willow"). If your assessment account was created before that date, you can still complete it under the previous version until 27 October 2026, after which any outstanding assessment must restart under the new requirements. The key tightening points are:
Separately from the April 2026 changes, it's worth remembering that Cyber Essentials has long required critical and high-severity security updates to be applied within 14 days across all in-scope devices, including firmware on routers, firewalls, and managed switches. This is not new for 2026, but it remains one of the most common reasons suppliers fail on reassessment, so it is worth checking alongside the newer cloud and scoping changes above.
For suppliers who have previously certified under looser scoping rules, this is worth treating as a genuine gap analysis exercise, not a rubber-stamp renewal.
Evidence of Cyber Essentials, basic or Plus, is required before contract award, and applicable requirements must be specified in the tender notice itself. Buyers are encouraged to flag the requirement even earlier, at the preliminary market engagement stage, to give suppliers the longest possible runway to certify.
Once certified, Cyber Essentials must be renewed every 12 months for the life of the contract. A lapsed certificate mid-contract is a compliance failure, not a paperwork inconvenience.
Cyber Essentials (basic) typically costs from around £300–£500+VAT depending on organisation size, while Cyber Essentials Plus is priced according to the size and complexity of your network, given the additional independent audit involved. Realistically, you should start the certification process at least three months ahead of when you expect to need it, longer if you have significant remediation to do first, particularly under the tightened 2026 requirements.
Even where a specific contract does not mandate it, Cyber Essentials is increasingly treated as table stakes for credibility in public sector procurement, and it carries real commercial value beyond the tender itself, including cyber liability insurance of up to £25,000 for smaller organisations that certify their whole business. If you are actively pursuing government, NHS, or defence-adjacent work, getting certified ahead of a live procurement, rather than in reaction to one, puts you ahead of competitors who are still scrambling when the requirement lands in a tender document.
No. PPN 014 only requires buyers to impose Cyber Essentials-level technical security controls where a contract carries certain risk characteristics, handling citizens' or government employees' personal data, ICT systems processing OFFICIAL-level data, or work touching public finances, criminal justice, defence, or confidential commercial information. Low-risk, low-data contracts shouldn't be burdened with the requirement.
Not strictly. PPN 014 makes it mandatory for in-scope buyers to require suppliers to meet Cyber Essentials-level controls on qualifying contracts, and holding a Cyber Essentials or Cyber Essentials Plus certificate is the standard way to satisfy that. But a supplier can instead demonstrate equivalent controls, normally verified by an independent, technically competent third party — self-declaration alone isn't accepted.
Standard Cyber Essentials is the default expectation for most in-scope contracts. Cyber Essentials Plus is expected for higher-risk contracts, access to government systems or networks, or work involving OFFICIAL-SENSITIVE data.
Evidence of certification, or of equivalent controls, is required before contract award, and the requirement should be stated in the tender notice itself. Buyers are encouraged to flag it even earlier, at the preliminary market engagement stage, so start certifying well before you expect to bid.
MFA became a mandatory, auto-fail requirement for all cloud services where it's available, the definition of in-scope cloud services was tightened so none can be excluded, and scoping language was clarified to remove loopholes some suppliers used to narrow their assessment boundary.
Cyber Essentials (basic) typically costs from around £300–£500+VAT depending on organisation size; Cyber Essentials Plus is priced by company size and complexity. Start the process at least three months ahead of when you need it, longer if you have remediation work to do.
We support suppliers across government, NHS, and defence supply chains with: