UK Cyber Essentials for non-UK businesses

Working with UK central government, the MoD, the NHS, or a UK enterprise client? Cyber Essentials certification is open to organisations of any size, in any country. We guide non-UK businesses through the full process remotely, from scope to certificate.
Non-UK business looking for Cyber Essentials Certification Support

Yes, non-UK organisations can be certified

Cyber Essentials is open to organisations of any size, in any country. There is no requirement to be UK-registered or to have a UK office. The certificate is issued in your organisation’s legal name and is identical in standing to one issued to a UK company.

That includes you if your organisation is headquartered in the United States, Ireland, the EU, Australia, New Zealand, Canada, India, or anywhere else.

This is the UK government’s Cyber Essentials scheme. Administered by IASME on behalf of the National Cyber Security Centre (NCSC), it is the certification required by UK central government, the Ministry of Defence, the NHS, and a growing number of UK private-sector buyers. It is a separate scheme from CISA’s Cyber Essentials guidance, which is a US framework with the same name but no certification component and no recognition in UK procurement. If a UK contract or buyer has asked you for “Cyber Essentials”, they mean the UK scheme.

Forensic Control is an authorised IASME Certification Body and has guided organisations across more than 30 countries through the certification process since 2017.

When non-UK organisations need Cyber Essentials

Four situations bring overseas businesses to us. The requirement applies to the supplier, regardless of where the supplier is headquartered.

UK central government contracts

Mandatory for any supplier bidding on contracts involving personal data or IT products and services, since October 2014 under PPN 09/14 (updated by PPN 01/24). Without a valid certificate, your bid will not be considered.

MoD and defence supply chain

Required for all Ministry of Defence contracts involving sensitive data or IT services, since January 2016. Applies to tier-2 and tier-3 international suppliers. Some contracts specify Cyber Essentials Plus.

NHS and UK public sector

Increasingly required by NHS procurement frameworks and UK public sector bodies as a baseline supplier requirement. CE Plus is often specified for contracts involving patient data.

UK private sector requirements

UK-headquartered prime contractors, financial institutions, insurers, and enterprise buyers increasingly require Cyber Essentials from their suppliers, regardless of where the supplier is based.

Common scenarios by region

We have certified organisations across the wrold. The questions we hear vary by region, but the eligibility and the process are the same wherever you are.

United States

US firms supplying UK MoD, central government, or NHS contracts. Common questions: how this differs from CISA's Cyber Essentials guidance, and how it sits alongside SOC 2.

Ireland and EU

Irish, Dutch, German, and French organisations trading into the UK supply chain. Common question: whether ISO 27001 or NIS2 compliance substitutes for Cyber Essentials in UK procurement (it does not).

Australia and New Zealand

Defence and government suppliers operating in both ANZ and UK markets. Common question: how Cyber Essentials maps to the Australian Essential Eight Maturity Model.

Canada

Canadian firms supplying UK government, defence, or financial-sector clients. Common question: whether Cyber Essentials is recognised by Canadian procurement (it is not, but it is recognised by UK procurement when the contract is UK-based).

India

Indian IT services firms and offshore development centres bidding for UK government or enterprise contracts. Common question: how to confirm a certification body is legitimately authorised by IASME.

Rest of world

Norway, Singapore, the UAE, South Africa, and beyond. Wherever a UK contract has asked you for Cyber Essentials, the same process applies. We work remotely across all time zones.

How the process works for non-UK organisations

The certification process is the same as for UK-based organisations and is fully remote. No UK office, no on-site visit, no travel required.

1
Introductory call
A 30-minute call with a senior assessor confirms scope, the level required (Basic or Plus), and timeline. Held in your time zone.
2
Define scope
For organisations with infrastructure in multiple countries, defining scope correctly is the most important step and the most common point of confusion. We work through it with you before you begin the questionnaire.
3
Complete the self-assessment
The IASME online questionnaire covers five technical control areas: firewalls, secure configuration, user access controls, malware protection, and patch management. We provide guidance throughout. Most organisations complete it in 1–2 days.
4
Assessment and certificate
Our IASME-accredited assessor reviews your submission and issues the Cyber Essentials Basic certificate. Most organisations receive their certificate within 2–5 working days of a complete submission. Resubmissions are included at no extra cost.
5
Cyber Essentials Plus audit (if required)
Cyber Essentials Plus is a separate certification that adds a remote technical audit. It includes internal vulnerability scanning and workstation checks, conducted without an on-site visit. The Plus audit typically takes 3–5 working days.

Defining scope across borders

Scope is the set of devices, users, and services covered by your certificate. For organisations with infrastructure in multiple countries, getting scope right at the outset is the single most important decision in the certification process.

A common pattern: a US-headquartered company has a UK subsidiary or a UK-facing product, and only that part of the business needs to be certified for the contract in question. We will help you decide whether to scope the whole organisation or a clearly defined subset, and we will document the scope boundary in a way that holds up under procurement scrutiny.

Under Cyber Essentials v3.3 (in force from 27 April 2026), any device that connects to the internet, in either direction, is in scope within the boundary you define. Cloud services used to store or process business data cannot be excluded.

We have run this scoping conversation with organisations from Boston to Bangalore. It usually takes 15 minutes of an introductory call to land the right answer.

Image placeholder

How Cyber Essentials sits alongside other frameworks

Cyber Essentials does not replace SOC 2, ISO 27001, NIS2, or the Australian Essential Eight. UK procurement teams do not accept any of those as a substitute for Cyber Essentials. Here is how the most relevant frameworks compare.

UK Cyber Essentials

Government-backed scheme administered by IASME on behalf of the NCSC. Required for UK public-sector contracts. Annual renewal. The page you are reading.

SOC 2

AICPA framework for service organisations. Annual audit by a CPA firm. Standard for US enterprise procurement. Not recognised by UK government procurement.

ISO 27001

International information security management standard. Useful internationally but does not, by itself, satisfy UK Cyber Essentials requirements for public-sector procurement.

EU NIS2 directive

EU-wide cyber security regulation for essential and important entities. Imposes operational obligations, not a certification. Does not substitute for UK Cyber Essentials in UK contracts.

Australian Essential Eight

Australian Cyber Security Centre baseline mitigations. Maturity model rather than a certification. Distinct from Cyber Essentials, though several controls overlap.

FedRAMP and CMMC

US federal frameworks for cloud services (FedRAMP) and defence contractors (CMMC). Required for US federal contracts. Separate from and not recognised by UK procurement.

Frequently asked questions

Questions we hear from non-UK buyers, with the answers we give.
Is this the UK Cyber Essentials scheme, or the CISA Cyber Essentials?
Can a non-UK company actually get UK Cyber Essentials certified?
How long does Cyber Essentials take for a non-UK company?
Is the Cyber Essentials Plus audit done remotely for non-UK clients?
How does UK Cyber Essentials relate to SOC 2 or ISO 27001?
Can EU companies get UK Cyber Essentials certified?
How does Cyber Essentials compare to the Australian Essential Eight?
How do we verify that a Cyber Essentials certification body is legitimate?

Ready to start? Book a call with a senior assessor.

Tell us about your contract and we will confirm the level of certification you need, define scope for your infrastructure, and walk you through the timeline. Calls held in your time zone where possible - select your time-zone from the Calendly menu to find a suitable slot.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.