Cyber Essentials

A practical way to check which suppliers hold Cyber Essentials, understand what their certificates cover and follow up where certification is missing.
By Jonathan Krause | Founder, Forensic Control | 16 September 2026
If a supplier looks after your IT, holds your data or provides a service you depend on, it’s worth running a Cyber Essentials supplier check. A certificate gives you a useful starting point for a conversation about security. You also need to know whether it covers the business and systems you rely on.
The government’s September cyber security newsletter, published on 15 September 2026, reported 61,430 certificates awarded in the year to 30 June. It also reported that more than 140 businesses had signed the Cyber Resilience Pledge, which includes commitments on supplier security. Those figures show growing participation, but they won’t tell you which of your own suppliers hold a current certificate.
A supplier’s cyber incident can interrupt your business even if your own systems remain available. The ransomware attack on Blue Yonder in November 2024, for example, disrupted services used by customers including Morrisons and Starbucks. It illustrates why the reliability of an external service matters alongside the security of your own network.
The Cyber Security Breaches Survey 2025/2026 found that 15% of businesses had reviewed the cyber security risks posed by their immediate suppliers in the previous year. Just 6% had reviewed their wider supply chain. These figures describe how many businesses carried out checks; they don’t establish how secure any particular supplier is.
I would start with a simple question: which suppliers would cause us the greatest difficulty if they lost access to their systems, exposed our data or had an account compromised? That gives the review a practical focus.
Under the Pledge declaration, signatories commit to registering for the IASME Supplier Check tool within two months of signing. They also commit to auditing Cyber Essentials coverage across their entire supply chain and discussing the results at board level.
They must take a risk-based approach to requiring certification. This may mean requiring it from every supplier. Where they decide otherwise, the board must be satisfied that the decision fits the organisation’s risk appetite and that adequate assurance is obtained in other ways. The Pledge is voluntary; it does not create a blanket requirement for every UK supplier to certify.
Our earlier article on the Pledge explains what this means for suppliers receiving a request. Buyers have a part to play too, by making the requirement clear.
If I were asking a supplier to certify, I would specify the level required, the business and systems that need to be covered, and the deadline. I would also ask who will manage the work. That gives both sides a clear basis for planning.
Your accounts payable list is a useful starting point. Ask your IT and operations colleagues to add any services it misses, including software subscriptions bought directly by individual teams.
Prioritise suppliers that have access to your systems, hold sensitive information or provide a service you would struggle to operate without. Your IT provider, payroll bureau and hosting company are sensible places to start. A low-cost service with an administrator account may deserve more attention than a supplier with a much larger invoice.
You can begin with a manageable group and work through the rest. A first review of a short list may take an afternoon; checking a whole supply chain and resolving unclear results will take longer.
Use the public IASME certificate search to search by organisation name or certificate number. Record the certificate level, reference and expiry date. If a name search produces no result, ask the supplier for its certificate number before drawing a conclusion.
Check the legal entity and the scope shown on the certificate as well. You need to establish that the certification covers the organisation and systems relevant to the service you buy. Ask the supplier to explain any exclusions or unclear wording.
Keep the result in your supplier register, along with the date you checked, any follow-up action and who is responsible for it. Set a reminder to check renewal before the certificate expires.
For larger lists, the IASME Supplier Check tool supports checking certification across a supply chain. Access requires registration and verification. IASME restricts both tools to their stated certification-checking purposes; they are not marketing databases.
Cyber Essentials is a verified self-assessment against five technical controls. Cyber Essentials Plus adds an independent technical audit, including vulnerability scans and checks on a representative sample of devices. Both levels use the same technical requirements, with Plus providing greater assurance that the controls are in place.
For a supplier with ongoing administrator access to your systems, I would normally ask for Plus and check that its scope is relevant. Certification should sit alongside questions about how access is controlled and what happens if the supplier has an incident. Neither level guarantees that a supplier cannot be breached or that its service will remain available.
First, establish the position. The supplier may be renewing, may hold certification under a different legal name, or may not have started. Ask what it can demonstrate now and what work would be needed to achieve the level you require.
Where certification is appropriate, agree a realistic deadline after that initial review. Timescales depend on the supplier’s setup, any changes needed and assessor availability. The supplier should establish what needs to change before committing to a completion date.
I would agree a named contact and a date to review progress. If a supplier cannot meet the proposed deadline, ask what is preventing it and what can be done in the meantime. Whether you continue using that supplier should depend on the risk to your business and the alternatives available.
For new suppliers and renewals, set out the certification requirement in the procurement process and contract. Be clear about the level, scope, deadline and renewal expectations. Where certification is not required, record the reason and the other evidence you have considered.
Search by name or certificate number in the IASME certificate search. Check the level and expiry date, then confirm that the certificate’s legal entity and scope cover the relevant organisation and systems. If you cannot find a match, ask the supplier for its certificate details.
It is for organisations checking certification within their own supply chain, including large lists of suppliers. You must register and pass IASME’s verification before getting access. The tool’s website explains how to apply.
Not automatically. Signatories commit to a full coverage audit and a risk-based approach to requiring certification. If they do not require it from a supplier, they must obtain adequate assurance through other means, with the board satisfied that the decision fits their risk appetite. See the Pledge declaration.
The September 2026 government newsletter reports 61,430 certificates awarded in the year to 30 June 2026: 46,245 at Cyber Essentials level and 15,185 at Cyber Essentials Plus. These are certificate counts, not a count of distinct businesses.
Choose the level according to the access, data and services involved. Plus adds independent technical testing to the verified self-assessment. I would normally ask for Plus where a supplier has ongoing administrator access, alongside other checks relevant to the service.
It depends on readiness. A supplier may need to address unsupported software, security updates or account settings before assessment. Ask a certification body for a timetable based on the actual setup. IASME states that the Cyber Essentials Plus audit can be completed within three months of the Cyber Essentials certification.
Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.