Cyber Essentials

Cyber Essentials for government contracts

Cyber Essentials is the certification that central government, its agencies and NHS bodies ask suppliers to hold on contracts involving personal data, OFFICIAL information or ICT services. This page explains when it applies, which level a buyer can ask for, and how to evidence it before award.

PPN 014 sets when a buyer can ask for Cyber Essentials

Procurement Policy Note (PPN) 014 is the Cabinet Office’s standing instruction on Cyber Essentials in public procurement. It was updated in February 2025 to sit under the Procurement Act 2023, and it replaced PPN 09/14 and PPN 09/23 for procurements starting on or after 24 February 2025. It binds central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. Local authorities are not bound by it, although many choose to mirror it.

The note names four situations in which a buyer should ask for Cyber Essentials or Cyber Essentials Plus: where a supplier handles the personal information of citizens, such as home addresses, bank details or payment information; where a supplier handles the personal information of government employees, ministers and special advisers; where the contract supplies information and communications technology (ICT) systems or services designed to store or process data at the OFFICIAL level; and where the contract deals with information about the day-to-day business of government, service delivery and public finances.

The same note is clear about its limits. It says the scheme should not be applied to all contracts as a matter of course and that in-scope organisations must not take a blanket approach. Where certification is asked for, a supplier has to demonstrate it before the contract is awarded, and a supplier that does not hold it must be able to show that equivalent controls are in place. Holding the certificate is the simpler of those two routes, and it is the one buyers are set up to check.

Where the requirement shows up

Four kinds of buyer ask for the same certificate, and each one words the requirement differently.
Government building icon representing central government departments and agencies

Central government

PPN 014 applies directly to departments, executive agencies and non-departmental public bodies. Cyber Essentials or Plus is named as a condition of participation on in-scope contracts.

Signed agreement icon representing framework and call-off contract terms

Government frameworks

Framework agreements such as G-Cloud carry their own conditions on top of PPN 014. The current G-Cloud framework recommends Cyber Essentials, and a buyer can require it or Plus at call-off.

Hospital icon representing NHS bodies and NHS Supply Chain suppliers

NHS

NHS bodies are in scope of PPN 014. NHS Supply Chain expects Cyber Essentials Plus from in-scope suppliers, with a security questionnaire as the route where it is not held. Suppliers handling patient data also complete the Data Security and Protection Toolkit.

Civic buildings icon representing local councils and their own tender conditions

Local authorities

Outside PPN 014, so there is no central mandate. Councils set their own conditions of participation and most mirror the PPN. The tender documents are the only place to check

Cyber Essentials or Plus depends on the contract, not the supplier

PPN 014 leaves the choice of level to the buyer’s own risk assessment, so the same supplier can be asked for Cyber Essentials on one contract and Cyber Essentials Plus on the next. The tender usually states it as a condition of participation, in wording along the lines of a valid Cyber Essentials Plus certificate held at the point of award, and the level tends to rise with the sensitivity of the data and the value of the contract.

Cyber Essentials is a verified self-assessment and is renewed every twelve months. Cyber Essentials Plus adds an independent technical audit of the systems in scope, which is why hosting lots and contracts involving patient or citizen data tend to ask for it. The cost difference between the two is set out in our Plus cost guide, and any IASME licensed certification body can issue either certificate.

What to do when a tender asks for a certificate you do not hold

Five steps, in the order that saves the most time.

1
Read the condition of participation
Find the exact wording, the level asked for, and whether it is required at submission, at award or within a grace period.
2
Fix the scope before anything else
Whole organisation or the part delivering the contract. Scope drives cost, time and whether the certificate covers what the buyer will check.
3
Close the gaps that fail assessments
Multi-factor authentication, unsupported software and unpatched devices are the usual reasons a first submission fails.
4
Certify at the right level
Self-assessment for Cyber Essentials, with the independent technical audit on top for Plus. Our assessment process guide explains what happens after you submit.
5
Build the evidence pack
Certificate, scope statement, renewal date and your entry on the IASME certified organisations list, plus the same for any in-scope subcontractor.
Forensic Control logo

“The Cyber Essentials Scheme should not be applied to all contracts as a matter of course. In-scope organisations must not take a blanket approach.”

Cabinet Office
Procurement Policy Note 014, Cyber Essentials Scheme

Frequently asked questions

Is Cyber Essentials mandatory for all government contracts?
Does a local council have to ask for Cyber Essentials?
Can we bid with ISO 27001 instead of Cyber Essentials?
Do our subcontractors need Cyber Essentials too?
Which certification body do government buyers recognise?
How long before a tender deadline should we start?

Talk to an assessor before the tender closes

We are an IASME Certification Body and certify suppliers remotely across the UK. Bring the tender wording and we will tell you what it needs.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.