Central government
PPN 014 applies directly to departments, executive agencies and non-departmental public bodies. Cyber Essentials or Plus is named as a condition of participation on in-scope contracts.
Procurement Policy Note (PPN) 014 is the Cabinet Office’s standing instruction on Cyber Essentials in public procurement. It was updated in February 2025 to sit under the Procurement Act 2023, and it replaced PPN 09/14 and PPN 09/23 for procurements starting on or after 24 February 2025. It binds central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. Local authorities are not bound by it, although many choose to mirror it.
The note names four situations in which a buyer should ask for Cyber Essentials or Cyber Essentials Plus: where a supplier handles the personal information of citizens, such as home addresses, bank details or payment information; where a supplier handles the personal information of government employees, ministers and special advisers; where the contract supplies information and communications technology (ICT) systems or services designed to store or process data at the OFFICIAL level; and where the contract deals with information about the day-to-day business of government, service delivery and public finances.
The same note is clear about its limits. It says the scheme should not be applied to all contracts as a matter of course and that in-scope organisations must not take a blanket approach. Where certification is asked for, a supplier has to demonstrate it before the contract is awarded, and a supplier that does not hold it must be able to show that equivalent controls are in place. Holding the certificate is the simpler of those two routes, and it is the one buyers are set up to check.
PPN 014 leaves the choice of level to the buyer’s own risk assessment, so the same supplier can be asked for Cyber Essentials on one contract and Cyber Essentials Plus on the next. The tender usually states it as a condition of participation, in wording along the lines of a valid Cyber Essentials Plus certificate held at the point of award, and the level tends to rise with the sensitivity of the data and the value of the contract.
Cyber Essentials is a verified self-assessment and is renewed every twelve months. Cyber Essentials Plus adds an independent technical audit of the systems in scope, which is why hosting lots and contracts involving patient or citizen data tend to ask for it. The cost difference between the two is set out in our Plus cost guide, and any IASME licensed certification body can issue either certificate.
Five steps, in the order that saves the most time.
“The Cyber Essentials Scheme should not be applied to all contracts as a matter of course. In-scope organisations must not take a blanket approach.”
We are an IASME Certification Body and certify suppliers remotely across the UK. Bring the tender wording and we will tell you what it needs.