A tender lands on a Tuesday morning, forty-odd pages long, and somewhere around page fourteen sits a single line: “Supplier must hold Cyber Essentials or demonstrate equivalent controls.” No explanation. No hand-holding. Just a cyber essentials requirement in tender paperwork that could, if you get it wrong, cost you the contract before you’ve even priced the job.
If you bid for council work, NHS contracts or anything on a government framework, you’ve probably met this before. Sometimes it’s a plain tender clause. Sometimes it hides inside a cyber essentials PQQ, or its newer relative the PSQ, under a heading like “technical and professional ability”. Either way, the buyer is asking one blunt question: can we trust you with our data? This article covers what buyers genuinely check when that question appears in your bid, and what to do about it before submission day, not after.
Where a Cyber Essentials requirement in a tender comes from
Most of this traces back to PPN 014: Cyber Essentials scheme, the Cabinet Office’s procurement policy note updated in February 2025. It replaced two earlier notes, PPN 09/14 and PPN 09/23, and it tells central government departments, executive agencies, non-departmental public bodies and NHS bodies when to ask suppliers for Cyber Essentials.
It applies where a contract touches citizens’ personal information, staff personal data (payroll, travel, expenses), ICT systems built to store or process data at OFFICIAL level, or information tied to day-to-day government business and public finances. That covers plenty of ordinary contracts that have nothing obviously “cyber” about them.
It is not a blanket rule, though. The PPN tells buyers to be proportionate and to avoid shutting SMEs out unnecessarily. A sole trader whose IT use is minimal and incidental to the contract probably won’t see this requirement at all. The honest answer to the question “will my tender need Cyber Essentials?” is: it depends on the contract. Always read the actual documents rather than assume.
Cyber Essentials PQQ and PSQ: same tender prequalification question, new name
Here is where procurement does what procurement does best: renames things. PQQ, pre-qualification questionnaire, is the term most bid writers grew up with. For procurements started on or after 24 February 2025, under the Procurement Act 2023, the equivalent document is the Procurement Specific Questionnaire, or PSQ. And what used to be called selection criteria are now “conditions of participation”.
Functionally, it is the same tender prequalification exercise with a new badge. You will still find a cyber essentials PQQ question, or its PSQ descendant, tucked into a section asking about your technical ability to deliver the contract safely. It usually reads something close to “does the supplier hold Cyber Essentials or Cyber Essentials Plus, or can it demonstrate equivalent controls?”. Expect both terms, PQQ and PSQ, to keep circulating for a while yet. Buyers and bid portals are not always quick to update their templates.
Who asks, and how hard: central government, NHS, MoD and councils
Not every buyer applies this the same way, and that matters more than most guidance admits.
Central government departments, executive agencies and non-departmental public bodies are directly bound by PPN 014. If the contract fits the criteria above, expect the question.
NHS bodies lean on Cyber Essentials too, often alongside the Data Security and Protection Toolkit, which covers a wider set of data handling obligations. The two tend to turn up together in NHS tenders.
The Ministry of Defence frequently asks for the higher tier, Cyber Essentials Plus, or a defence-specific scheme, particularly on supply chain work. “Frequently” is the right word here, not “always”: check the specific MoD tender rather than assume Plus is a given.
Councils sit outside PPN 014 altogether. They are not bound by it. In practice, though, many councils ask for Cyber Essentials in ITTs covering IT, data, finance or anything touching citizen information, because it is a sensible, recognisable bar to set. We’ve covered the basics of who needs Cyber Essentials to win government contracts in more detail elsewhere, but the short version for all four buyer types is the same: check the tender.
What buyers actually check when they see a Cyber Essentials requirement in your tender
This is the bit most suppliers skip past, and it is the bit that decides whether your bid stands up.
Drawing from what PPN 014 asks buyers to do, here is roughly what gets looked at when a cyber essentials requirement in tender evaluation lands on an assessor’s desk:
- Does the certificate exist and is it current? Buyers can check this themselves on the IASME certificate search, so don’t assume a vague claim will pass unnoticed.
- Does the level match what was asked for? Basic Cyber Essentials is not Cyber Essentials Plus, and bidding with the wrong tier is a common, avoidable mistake.
- Does the certified entity match the entity actually bidding? Group structures and trading names trip people up here more than you’d think.
- Does the certificate’s scope cover the systems that will touch the buyer’s data? A certificate can legitimately cover only part of an organisation. The PPN specifically tells buyers to check this rather than take it on trust. Scope never extends to third parties, such as a cloud provider you rely on.
- If you are claiming “equivalent controls” instead of certification, is that backed by independent, technically competent verification, or is it just you saying so?
Buyers are instructed to accept equivalent controls under the Procurement Act 2023. What they are not told to do is accept your word for it. Evidence has to satisfy them, and that normally means independent, third party verification, which is mandatory for Cyber Essentials Plus in any case.
Would your ISO 27001 certificate cover this instead? Nice idea, but no. ISO 27001 is shallower on the five technical controls. They are not normally all in scope or tested the way Cyber Essentials tests them. Plenty of ISO-certified firms still need Cyber Essentials separately, or must demonstrate equivalence properly.
Cyber Essentials or Plus: which tier does tender prequalification usually ask for?
Basic Cyber Essentials is a verified self-assessment. You answer questions about the five controls (firewalls, secure configuration, user access control, malware protection and patching), a board member signs off the answers, and an assessor marks it.
Cyber Essentials Plus adds hands-on technical testing, remote and on-site vulnerability checks against those same five controls. For the full detail on how the two tiers actually differ, the NCSC’s Cyber Essentials overview is the primary reference.
So which tier should you expect, Basic or Plus? Tenders tend to ask for Plus on higher value or higher sensitivity work, defence supply chains being a familiar example. For most ordinary public sector contracts, basic certification is what gets asked for. Check the wording of your specific tender prequalification question before assuming either way. And when in doubt, ask the buyer directly.
Timing: why “we’ll sort it if we win” is a bad plan
Certification is not instant. Getting the five controls genuinely in order, then booking an assessment, then waiting for the result, takes weeks rather than days, especially if your IT estate has drifted.
Evidence of certification, or an accepted equivalent, is normally required before contract award, and in all cases by the point data gets passed to you. Some buyers will allow a contract to start while a lapsed certificate is being renewed, but the PPN frames that as an exceptional, risk-based decision, not a fallback plan.
And then there is renewal. Certification runs for twelve months, and it has to be renewed for the life of the contract. Stop patching, stop managing configuration properly, and you can fall out of compliance well inside that year. “We’ll sort it later” is how companies lose contracts they were otherwise well placed to win. The full process is worth understanding before you need it. Which is why we keep a plain-English rundown on our Cyber Essentials certification page.
Would you pass Cyber Essentials? Find out before the buyer asks
So, would you actually pass if someone checked today? Most businesses genuinely do not know, and that is the uncomfortable bit nobody puts on page fourteen of the tender.
Your IT Department runs a free thirty minute Would You Pass Cyber Essentials? readiness review with a qualified assessor. We look at where you stand against the five controls, tell you honestly what would fail and what is fine, and send a written summary. There is no obligation to proceed with us afterwards.
The usual stumbling points are predictable rather than dramatic. Gaps in multi-factor authentication, software that has gone unsupported, patching nobody can actually evidence when asked. None of that is a crisis if you catch it before a buyer does.
A cyber essentials requirement in a tender, or a cyber essentials PQQ question you cannot answer confidently, does not have to be the thing that sinks your bid. Book the review, get the honest answer, and decide what to do about it on your own schedule rather than the buyer’s. The buyer certainly won’t wait for you to work it out mid-evaluation.