Your IT Department

Do you need Cyber Essentials to win government contracts?

Short answer: often, yes. Not always, and not for everything, but if you’re bidding for UK public sector work there’s a good chance Cyber Essentials certification will appear somewhere in the tender paperwork. The honest answer to “do I need Cyber Essentials for government contracts” is that it depends on what the contract involves, and the only way to know for certain is to read the documents in front of you.

That’s not a very satisfying answer, though. So let’s break down when it’s required, when it isn’t, and what councils, the NHS and the MoD actually ask for.

When central government requires it

Since 2014, central government has required suppliers to hold Cyber Essentials certification for certain contracts. The rules live in a Procurement Policy Note, which is the Cabinet Office’s way of telling departments what to build into their tenders. The current version is PPN 014: Cyber Essentials scheme, updated in February 2025 to sit under the Procurement Act 2023. It replaced the earlier PPN 09/14 and PPN 09/23, so if you’ve seen those referenced in older guidance, they’ve been superseded.

PPN 014 applies to central government departments, their executive agencies, non-departmental public bodies and NHS bodies. It requires Cyber Essentials or Cyber Essentials Plus certification (or equivalent controls) where a contract involves any of the following:

  • Personal data of citizens or staff
  • ICT systems and services that support those systems
  • Cyber security services themselves

It’s not a blanket rule. A contract to supply stationery won’t ask for it. A contract handling patient records or running government IT absolutely will. The principle is proportionality: the more sensitive the data and systems involved, the more likely certification becomes mandatory. And

One detail worth knowing: suppliers must maintain certification annually for the duration of the contract. It’s not a one-and-done box tick to win the bid. Let it lapse mid-contract and you’ve got a compliance problem.

Cyber Essentials for council contracts

Local councils are a different story, and this is where people get caught out. Councils are not bound by PPN 014. They set their own procurement rules and risk thresholds, which means there’s no universal mandate across local government.

In practice, though, plenty of councils ask for it anyway. Whether there is a requirement for Cyber Essentials for council contracts comes down to the specific tender or Invitation to Tender, and the requirement scales with what’s at stake. A small supplies contract might not mention it. An IT services contract, anything touching citizen data, or work involving council finances very likely will, and larger or higher-risk contracts may specify Cyber Essentials Plus rather than the standard level.

The same pattern shows up across the wider public sector. NHS trusts lean on the Data Security and Protection Toolkit, which expects Cyber Essentials under the hood. Universities increasingly list it in framework applications. And the MoD is the strictest of the lot: any work touching defence information comes with firm certification requirements, frequently stepping up to Cyber Essentials Plus or the defence-specific schemes.

The practical takeaway: never assume. Check the tender documents, and if the wording is ambiguous, ask the buyer before you bid rather than discovering the requirement at evaluation stage.

Cyber Essentials or Cyber Essentials Plus?

The two are separate certifications, and buyers are usually specific about which one they want.

Cyber Essentials is a self-assessment against five control areas: firewalls, secure configuration, user access control, malware protection and patch management. Your answers are independently reviewed and verified by an accredited certification body. It’s achievable for most organisations in a few weeks if the fundamentals are already in place.

Cyber Essentials Plus covers the same five controls but adds a hands-on technical assessment. An assessor tests your actual devices and systems, including vulnerability scans. It carries more weight with insurers, larger buyers and regulators, and it’s increasingly specified for higher-value contracts, NHS work and defence-related supply chains.

If the tender says “Cyber Essentials or equivalent”, the standard level usually suffices. If it names Plus, there’s no way around it. And if the paperwork is vague, get someone qualified to read it with you before you commit either way.

Timing matters more than people expect

Here’s a detail that trips up first-time bidders. Councils and public bodies often require a valid certificate at the point of contract award rather than at submission. Sounds like breathing room, right?

It isn’t, really. Certification takes weeks, not days, and if the assessment surfaces gaps (unsupported software, missing multi-factor authentication, patching you can’t evidence), remediation adds more time. Starting the process after you’ve won the bid means racing a clock you didn’t set. Starting before you bid means the certificate is simply there when you need it, and you can respond to opportunities quickly instead of turning them down.

There’s also the renewal cycle to think about. Certification lasts twelve months, so if you bid on public sector work regularly, keeping it current beats re-certifying in a panic every time a tender appears.

Getting certification is the easy part (once you know where you stand)

Most businesses don’t go looking for Cyber Essentials. It arrives in someone else’s paperwork, usually with a deadline attached. The good news is that the five control areas are the basics that stop the majority of common attacks anyway, so the work is worth doing regardless of the tender.

If a tender, a council framework or a main contractor has raised the question, the sensible first step is finding out whether you’d pass today. We offer a free Cyber Essentials readiness review: thirty minutes with a qualified assessor who tells you exactly what would fail and what’s already fine, plus a written summary you can act on however you like.

From there, our Cyber Essentials certification services take you through to certification (or Cyber Essentials Plus, if the contract demands it) with assessor support at every step. And if the review shows gaps that need ongoing attention rather than a one-off fix, our cyber assurance and vulnerability management programme keeps you certified, patched and able to evidence improvement, which is increasingly what public sector buyers want to see.

Public sector work is steady, well-paid and worth winning. A certificate that costs a few weeks of effort shouldn’t be the thing that stops you.

Your-IT-Department-logo