Cyber Essentials for Construction Companies and Contractors
Construction firms bidding for government infrastructure work, MOD contracts, or public-sector framework places are increasingly required to hold Cyber Essentials. This guide covers how the controls apply to construction-specific infrastructure, including site laptops, tablets, and BIM platforms.

Section 01
Cyber Essentials for Construction Companies and Contractors
Construction buyers can request Cyber Essentials or Plus through specific contracts and frameworks. Check the dated tender schedule and any flow-down condition rather than infer a mandate from framework names or MOD involvement. PPN 014 has a defined procurement scope; defence contracts also need their assigned Cyber Risk Profile and assurance conditions checked.
This guide covers what certification actually means for a construction business, how the controls apply to the site-based and office-based mix of infrastructure most contractors run, and the scoping and BYOD questions that are distinctive to the sector.
Section 02
Why construction firms are being asked for Cyber Essentials
Four overlapping pressures:
Government construction frameworks. Most CCS construction frameworks, including the major Works frameworks and the Construction Design & Build frameworks, list Cyber Essentials as a minimum requirement at the supplier qualification stage. Several go further and require Plus.
Tier-one subcontract terms. Larger contractors (Balfour Beatty, Kier, Mace, Skanska, Morgan Sindall, Willmott Dixon, Lendlease) increasingly cascade CE requirements into their subcontract terms. If you are a specialist subcontractor bidding to a tier one on a public-sector project, expect to be asked.
MOD and defence infrastructure. Work at MOD sites, for DE&S, or on Defence Infrastructure Organisation projects requires CE as a baseline. Some specific projects require CE Plus plus DEFSTAN 05-138 compliance.
Principal Designer / CDM overlap. Increasingly, principal designers and principal contractors are being asked about the cybersecurity posture of their entire supply chain as part of construction project risk management. CE has become the simplest way to demonstrate a baseline.
Section 03
What construction infrastructure looks like
The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.
A typical UK construction firm runs a mix:
- Office-based staff on Microsoft 365 or Google Workspace, with estimating, commercial, and bid management roles working from laptops
- Site-based staff on laptops or tablets, often moving between multiple project sites each week
- A project management platform (Procore, Aconex, Asite, Fieldwire, PlanGrid)
- BIM / CAD platforms (Autodesk BIM 360, Bentley ProjectWise, Revit)
- Commercial software (Causeway, COINS, CIS, Eque2 Construction Manager, Sage 200 Construction)
- Accounting / payroll (Sage, Xero, CIS-aware variants)
- Site cameras and remote monitoring
- Contractor-issued mobile phones for site use
- Plant and equipment with telematics (JCB Livelink, Caterpillar VisionLink)
Everything up to and including BIM and the commercial systems is in scope. Site cameras and plant telematics may or may not be, depending on whether they process organisational data - the answer is usually that the data they push to the cloud service is organisational, so the telematics platform is in scope even if the physical devices are vendor-managed.
Section 04
Site-based laptops and the BYOD question
The hardest Cyber Essentials area for construction is device management on site. Staff move between sites, use laptops in site offices that have temporary wifi, connect to client wifi networks, and sometimes tether from personal phones. The software firewall requirement gets more load than it does in a purely office-based business.
Specific issues to get right:
- Laptops need to have their software firewall enabled and locked, so that connecting to a site wifi does not turn it off
- Full-disk encryption (BitLocker or FileVault) is a recommended theft-and-loss safeguard for site laptops, or a separate contractual requirement where specified; it is not a universal Cyber Essentials requirement.
- If using MDM, verify that its policies actually reach site devices. Other evidenced management approaches can also satisfy the scheme controls.
- Mobile phones used for site work need the applicable malware-protection and configuration controls. Their users need MFA when accessing in-scope cloud services; do not treat a local phone account as a cloud login.
A planning example: a contractor has MDM-enrolled laptops for office staff but the site manager team uses pool laptops that were imaged two years ago and have never been managed centrally. Those pool laptops are in scope and need the same controls as the office fleet.
Section 05
Subcontractor access
A construction business routinely shares BIM models, drawings, and programmes with subcontractors. Those subcontractors may have login access to the company's Procore, Aconex, or Asite tenant. Every one of those accounts is a user under v3.3 and needs MFA.
The realistic position for a mid-sized contractor is:
- Main permanent staff: on the corporate Entra ID / Google identity, MFA enforced, standard user rights on managed devices
- Subcontractor users: on the BIM or project platform's own identity, MFA enforced at the platform level, time-limited to the duration of the engagement
- Short-term site staff and labourers: typically no system access at all; if they need access to anything (e.g. a daily briefing platform), they get a time-limited dedicated account
What does not pass: shared subcontractor accounts ("subby1", "subby2"), or a long list of legacy subcontractor accounts left active years after the relevant project finished.
Section 06
BIM, CAD, and model sharing
Cloud-hosted BIM services are in scope alongside applicable user accounts, desktop applications and integrations. Document the provider/customer control responsibilities and verify the actual MFA configuration; provider operation does not automatically exclude the service.
Specific things to check:
- MFA enforced on every user account on your BIM platform, including external collaborators if you own their account
- Consider encryption for locally synced model files according to project contracts and risk; distinguish that safeguard from the Cyber Essentials control requirements.
- Departed staff have had their BIM access revoked promptly
- Design-software updates. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update. Plan compatibility testing early enough to meet the applicable deadline.
Section 07
Commercial systems and CIS
CIS-aware accounting systems (Causeway, COINS, CIS software) hold payroll and subcontractor payment data. This is in scope because it holds organisational and personal data (National Insurance numbers, UTRs, bank details). The applicable CE controls apply: MFA for every user of in-scope cloud services, plus authorised access, account ownership and leaver processes.
A failure pattern: the commercial director has a CIS software login that was shared with the office manager "so they can enter invoices when I'm on site". Shared accounts fail.
Section 08
Five construction-specific failure patterns to check
1. Pool site laptops unmanaged. Office fleet is under MDM; the three laptops the site teams share are not.
2. Subcontractor accounts left live. Subcontractor finished their scope in 2023, their Procore account is still active in 2026.
3. Plant telematics platform not considered. The organisation has not thought about the fact that the plant telematics cloud account holds data that is organisational and is accessed by named users with password-only credentials.
4. BIM desktop software unpatched. Critical Autodesk or Bentley updates deferred "because the project is using a specific build". These need to be patched or formally excepted.
5. Employee BYOD without evidenced controls. Personal devices used for work are generally in scope. Meet the applicable controls, through MDM or another evidenced approach, or prevent the work access; simply recording an exception does not establish compliance.
Section 09
Practical path to certification for a construction firm
If you are a construction company with 10-250 staff:
1. Map every system that holds project data. Include the commercial systems, BIM, project management, site cameras, and plant telematics.
2. Audit user accounts on every in-scope system. Enforce MFA for every user accessing in-scope cloud services and apply the separate password and administrative-access controls elsewhere. Reconcile against current staff and active subcontractors.
3. Verify device controls. Use MDM or another evidenced management approach to meet the five scheme controls; employee BYOD accessing work data is generally included, while access restrictions must be implemented in practice.
4. Verify mobile-device controls. Use MDM or another evidenced management approach to meet the five scheme controls; employee BYOD accessing work data is generally included, while access restrictions must be implemented in practice.
5. Document plant telematics and site cameras as part of scope, with the cloud service's own MFA and user management described.
6. Submit. CE small (10-49 staff) £399.99 + VAT; medium (50-249) £449.99 + VAT; large (250 - 9,999) £549.99 + VAT. Plus ranges from £1,499.99 to £4,499.99 + VAT.
Section 10
Bottom line
Construction buyers can make certification a tender condition, but shortlist and PQQ outcomes depend on the specific opportunity. Prepare office and site systems against the same applicable controls; a certificate does not guarantee bid acceptance.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.
Read articleIndustry
Cyber Essentials for Schools, Colleges, and Universities
Cyber Essentials is increasingly expected across UK education. DfE guidance, Jisc recommendations, and funder due diligence are pushing schools and further / higher education institutions toward certification. This guide covers how the controls apply to education-specific infrastructure.
Read articleCompliance
Cyber Essentials for Government Contracts: The Complete Guide
PPN 014 applies Cyber Essentials controls proportionately to certain government and NHS contracts. This guide explains when certification or equivalent controls apply and how the tender determines the level.
Read article

