How to verify a Cyber Essentials certificate: the buyer and procurement-team guide (2026)
A supplier has sent you a PDF claiming to be their Cyber Essentials certificate. How do you confirm it is real, current, and issued to the organisation you are actually contracting with? This is the verification guide for procurement and tender-assessment teams.

Section 01
How to verify a Cyber Essentials certificate: the buyer and procurement-team guide (2026)
A supplier has sent you a PDF claiming to be their Cyber Essentials certificate. Your tender, your supplier-onboarding process, or your procurement policy requires certification as a gate. The question for you as the buyer is straightforward: is this certificate real, current, and issued to the organisation you are actually contracting with?
This guide is the verification checklist for procurement, tender-assessment, supplier due-diligence, and risk-management teams. It takes about five minutes per certificate to complete properly.
Section 02
Start with IASME certificate search
Use IASME’s certificate search for supplier certification. The certification-body directory lists licensed assessing bodies and serves a different purpose.
If a search returns no match, search the certificate number and alternate legal or trading names and request the original PDF. Ask IASME to clarify unresolved records before concluding that a certificate is invalid, fraudulent or grounds for exclusion.
Section 03
Five things to check on every certificate
1. The organisation name matches the legal entity
Check the legal entity and documented scope on the certificate. Companies House can help for UK companies, but sole traders and non-UK entities may have different records. A group certificate may list covered subsidiaries; confirm the actual entity and scope rather than assuming either automatic group coverage or automatic exclusion.
- Parent group versus subsidiary. Check whether the subsidiary is expressly included in the certified entity/group and scope. A parent name alone does not establish coverage either way.
- Trading name versus registered name. "Acme Consulting" trades as the brand, but the Companies House entity is "Acme Consulting (UK) Limited." The certificate should match the legal entity.
What to do: confirm the organisation name on the certificate matches the legal entity on the contract, on Companies House, and on the supplier's VAT invoice.
2. The certificate is current
Every certificate shows an issue date and an expiry date. Validity is 12 months from the date of issue. Check both dates - an issued-today certificate valid through 2027 is current; an issued-two-years-ago certificate is not.
Check the certificate’s issue and expiry dates against the actual IASME certificate-search record. A missing or unclear record is unresolved verification, not proof of expiry; confirm alternate names, certificate number and IASME clarification.
What to do: open the IASME directory, search the organisation, and confirm the entry shows a current certificate with the expiry date still in the future.
3. The certification body on the certificate is IASME-licensed
Every Cyber Essentials certificate is issued by an IASME-licensed certification body. The body's name appears on the certificate and on the directory entry. IASME maintains the current published list on its find-a-certification-body page.
Red flags:
- The certificate names a "certification body" you cannot find on the IASME list.
- The certificate does not name a certification body at all.
- The certificate uses a generic "NCSC-approved" phrasing with no specific body named.
What to do: check current licence status and, where it has changed or is unclear, obtain IASME confirmation of status when the certificate was issued. Current absence alone does not prove historical invalidity.
4. The level (CE or CE Plus) matches the requirement
Cyber Essentials and Cyber Essentials Plus are different products. Plus requires hands-on technical testing by an assessor; Cyber Essentials does not. If your tender specifies Plus, a supplier holding Cyber Essentials (not Plus) does not meet the requirement.
What to do: read the certificate carefully. The words "Cyber Essentials Plus" must appear explicitly. A certificate that says "Cyber Essentials" alone is not Plus.
5. The scope is relevant
Most Cyber Essentials certificates are issued with "whole organisation" scope, meaning every internet-connected device and user in the organisation is covered. Some are issued with sub-set scope, where the organisation has certified only a defined part of its estate.
If a supplier's certificate is sub-set scoped, the scope statement on the certificate should be relevant to the contract. A supplier certifying only their London office but providing services from Manchester gives you less coverage than the certificate implies.
What to do: check the scope statement on the certificate. If it is sub-set scoped, confirm the scope covers the part of the supplier's operations that will deliver your contract. See Cyber Essentials v3.3 sub-set scoping.
Section 04
The five-minute verification protocol
For every Cyber Essentials certificate presented to you in procurement:
1. Open IASME certificate search and search the certificate number and organisation names. Use the separate body directory only for issuer checks.
2. Search the certificate number and supplier’s legal name. Check alternate trading names and any explicitly listed group entities where needed; confirm the contracting entity and actual scope.
3. Confirm there is a matching entry showing a current certificate.
4. Confirm the level (Cyber Essentials or Cyber Essentials Plus) matches your requirement.
5. Confirm the issuing body named on the PDF matches the body named on the directory entry.
6. Check the expiry date is still in the future and gives enough time to cover the contract term (or will be renewed before expiry).
7. Check the scope statement for any sub-set scoping that could limit the practical coverage.
Section 05
Red flags and scam patterns
A small number of fake or misrepresented certificates circulate in UK procurement every year. The patterns to watch for:
- PDF that does not match the IASME directory. Most common. A PDF that looks plausible, names a non-existent certification body, and cannot be found on the directory.
- Expired certificate presented as current. Visually indistinguishable from a current one unless you check the dates and the directory.
- Certificate for the parent group, presented by a subsidiary or trading entity. The certificate may be genuine; confirm whether its listed entities and scope cover the contracting supplier.
- Cyber Essentials (not Plus) presented where Plus is required. Sometimes deliberate, sometimes an honest misreading of the requirement.
- Screenshot or image, not the signed PDF. Always request the original PDF so you can cross-reference.
- "We are IASME-accredited assessors" marketing language without a named certificate. The term "accredited" in UK scheme usage applies to IASME-licensed certification bodies, not to the end organisation's certification status.
Section 06
What to do when verification fails
If a supplier's certificate fails verification, the appropriate response depends on the contract stage:
- During tender evaluation: flag the certificate as not verified and treat the supplier as non-compliant with the tender's CE requirement. Request the correct entity and scope evidence, ask IASME to clarify unresolved records, and follow the tender’s verification and exclusion rules before making an adverse decision.
- At supplier onboarding: request the correct certificate. If the supplier is mid-renewal (certificate expired within the last 30 days and a renewal is in progress), ask for the certification body's written confirmation that an assessment is under way and obtain the new certificate before contract start.
- At contract renewal: request an up-to-date certificate. If the supplier has let the certificate lapse, this is a material contract-compliance issue and should be raised formally.
- If you suspect deliberate fraud: report to IASME via their contact page. Misrepresenting a Cyber Essentials certificate is both a scheme breach and, depending on context, potentially a matter for action under fraud legislation.
Section 07
Building certificate verification into your procurement workflow
Organisations that onboard suppliers at scale typically standardise the verification into a two-line checklist in their supplier-management system:
- [ ] Cyber Essentials certificate verified on IASME directory (date of check, name of checker)
- [ ] Certificate expiry date recorded, renewal check scheduled 60 days prior
A handful of larger UK procurement teams now automate the check using the IASME directory as a reference source, alerting when a supplier's certificate is within 60 days of expiry or has lapsed since onboarding.
Provide the registry link as well as the PDF, but verify the actual entry and dates. Certificate issue and public listing are separate steps; this guide does not guarantee an immediate registry update.
Section 08
If you are a supplier presenting your certificate
Make verification easy. Send the PDF as an attachment, include the direct link to your IASME directory entry, and pre-empt the obvious questions:
- Legal entity name as it appears on the directory.
- Certificate level (CE or CE Plus).
- Issue and expiry dates.
- Issuing certification body and its IASME licence ID.
- Scope statement.
A supplier who saves the procurement team the verification time earns goodwill. A supplier who makes verification hard invites closer scrutiny everywhere else.
Section 09
Why Fig Group certificates are easy to verify
Every Cyber Essentials certificate issued by Fig Group:
- Can be checked through IASME certificate search once the registry record is available; public listing timing is separate from the assessment service.
- Names Fig Compliance Ltd as the certification body, with the scheme licence independently verifiable through the Blockmark badge and registry link on the trust page.
- Links to a clean organisation-level entry with legal name, level, issuing body, and dates.
- May qualify for IASME-arranged cyber liability insurance, subject to current eligibility, whole-organisation scope, opt-in requirements and policy terms; do not assume same-day activation.
For procurement teams, a Fig Group certificate is designed to be verified in under 60 seconds: open the link, see the entry, done.
Section 10
Bottom line
Verifying a Cyber Essentials certificate is a five-minute job and a standard part of competent procurement. The IASME certificate search supports supplier verification; an unresolved search result requires name/number checks and IASME clarification before any invalidity conclusion. Check the legal entity, the dates, the level, the issuing body, and the scope - and you have a defensible, documented record that the supplier's certificate is genuine.
For suppliers making it easy: publish your certificate's directory link, keep the renewal ahead of expiry, and buy from a fast IASME-licensed body so your certificate can issue and be listed quickly when procurement asks for it.
Start your verifiable Cyber Essentials certificate from £299.99 + VAT | All pricing | What a Cyber Essentials certificate is | FAQ
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Guides
Cyber Essentials Online: the complete UK guide for 2026
Cyber Essentials is an online certification - the self-assessment, the evidence review, the assessor feedback, and the certificate itself all happen through a portal. This is what that actually looks like in 2026, what to watch for when you pick a certification body, and where the market currently sits on price and turnaround.
Read articleGuides
Cyber Essentials Certificate: what it is, how to get one, and how long it lasts (2026)
A Cyber Essentials certificate is a dated, verifiable digital document issued by an IASME-licensed certification body. This guide covers exactly what the certificate proves, how long it is valid, how third parties verify it, and the fastest, cheapest route to getting one in 2026.
Read articleGuides
Cyber Essentials Harlow: the 2026 guide for Harlow businesses
A practical Cyber Essentials guide for Harlow suppliers: confirm the buyer's requirement, define the assessment scope and prepare accurate evidence before certification.
Read article

