Skip to content
Guides

Is Cyber Essentials a legal requirement?

Cyber Essentials is not a general UK legal requirement. Check the actual tender, MOD contract, insurer conditions and permitted equivalent controls.

brown wooden tool on white surface

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

4 min read

Share

Section 01

No - Cyber Essentials is not a legal requirement for UK businesses in general. It is a voluntary NCSC-backed certification scheme. However, it is contractually mandatory for many UK central government contracts, for MOD sub-contracting, for St. James's Place partner practices, and for a growing number of regulated supply chains.

Section 02

Where Cyber Essentials is contractually mandatory

Central government and NHS procurement. PPN 014 applies to relevant procurements commenced from 24 February 2025 by central-government departments, their executive agencies, non-departmental public bodies and NHS bodies. Controls must be relevant and proportionate, with permitted equivalents; the policy does not require certification for every contract or select Plus automatically by value.

MOD contracts and subcontracting. Check DEFCON 658, Def Stan 05-138 issue 4, the buyer’s numeric profile/RAR and flowed-down terms. DCC can provide independent evidence, but the full SAQ remains mandatory under current MOD guidance. CE is a DCC certification prerequisite; Plus applies at Levels 2 and 3. The industry request for Level 0 by end-2026 is separate from the actual contract condition.

NHS supplier frameworks. Many NHS procurement frameworks - including those operated through NHS Shared Business Services - reference CE or Plus in supplier-onboarding requirements.

SJP partner practices. SJP's published reporting describes Cyber Essentials Plus or use of its Device as a Service solution. Confirm the applicable route with SJP; see our sourced Partner Practice guide.

Insurance. Many UK cyber-insurance and PI policies reference CE in underwriting - not legally mandatory, but commercially very close to it for firms facing PI renewal cycles.

Section 03

Where Cyber Essentials is strongly expected but not legally mandated

SRA-regulated law firms. Verify the firm’s actual regulatory and customer requirements. Cyber Essentials can support baseline assurance but is not a substitute for all professional or data-protection duties; this guide establishes no profession-wide certification mandate.

FCA-regulated firms. Apply the relevant operational resilience and security rules to the actual regulated activity. Do not infer a universal Cyber Essentials mandate or regulator endorsement from general technical-control expectations.

UK GDPR Article 32. Appropriate technical and organisational measures depend on risk. CE can provide technical evidence but does not establish full GDPR compliance or replace information-governance obligations; see the GDPR guide.

Section 04

Where Cyber Essentials is not legally required

Most UK SMEs have no general statutory duty to hold CE. A contract or insurer may still require it. Any IASME-arranged cyber liability cover depends on current eligibility, whole-organisation scope, opt-in requirements and policy terms; certification does not guarantee activation or insurance suitability.

Section 05

The Cyber Security and Resilience Bill is a separate legislative proposal; do not treat a Bill as enacted duties or a general CE mandate. Check final legislation, commencement and sector guidance before applying any new obligation.

Section 06

Bottom line

Cyber Essentials is not a general UK legal requirement. It may be required by a particular tender, subcontract or insurance policy; read those terms, permitted equivalents and scope before purchasing.

Start Cyber Essentials from £299.99 + VAT | Free readiness check | Cyber Essentials for government contracts

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group