Procurement-team Cyber Essentials checklist: what to require from suppliers
For buyers, not sellers. A practical Cyber Essentials checklist for UK procurement teams managing supplier cyber-risk - which clauses to put in contracts, what evidence to accept, and how to spot expired certifications.

Section 01
Procurement-team Cyber Essentials checklist: what to require from suppliers
Most Cyber Essentials content is written for the seller - how to get certified, how to pass the audit, how to renew. This one is written for the buyer.
If you are a UK procurement, commercial, or supplier-management team deciding what cyber evidence to require from your suppliers, this is the practical checklist. It covers contract clauses, evidence formats, register checks, and how to monitor for lapse.
Section 02
Why this matters in 2026
Three drivers are pushing buyers to require supplier Cyber Essentials in 2026:
PPN 014 applies to central-government departments, their executive agencies, non-departmental public bodies and NHS bodies for relevant procurements commenced from 24 February 2025. Apply proportionate controls and permitted equivalents; do not require CE for every contract as a matter of course.
NIS2 duties depend on the EU entity and national implementation; UK CS&R proposals must be distinguished from existing NIS law. Contractual supply-chain assurance can reach suppliers without making each one directly regulated. CE is the cheapest and fastest baseline evidence in this guide, but does not replace a full supplier-risk assessment.
Cyber insurance renewals
Some underwriters ask about critical-supplier certification. Check the actual questionnaire and policy terms; a missing certificate does not establish an automatic premium increase.
Section 03
Illustrative supplier tiers - tailor to risk and legal requirements
These tiers are procurement advice, not universal statutory rules. Select CE, Plus or equivalent controls according to the actual service risk, buyer rules and contract. Data access alone does not impose Plus by law.
Tier 1 - Critical suppliers
Suppliers with access to customer data or production systems.
- Cyber Essentials Plus - third-party verified, not self-assessed
- Annual renewal enforced by contract
- Notification obligation within two business days if the certificate lapses or is revoked (an illustrative contract choice)
- Incident notification clause: supplier must inform you of any security incident affecting your data within 24 hours
Tier 2 - Material suppliers
Suppliers with access to corporate systems but not customer data.
- Cyber Essentials (self-assessed) at the appropriate size tier
- Annual renewal evidenced on renewal
- Scope declaration - the supplier's CE scope must include the systems they use to deliver your service
Tier 3 - Low-risk suppliers
Professional services with no data access.
- No CE requirement, or CE as a "would be nice" rather than a contractual obligation
- Focus procurement risk assessment on other areas (financial, delivery risk)
Section 04
Contract clause templates
Illustrative drafting for procurement and legal review: the two-business-day certificate notice, 24-hour incident notice, 14-day analysis and 30-day recertification targets below are negotiable sample terms, not universal law. Define business days, triggers, recipients, severity, evidence and lawful award exceptions for your contract before use.
CE requirement clause (Tier 1)
> "The Supplier shall hold, maintain, and continuously renew a valid Cyber Essentials Plus certification issued by an IASME-licensed certification body. The certification scope must include all systems, infrastructure, and personnel used by the Supplier in the performance of the Services. The Supplier shall notify the Customer in writing within two (2) business days of any suspension, lapse, revocation, or scope change affecting the certification, and shall provide evidence of re-certification within thirty (30) days of lapse."
Evidence clause
> "The Supplier shall provide, at contract signature and at each anniversary thereafter, a true and complete copy of the current Cyber Essentials certificate issued by an IASME-licensed certification body. The Supplier consents to the Customer verifying the certificate through the IASME Certificate search tool."
Incident notification clause (Tier 1, paired with CE Plus)
> "The Supplier shall notify the Customer of any Security Incident affecting Customer Data or the Services within twenty-four (24) hours of becoming aware of the incident, and shall provide a full root-cause analysis and remediation plan within fourteen (14) days."
Section 05
What evidence to accept
Accept:
- A current Cyber Essentials or Cyber Essentials Plus certificate PDF issued by an IASME-licensed certification body, showing:
- The supplier's registered legal entity name matching the contract.
- Issue date and expiry date, with the current date within the validity window.
- The certificate ID that can be verified through the IASME Certificate search tool.
- The IASME licence number of the issuing certification body.
Do not accept:
- "Cyber Essentials Ready" or "Cyber Essentials Verified" (marketing language - these are not CE certificates).
- Expired certificates, even if "renewal is in progress".
- Unverified issuer status: ask IASME to confirm the body’s licence at the issue date before rejection.
- Certificates whose documented entity/group and service scope do not cover the contracting supplier; check the actual listed group scope before rejecting a parent certificate.
Section 06
Verification checks
Use IASME’s certificate search to verify supplier certification. The certification-body directory is a separate licence lookup. Search certificate number and alternate legal/trading names; obtain IASME clarification for unresolved records before declaring invalidity or fraud.
1. Search by organisation name.
2. Confirm the certificate ID matches.
3. Confirm the issue date matches the PDF.
4. Confirm the expiry date is in the future.
Do this on onboarding and re-do it at every contract anniversary. For Tier 1 suppliers, run quarterly checks.
Section 07
Lapse monitoring
Certificates lapse on their anniversary with no grace period. For critical suppliers, put this in your system:
- 90 days before expiry: automated reminder to the supplier manager.
- 30 days before expiry: automated reminder plus a check-in with the supplier.
- Day of expiry: automated verification through the IASME Certificate search tool. If the certificate has lapsed and not been renewed, escalate.
Many procurement tools now support this natively. If yours does not, a shared Google Sheet with a date formula works.
Section 08
Tier selection guidance
A common procurement mistake is requiring CE Plus from every supplier regardless of risk. This inflates supplier cost (Plus pricing depends on scope and testing effort; there is no universal five-times ratio), compresses the market, and creates friction without reducing risk.
Illustrative starting points, subject to risk assessment and applicable rules:
- Supplier has access to customer PII or systems: CE Plus.
- Supplier has access to corporate systems but not customer data: CE.
- Supplier has access to no sensitive systems: CE is a reasonable "nice to have" but not a blocker.
Section 09
The MSP question
Managed Service Providers and IT consultancies are a common Tier 1 category for UK buyers. They have privileged access to multiple client environments. Specific procurement considerations:
- Require CE Plus, not CE, given the privileged access.
- Require that the MSP's scope covers their operational environment (the tools they use to deliver managed services, not just their corporate laptops).
- Consider requiring ISO 27001 in addition to CE Plus for larger MSPs.
Fig Group writes extensively about the MSP-specific scope question - see the MSP sector guide.
Section 10
What to do when a supplier says "we are in the process of getting certified"
This is a procurement decision, not a CE decision. Options:
- Block contract award until the certificate is in place.
- Consider a conditional award only where the applicable procurement rules allow it, with an approved milestone and required evidence before data access; there is no universal 60–90-day grace period.
- Accept an interim evidence pack (the supplier provides evidence of the five CE controls even though they are not yet certified).
For contracts under PPN 014 or regulated-sector rules, follow the exact award, evidence and permitted exception provisions. A pending certificate is not current certification; any exception requires the buyer’s documented decision and lawful conditions.
Section 11
Bottom line
Cyber Essentials is the cheapest, fastest baseline certification option considered in this guide for demonstrating the five technical control families, subject to scope, readiness, pricing and delivery terms; this is not a market-wide ranking. Procurement teams that require the right tier from the right suppliers, monitor lapse, and verify the register do more to manage supply chain cyber risk than most six-figure supplier risk management platforms.
Use the contract clauses above as a starting point. Calibrate by risk. Verify on the register. Certificate checks are one part of a wider supplier-risk programme, alongside service-specific controls, incident handling, continuity and contract monitoring.
Get certified yourself in 6 hours | Read about supplier risk | See Fig Group vs traditional GRC
The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Explore how Fig Group automates compliance mapping, evidence collection, and framework alignment across 65+ standards.
Request a demoRelated guides
Continue reading
Compliance
How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers
Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.
Read articleCompliance
Cyber Essentials for UK Organisations: Choosing the Right Certification Body
A practical guide to selecting a Cyber Essentials certification body if you are a UK organisation navigating government contracts, supply chain requirements, or regulatory expectations.
Read articleGuides
Cyber Essentials Bristol: a practical certification guide
For a Bristol business, choosing Cyber Essentials starts with the service being delivered and the assurance a customer needs. An engineering supplier exchanging design files may face different contractual questions from a digital agency managing campaign assets, even though the national Cyber Essentials controls are the same.
Read article

