Short answer
Some private-sector buyers require Cyber Essentials or Cyber Essentials Plus through supplier contracts. The required level, organisational scope and any accepted alternative depend on the buyer and engagement. Ask for the current written requirement rather than assuming a universal rule for a sector or every Tier 1 supplier.
Why this matters
Procurement questions matter because Cyber Essentials is often used as a supplier-risk filter. The buyer needs confidence that the certificate is valid, current, in the correct legal name, and sufficient for the contract requirement.
Public-sector requirements vary by contract. Some require Cyber Essentials, some require Cyber Essentials Plus, and defence suppliers may also need Defence Cyber Certification. Private-sector buyers increasingly use Cyber Essentials as a minimum supplier control, particularly where personal data or managed IT access is involved.
What to check next
- Read the bid wording before buying the wrong level of certification.
- Verify supplier certificates through the IASME Certificate search tool.
- Keep renewal dates visible so certificates do not lapse during a contract period.
Official sources and related Fig Group guidance
For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.