Skip to content

Government, procurement, and supply chain

Is Cyber Essentials mandatory for UK government contracts?

PPN 014 applies to specified central-government and NHS bodies and relevant procurements, with proportionate assurance and equivalent-control provisions. Check the tender for the required certification or accepted equivalent, scope and award timing. Transitional procurements may refer to PPN 09/23. It is not a blanket rule for every public-sector supplier.

Short answer

PPN 014 applies to specified central-government and NHS bodies and relevant procurements, with proportionate assurance and equivalent-control provisions. Check the tender for the required certification or accepted equivalent, scope and award timing. Transitional procurements may refer to PPN 09/23. It is not a blanket rule for every public-sector supplier.

Why this matters

Procurement questions matter because Cyber Essentials is often used as a supplier-risk filter. The buyer needs confidence that the certificate is valid, current, in the correct legal name, and sufficient for the contract requirement.

Public-sector requirements vary by contract. Some require Cyber Essentials, some require Cyber Essentials Plus, and defence suppliers may also need Defence Cyber Certification. Private-sector buyers increasingly use Cyber Essentials as a minimum supplier control, particularly where personal data or managed IT access is involved.

What to check next

  • Read the bid wording before buying the wrong level of certification.
  • Verify supplier certificates through the IASME Certificate search tool.
  • Keep renewal dates visible so certificates do not lapse during a contract period.

Official sources and related Fig Group guidance

For scheme-level confirmation, use the official NCSC and IASME resources. Fig Group links to these sources so Cyber Essentials buyers can verify the scheme, delivery partner and certificate record independently.